|
A New Approach to Secure Communication: Identity-Based Encryption Voltage delivers a revolutionary new way of securing communication that overcomes the hurdles of existing solutions. As a result, Voltage delivers communication security solutions that help enterprises to experience the full benefits and ROI of moving business processes to the Internet. By using a commonly used identity—such as the user’s email address or network ID—as the user’s public key, Voltage is the only provider that addresses the critical requirements of ubiquitous secure communication beyond corporate boundaries. Voltage’s transparent encryption breaks down the barriers to secure messaging by making it second nature—thereby enhancing enterprise security. Voltage Security is the first to use identity to bring confidence to your business communication.
Based on a new form of public-key cryptography called Identity-Based Encryption, (IBE) that utilizes commonly used identities as the user’s public key, Voltage Security delivers the breakthrough technology that radically changes the way people think about secure communication. By eliminating the need for individual per-user certificates, Voltage Security’s solutions provide a highly scalable, universally inter-connectible method for secure communication that overcomes the flaws of existing approaches. Specifically, Voltage Security solutions: Secure anytime, anywhere communication Voltage Security solutions allow users to conduct secure business communication anytime, anywhere – even on the road. For example, a secure email can be encrypted or decrypted on a laptop even when not online. With Voltage, users can conduct business securely—from anywhere in the world—because they can roam transparently, enabling complete flexibility in how, and when, users conduct their work. Allow for self-provisioning to conduct secure communication The elimination of per-user certificates and the related requirement to connect to third-party servers to verify these certificates before initiating secure connections allow for user self-provisioning. No pre-enrollment of users is needed to conduct secure ad hoc communication. Secure ad hoc communication enables users to securely exchange messages, via email, instant messaging or other means, without having knowledge of whether the other party is already enrolled or registered. This type of communication matches the way people normally interact over the telephone or with a fax machine. This makes Voltage Security solutions infinitely scalable for an enterprise. Enable secure messaging that is transparent to users By using a commonly used identifier as the encryption key, Voltage Security provides a simple, yet highly secure, method to encrypt business communication, thereby enhancing the overall enterprise security. No additional steps or clicks are required on the user’s part to ensure secure communication because the user is recognized by his identity—e.g. his email address or user login. Easily managed by administrators With Voltage Security solutions, administrators can centrally manage the security of their business communication. Policies used to secure business communication are enforced at the central key server and can be changed simply and automatically. The sender merely transmits his security requirements and the key server enforces them. Administrators are also given the flexibility of working with any leading authentication methods with Voltage solutions. This flexibility allows Voltage solutions to secure virtually any system or network object centrally through one solution. Low cost Voltage Security provides a lightweight solution that integrates easily and quickly with existing enterprise application infrastructure. Because heavy infrastructure and third-party CAs are not required, implementation of secure messaging within the enterprise’s infrastructure is simplified. In addition, instead of deploying a point solution for each type of business communication to secure, administrators can deploy a single platform—the Voltage Security platform—to secure all types of business communication, ensuring a low total cost of ownership (TCO) for the enterprise. How the Voltage Security Solution Works Voltage Security solutions allow enterprises to secure a wide range of mission critical business communication - one example of which is to secure email communication with the Voltage SecureMail™ solution. These examples also apply to Instant Messaging using Voltage SecureIM™ . Alice at Company A would like to send her customer Bob at Company B a sensitive email. For compliance reasons, the email must be secure. Alice uses the Voltage SecureMail solution to send the secure email to Bob.
Alice Sends a Secure Message to Bob After Alice composes the message, she simply hits the Send Secure button, which automatically secures the message, along with any attachments, using Bob’s email address "bob@b.com". Voltage SecureMail does not require pre-enrollment of users to receive secure email; even if Bob has never previously communicated with Alice or has never used Voltage SecureMail, he is still able to receive secure email from Alice. Bob Receives the Secure Message The first time Bob receives the secure message on his laptop, Bob clicks on a link in the message header and downloads the Voltage SecureMail client. He then proceeds to enroll and authenticate to Company A’s SecurePolicy Suite. The method used to authenticate Bob is completely flexible to the requirements of the enterprise. Bob Decrypts and Views the Message Upon completion of proper authentication, the SecurePolicy Suite will present Bob with his private key to read the secure email. Alice and Bob can now communicate securely with Voltage SecureMail. With his private key downloaded to his laptop, Bob can decrypt and view his received secure email even when he is offline on an airplane. Bob can even read his secure email at a business center using Voltage SecureMail's transparent roaming capabilities. Secure Email Sending a secure email today, using a traditional email application combined with PKI, is complicated and presents many roadblocks, which is why the vast majority of email is not encrypted. Often, the sender only knows the recipient’s email address, and must determine the recipient's certificate either by consulting a directory or by contacting the recipient directly. While directories do exist, they are not widespread, so consulting them is generally futile. If the sender must contact the recipient, this can create delays. Moreover, the request for the certificate is unprotected. Another solution offered in the market today is web-based secure email. In this example, the message is stored on a web server and the recipient is notified of the message with a secure URL link. While its ease of use may be somewhat attractive, most email users are unwilling to switch over to non-standard email clients. The inability of easily integrating ones email into standard clients breaks workflow and creates usability issues for users. Because the email is now stored on a web server, the user is required to be online to view the email. Corporate email users have demonstrated the need for managing their emails locally on their machines. A solution that places strict online requirements will not suffice for enterprise email users. In contrast, Voltage SecureMail enables users to send secure email directly to any recipient—instantly. If this is the first encrypted message received by the recipient, he simply contacts the enterprise key server to acquire the private key. Otherwise, he merely decrypts the message without any additional steps or effort. Because Voltage Security solutions overcome the roadblocks to secure messaging and enables transparent encryption, enterprises gain better, finer-grained control over external communication. With fewer impediments to use, encryption becomes second nature, and the more users that implement secure email, the better enterprises can audit and comply with government regulations. Secure Instant Messaging and Peer-to-Peer Communication As the popularity of Instant Messaging has grown, so has the volume—and types—of information communicated using the technology. But without built-in provisions for security, IM has become a major perpetrator in the compromise of enterprise security. The Voltage SecureIM™ solution enables users on any public IM platform—Yahoo!, MSN, AOL, etc.—to send and receive secure IM messages from business partners, customers, and partners running any other IM platform. To send a secure IM using the Voltage Security solution, the user simply types in the recipient’s identity (typically an IM screen name or a user’s email address) and the IM client automatically encrypts the message—no searching for a directory or verifying certificates. The transparent encryption delivered by Voltage enables end-to-end security for IM with significantly less overhead than those that rely on the security mechanisms delivered by the IM solutions themselves. In comparison, IM solutions that deliver security options for their products encrypt and decrypt the IM communication twice: once from the sender’s IM client to the IM server, and then again from the IM Server to the recipient’s IM client. While on the IM server, the message—and its contents—are unencrypted and unprotected, which can leave sensitive information open to prying eyes. Using Voltage Security Solutions to Enable Secure Files Whether it’s a Microsoft Excel spreadsheet attachment sent via email, customer financial information stored on a hard disk, confidential patient information stored on a shared file server, or the latest product pricing strategy stored in the company intranet or pricing portal, all of an enterprise’s files must be stored securely to ensure the protection of sensitive company secrets—and customers’ privacy. The security must go beyond the creator of the file simply encrypting the document for his or her own use to encrypting and signing the file for designated users or groups of users. The consequences of improper management of such sensitive material are serious, from both a corporate security as well as an economic standpoint. Recently passed federal regulations such as the Gramm-Leach-Bliley (GLB) Act or the Health Insurance Portability and Accountability Act (HIPAA) dictate the protection of customer data, and individual states have also enacted severe penalties for companies that fail to protect customer privacy. The flexibility of Voltage Security’s SecureFile™ allows users to encrypt and sign files for use by other authorized individuals. Files can be encrypted to multiple users based on their email addresses and/or policies set by the creator of the encrypted file. Secure files that are signed provide assurance of the authenticity of the originator of the encrypted file. Once secure, these files can be transported easily by any medium and be assured of its confidentiality. For more information:contact Synergy Software Systems 097150
4564456 |