Home Business

Business Home: The BOTTOM LINE

On this page we address the business bottom line:
  1. Cryptographic security is the great enabler of the 20th century. Security technologies have enabled eCommerce, the reliable operation of critical infrastructure, and so much more.

    • Synaptic technologies address existing security problems in designs that support the next great wave in advances such as mobile eCommerce, machine-to-machine communications and increased multi-functionality in ever smaller devices. Synaptic technologies drive long term security into smaller devices with more functionality, greater efficiency and at low risk. Synaptic technologies can simply provide an additional layer of long term defence to protect today's encrypted data against tomorrows attacks.
  2. You have invested heavily into existing standards based security solutions. We do not ask you to abandon your investments in existing security standards or to fall out of step with the wider industry.

    • In most day-to-day business cases Synaptic technologies incrementally enhance your existing standards-based security in low cost low risk ways without seriously disrupting your systems. Choose the Synaptic technology that enhances your current investments and matches your corporate objectives. Synaptic technologies also offer the potential to seemlessly evolve a next generation security ecosystem that protects your business and its supply chains, enhances your market opportunities and that can easily synchronise with your organisation's strategic objectives and business cycles.
  3. Obama-Biden Plan / ENISA / British Government Technology Strategy Board and leading security networks of excellence state clearly that we have major problems in global security systems and that it is no longer reasonable for any one part of our society or infrastructure to be silo'd behind strong security protection when other interdependent links are not. Our communications systems and devices must be secure by default.

    Information in particular has become a precious asset that must be protected against threats to its confidentiality, integrity and availability.

    But conventional security is not enough.

    The complexity of today's operational environment means organisations must embrace a level of business resilience that is normally associated with the protection of critical national infrastructure.

    • Synaptic offers simple low cost low risk technologies that incrementally address these known challenges. They have been specified within a larger holistic security ecosystem vision that is incrementally deployable in the fragmented security market to enable a wide spread upgrade throughout the interdependent information society as a whole. Early collaborators and licensors of Synaptic technologies may be able to bid solutions into the highly anticipated Obama-Biden Homeland Security projects.
  4. We know that our long term security issues are overlooked or pushed aside for later:

    Security and dependability issues typically go along with the life cycle of a technology. The trend to first deploy a technology and later fix its problems – typically driven by economic motives – is gradually making way for security by design, resulting in improved security at the beginning of the life cycle.

    The use of marginally secure cryptography means that sensitive business operational and trade secret information may be decrypted at a later stage. Weak superceded security technologies used by one group can cause security risks for everyone in global systems, such as in the case of the global Certificate Authority attack (November 2008).

    • Synaptic technologies and the wider security ecosystem vision manage these risks and offer you the opportunity to protect yourself and your customers through superior technologies engineered for efficiency that enhance  existing security investments with higher security margins.
  5. We now know that code-breaking quantum computers may abruptly devastate our global security systems. Some expect quantum physics to provide a solution, but until such as solution is commercialised and ubiquitously deployed then all recorded secure data (using standards based systems) cannot be protected. Some hope that quantum key distribution (QKD) may solve the Quantum security risks, others expect that solutions will simply emerge in some future global standard overnight. However QKD is extremely expensive, requires point-to-point optical fibre connections between parties for full security, suffers from attacks just like classical cryptography, and is widely acknowledged by its proponents as NOT BEING A SOLUTION for the Internet or e-Commerce. While we wait for someone else to solve the open problems and create a low cost solution our company, our associates, and our customers sensitive data is being recorded for later decryption AND we run the risk of an earlier than expected arrival of large quantum computers that will force a disruptive and inadequately planned global rip and replace security scenario.

    • Synaptic technologies are targeted to address the security challenges facing businesses today WITH the added bonus of immediate universal low cost protection against code breaking quantum computers. Synaptic protection can be incrementally built in for literally billions of devices, large and small. The careful design and implementation of a new security ecosystem can avoid the drama and gracefully improve the security of our interconnected global community to secure long term assurance. This applies not only for new infrastructure projects but also retrospectively for many already deployed systems.
  6. We must work under the assumption that all our secured data is being recorded, either over the Internet or by black hats in your organisation, particularly if you or one of your supply chain collaborators are high value targets.  Can your organisation and supply chain afford the exposure that would result from recorded sensitive data being decrypted 5, 10 or 15 years in the future? Isn't it worth a little effort to mitigate the risk now?

    • Synaptic halts providing pension plans for hackers and thwarts international espionage by stopping the returns on performing low cost wait-and-see attacks by using technologies that are not vulnerable to known and anticipated attacks.

Organisations that adopt Synaptic technologies will gain all the above advantages and be able to offer higher business continuity assurances to their stakeholders. They will be able to clearly differentiate and insulate themselves from those organisations that choose not to manage the known risks while still interoperating with them. They will secure market differentiation through offering higher assurance services and products that can incrementally harden existing infrastructures in a non-disruptive manner at low risk and cost. There is also the potential to provide new services and new products enabled by the Synaptic technologies.

More information on Synaptic Labs' low risk technologies:

Your company currently uses open source and de facto security standards. You want to avoid getting out of step with the industry. You do not want to invest in a security product that may not win wider industry support. Synaptic Labs' technologies are designed to overcome these barriers to acceptance. Most of the enhancements made possible by our technologies can be easily won when you continue to exploit your existing security investments and industry standards!

For example, our key exchange solutions are simply a better way of using standards based cryptography to negotiate a new session key which can then be supplied to existing security standards for performing data protection operations. The underlying techniques employed in Synaptic’s key exchanges are known and trusted secure networking techniques. The inventive step is bringing the known techniques together in a way that overcomes limitations of more naive approaches. No new body of cryptographic theory is required to understand why the Synaptic solutions work. No complex quantum physics. No expensive fibre optic connections, or new network transceivers. No new communications infrastructure. More often than not, there is no need to change the hardware designs for devices that are currently being manufactured. Many devices can be upgraded in the field or by returning them to base.

If a particular Synaptic solution adds in a networking or cryptographic element alongside the existing standards solution then this extra element is itself derived from open sources that have been well studied and trusted. No new mathematical theory, no quantum physics, simply a conservative way of bringing together known and trusted techniques to build a superior and inventive solution. Synaptic solutions are suitable for small groups through to billions of users.

Lets provide an example: all the Synaptic key exchanges can be deployed using your current US NIST standards cryptographic algorithms such as AES-256 and SHA-512. Now that is a good start, let's go deeper. We used a derivative of well known networking and multi-path key exchange techniques ON A ONE TIME BASIS to ensure that your current asymmetric key exchange operation is performed in a manner that removes the need for any further key length upgrades and whereby even super computing power e.g. of a code breaking quantum computer, cannot be brought to bear against the asymmetric key exchange. As Professor Jacques Patarin says, the solution is simple, effective, suitable for universal applications such as eCommerce and the underlying cryptographic security can be easily argued from the strength of the trusted algorithms selected. Compare this to proposals for new public key algorithms, such as the recently accepted ECC algorithm, that required approximately a twenty year flawless security record based on intense global study before they can become trusted, or with quantum physics based solutions that need fibre optic direct links and expensive unproven hardware!

Synaptic techniques are low risk because they are based on a small incremental improvement on established cryptographic techniques and can use industry standards. So what other differentiators will Synaptic technologies provide?

Many. Lets use asymmetric algorithms and the Synaptic post quantum secure key exchanges as the example again. Existing PKI exchanges use asymmetric algorithms to negotiate a symmetric session key which is then used for high speed data protection operations. When you initialise with the Synaptic method it is unnecessary to use asymmetric algorithms again. Part of the reason is because we store the session key securely in hardware security modules such as smart cards. To satisfy standards you might choose to use asymmetric algorithms to generate each new session key, but this operation can be ‘protected’ by a layer of security using standards symmetric algorithms that are already accepted as long term (including post quantum) secure. In this way you can continue on with the stronger trusted US NIST algorithms, but with the advantage of knowing that when equivalently rated standards-based systems fail your data will remain secure.

In performance sensitive systems you can simply rely on the secret in the smart card and standards based symmetric techniques to negotiate new session keys faster and for less cost than existing PKI.

As a further incentive, the Synaptic key exchange techniques open a new opportunity for simple low risk 100 year secure identity-based encryption and secure email. That is, using the email address as the key, thereby simplifying key-management and reducing the cost of doing business.

So, with one simple added procedural step you can remove a) the risk of short to medium term decryption of your recorded data, b) remove the incentive for wait-and-see attacks, c) cost of periodic asymmetric algorithm key length upgrades, d) remove the risk of catastrophic failure resulting in a disruptive and inadequately planed rip and replace scenario should code breaking quantum computers arrive. Additionally you can to take advantage of new features to make your system FASTER and more efficient, and with new functions such as identity-based email. All this is achievable with a small enhancement to your existing standards based security investment. Your Customers should like those advantages! There are many other important differentiators, we have just pointed to a few. Here is one more. The Synaptic solutions can be deployed within an organisational unit, within a group of collaborators and wider groups without impacting negatively on the existing industry standards based operations.

Early adopters and collaborators win the opportunity to shape the universal deployment of Synaptic technologies with the added opportunity of potentially bidding in to the massive proposed Obama-Biden Homeland Security projects.

Some people believe that clever advances in physics such as quantum cryptography will create universal security solutions to overcome these recognized risks. While most people agree that the mathematical theory appears sound, the problem is achieving a secure reduction to practice - real world attacks plague quantum cryptography just like classical cryptography. The systems available on the market are not perfect. They are no more perfect than they are universal. Quantum Key Distribution requires line-of-sight lasers or optical fibre with expensive purpose-built hardware (USD 100K+ a pair) just for performing key exchanges. The proponents of QKD openly acknowledge that the technology is not suitable as a general purpose replacement for at risk public key cryptography.

Many cryptographic teams are attempting to find the “next” asymmetric cryptographic primitive that will achieve security against classical and quantum computers. The vast majority of these schemes have been quickly found to be insecure against classical computers. Elliptic Curve Cryptography took approximately 20 years of strong resistance against attacks before it could be trusted: even when it offered a 64:1 performance improvement over RSA to achieve a 256-bit classically secure rating. The reason for this is that asymmetric techniques are notoriously difficult to prove secure. New proposals have NOT withstood the necessary level of intense active global cryptographic study required to validate that line of approach. The comprehensive US ARDA report on the development roadmap for quantum computing claims that new quantum algorithms may emerge that would attack the 'hardness' property championed by many of these new schemes, including against McEliece schemes. Existing and candidate asymmetric cryptographic primitives cannot achieve the necessary level of assurance to provide 100 year security ratings with any confidence.

So why do we hear so much more about QKD than classical cryptographic approaches? The answer may lie in the vastly different financial backing received by the two different approaches. Quantum cryptography receives most of its funding as part of the over-all research into building code-breaking quantum computers. Ironically the lack of a hard date for the arrival of large code-breaking quantum computers has made it difficult in practice for the cryptographic community to coherently organise itself to begin addressing the long and hard open problems for building asymmetric cryptographic solutions.

What is clear is that the community needs to build commercially relevant high assurance systems that address the hard known security risks that are of great importance to our interconnected information society.

Synaptic Laboratories, as a privately funded organisation, has taken a lateral approach to solving the problem of building post quantum secure cryptographic systems. Instead of searching for a new 'hard' mathematical problem which may or may not be secure against classical and quantum computers, Synaptic successfully for a solution based on known strong symmetric cryptographic components. These strong symmetric components are based on established cryptographic techniques and hardware security modules to build the required functionality.

With conservatively large parameters supporting 256-bit security ratings against code-breaking quantum computers Synaptic can justifiably argue 100 year security ratings with high assurance. Who wants to go to the expense of deploying a new untrusted asymmetric algorithm that has not withstood the necessary global cryptographic study required when you could use the Synaptic techniques that are based on already trusted symmetric standards based cryptography?

Can you afford to run the risk with intrinsically complex solutions that have not withstood the necessary test of time and have NOT won the acceptance of the wider cryptographic community? Likewise, can you afford to wait and see if a better solution comes along?

It can take the commercial sector more than 10 years to migrate to a new cryptographic algorithm AFTER one is finally accepted and trusted as a new standard. In the meantime most secure data is being recorded, or is at risk of hacking, and it cannot then be retroactively made secure against advances in classical attacks or quantum computers when they arrive. Our modern information society is completely interdependent. Why ignore the risks when Synaptic offers a simple and effective risk management solution that guarantees business continuity and also makes OTHER system enhancers and product differentiators possible?

Apart from the increased assurance and other wins Synaptic technologies make possible they also offer an opportunity for UNIVERSAL global standardisation for 100 year post quantum security at low risk and low cost.

Let us explain why we see this vision. Firstly, the Synaptic solutions are designed for the full range of devices, ranging from Ambient Intelligence through to multi-gigabit communications. Secondly, the barriers to acceptance have been carefully addressed in a coherent manner from the beginning of the ecosystem design. Thirdly, we are exploring high assurance design processes that would enable the implementation of the technologies to be used in a global critical infrastructure project that may connect every building in the world.

Fourth, Synaptic have filed patents that cover the fundamental building blocks for: (a) creating a scalable many-to-many long term secure key exchange systems based on symmetric techniques and (b) efficiently accelerating the full suite of long term secure cryptographic operations on smart cards while remaining efficient on desktops. This patent foundation can become the basis of a uniform UNIVERSAL global deployment that is commercially viable and that avoids the risk of later needing to bridge disparate systems. We anticipate that industry and the open community will collaborate together to determine the most refined implementations.

We anticipate that Synaptic’s extensive use of existing and trusted cryptographic and networking techniques will enable the global community to rapidly converge the most optimal implementations of Synaptic Labs' technologies. The absence of a competitor with similar credentials makes the Synaptic solutions exciting.

 

The Synaptic (Enterprise/Universal) key exchange is a very attractive and very interesting proposal to resolve a major global problem. We are unaware of any symmetric key designs proposing to be suitable to replace public key cryptography in this way. We consider the design to be inspirational and really exciting. The Synaptic design relies on well studied cryptographic techniques and block ciphers and hash functions that are international standards and that are already accepted to offer post quantum security.

– Professors Jacques PATARIN and Louis GOUBIN.  Jacques and Louis are Professors in, and Jacques is Head of, the Cryptography Department in the PRiSM Research Laboratory, University of Versailles-Saint-Quentin-en-Yvelines (YUV) in France.  Both Jacques and Louis are expert security consultants to global corporations and are published inventors of several next-generation public key algorithms intended to be secure against quantum computer attacks. Therefore they were uniquely qualified to make the initial independent assessment of the Synaptic Labs model.

 
Add to: Facebook Add to: Mr. Wong Add to: Buzka Add to: Windows Live Add to: Ximmy Add to: Favoriten.de Add to: Social Bookmark Portal Add to: Bookmarks.cc Add to: Newskick Add to: Newsider Add to: Linksilo Add to: Readster Add to: Yigg Add to: Linkarena Add to: Digg Add to: Del.icoi.us Add to: Reddit Add to: Jumptags Add to: Upchuckr Add to: Simpy Add to: StumbleUpon Add to: Slashdot Add to: Netscape Add to: Furl Add to: Yahoo Add to: Blogmarks Add to: Diigo Add to: Technorati Add to: Newsvine Add to: Blinkbits Add to: Ma.Gnolia Add to: Netvouz Add to: Folkd Add to: Spurl Add to: Google Add to: Blinklist Information