-
Read more...
"Many crypto-systems considered robust have been broken after a certain amount of time (between 10-20 years). ... We need to build crypto-systems that offer long term security, for example for protecting financial and medical information (medical information such as our DNA may be sensitive information with impact on our children, our grandchildren and beyond)."
SecurIST, “D3.3 – ICT Security & Dependability Research beyond 2010: Final Strategy”, January 2007 -
Read more...
“Systems built without requirements cannot fail; They merely offer surprises. Usually unpleasant!
Robert Morris, former Chief Scientist of the US National Security Agency (NSA), National Computer Security Center, 1995
-
"Dropping support for a broken crypto primitive is hard in practiceRead more...
- but crypto can be broken overnight
- what do we do if SHA-1 or RSA falls tomorrow?"
Alexander Sotirov, Marc Stevens, Jacob Appelbaum, Arjen Lenstra, David Molnar, Dag Arne Osvik, Benne de Wegerr, "MD5 considered harmful today - Creating a rogue CA certificate", December 2008
|
Synaptic Labs' Universal Security Ecosystem
The National Coordination Office (NCO) for Networking Information Technology Research and Development (NITRD), Federal Register: December 30, 2008 (Volume 73, Number 250).
Synaptic Laboratories Limited researchers have been privately funded over more than ten years to design a cross domain and Universal Security Ecosystem for the 21st century. The Synaptic Universal Security Ecosystem (S-USE) embraces a wide range of conservative and proven approaches to software and hardware security to confidently resolve existing and future known risks across multiple domains. It also includes a proposal for a new telecommunications infrastructure designed to retroactively secure today’s at-risk communications networks. Barriers to acceptance have been systematically addressed to encourage acceptance by both individuals and organisations. Adopting the S-USE can be non-disruptive, low cost and incremental. The S-USE is described as UNIVERSAL because each of its components have been designed as part of a unified design strategy that recognises that everything (people, devices, software) in our global village is interdependent and interconnected. To achieve universality the S-USE:
S-USE recognises our global interdependence and seeks to overcome the imbalances in existing security protocols that mistakenly protect the interests of one party or group while exposing a large number of stakeholders in the technology to increased cyber, financial, physical or psychological security risks. S-USE meets the data-longevity needs of personal communications, the sensitive information entrusted to or created by corporations and medical organisations, government administration, critical infrastructure and long term data archiving. For high assurance in our global village the security needs of the most security conscious individuals and organisations must be uniformly met across the interconnected web of networked organisations. Furthermore S-USE seeks to future-proof existing systems to manage the risks of old systems catastrophically failing and placing the community at risk. For example the deployment of weak components by ONE organisation has been shown to have the potential for direct consequence on the security of the GLOBAL system even when others are using strong components. A recent case example that clearly highlights this is the Certificate Authority attack (2009) that demonstrate this singular weakness / global impact on the Internet for e-commerce and e-banking today. The recommended deployment parameters for S-USE achieves data security with 100 year security ratings against all foreseen risks including optical, analog, quantum and DNA computing, while also using cryptographic primitives that have established trust in the global community. S-USE exploits the global investment into the US NIST standards ciphers such as AES, DES (within PQSDES) and SHA-2 while simultaneously supporting interoperability with up to 100 year security ratings in area constrained devices that today cannot run some of these algorithms efficiently. S-USE includes new cryptographic network protocols and cryptographic components that systematically address the weaknesses in the design of our existing systems to achieve new levels of security previously unattainable. Synaptic Labs' published protocols and algorithms are clearly defined, easy to understand, built on trusted well known components, and address the concerns of the international community to rapidly gain acceptance. Synaptic is VERY conscious of the need to minimise costs both in hardening existing security and in proposals for a new infrastructure. Our security software and hardware technologies protect and build on existing huge global investments into security standards that will otherwise eventually need to be abandoned and replaced. In many cases we can offer the alternative of replacing existing at-risk standards with more economical and functional alternatives. In many cases upgrades can be deployed in software without retooling or forced obsolescence of the billions of low-cost hardware devices deployed in the field. In many applications the cost of achieving the proposed benefits will be LESS than the cost of your current security solution with MORE functionality and better day-to-day performance. S-USE comprehensively addresses the known security risks to enable a solid cross domain platform. This solid platform will enable organisations to design application specific systems that manage application specific risks. The S-USE objective is for security to become less of a burden and for long term security to increasingly become, for most people, ubiquitous, transparent and virtually invisible. S-USE enables the security industry to deliver more on its promise to protect and assure the global community’s endeavours whereby organisations can more confidently focus on their core business. It is within this holistic context that Synaptic has designed (and is in the process of systematically completing, patenting and publishing) our ecosystem of cryptographic protocols and algorithms. As you read more about the technology components in the S-USE it will become increasingly clear how we are achieving these objectives in an incremental but universal and unified ecosystem. To learn more about the technology components in our security ecosystem organised by application domain click here. Further information on the unique selling points of the S-USE within the context of a secure collaboration platform can be read here [PDF]. |

Ecosystem