-
Read more...
"In the medium term, we need to be prepared for the eventuality that large quantum computers could be built: this would require an upgrade of most symmetric cryptographic algorithms and a completely new generation of public-key algorithms."
SecurIST, “D3.3 – ICT Security & Dependability Research beyond 2010: Final Strategy”, January 2007 -
Read more...
“Build-in Security: Ensure that security is considered and built into the design of new infrastructure, so that our critical assets are protected from the start and more resilient to naturally-occurring and deliberate threats throughout their life-cycle."
Obama-Biden Plan, Agenda: Homeland Security, December 2008
-
Read more...
"One should not assume that stakeholders do not care about their security merely because they do not understand the consequences of certain actions. The perception of risk can vary significantly from actual risk and, in the short term, convenience may lead some early adopters to make hazardous decisions."
SecurIST, “D3.3 – ICT Security & Dependability Research beyond 2010: Final Strategy”, January 2007

| Synaptic Identifier Based Encryption Technical |
TechnicalHow does it work?At its simplest level identifier based encryption is enabled by associating an email address with a smart card identity that has been enrolled in two or more online trusted third party servers. Similar to key exchanges performed over the Enterprise and Universal KX systems, a simplified description of the secure e-mail protocol on the Enterprise system may work as follows:
Additional improvements in performance, functionality and security are described in our related patent applications. How well studied are the cryptographic techniques used in the system?All the techniques in the system are well studied and familiar to most cryptographers. As illustrated above the system can be build using globally accepted cryptographic primitives such as AES-256 and SHA-2. Threshold secret schemes are mathematically very simple and are a mature area of research. For example split secret sharing schemes are used to manage today's mainstream public key certificate infrastructure. Many of the ad hoc mesh network protocols use multi-path key distribution techniques. How fast is the service?The performance of Synaptic Labs' Identifier Based Encryption in many applications is a one-off cost that is bound by the cost of network communications. After the contact details for an identity is discovered and a key exchange is performed, all the required information for ongoing direct communications is available to the smart cards. How does SIBE overcome the previous limitations of the competition?Traditional symmetric protocols for performing IBE, such as the Kerberos protocol, are known but suffer from the limitation that the online trusted server can decrypt all the messages and forge messages attributed to another identity. Modern asymmetric protocols which derive a public key and private key pair from an e-mail address also suffer from the same limitations, that is the online trusted server can decrypt all messages and forge messages attributed to another identity. The Synaptic Identifier Based Encryption (SIBE) is the world's first globally scalable scheme that prevents a collusion of (n-1) of the (n) participating, independently managed, online trusted servers from decrypting the sensitive messages sent between users of the system. Furthermore Synaptic Labs' is the first explicitly 10-to-100 year post quantum secure identifier based encryption proposal. The SIBE is a feature that extends Synaptic Labs' Enterprise and Universal Key Exchange protocols. The SIBE is designed for use on low-cost smart cards and network attached hardware security modules. Secure desktop communications are enabled through the use of smart cards that run the host Synaptic key exchange protocols. What is the minimum configuration?The minimum configuration of the Synaptic Identifier Based Encryption is two smart card clients, two relay servers implemented on two independently managed hardware security modules, SHA-256 and access to a small portable Faraday cage during smart card enrolment. How can I integrate SIBE with my existing system?Synaptic is developing an application programming interface, a simple secure tunnel protocol and a graphical user application around the Enterprise and Universal KX. These interfaces will support the SIBE functionality. Further InformationAdditional information is available via the menu bar on the right of the screen under the Identifier Based Encryption menu item. The Identifier Based Encryption functionality has been described in a paper published on ePrint. That paper is an extended version of a short 4 page peer reviewed technical abstract presented at the U.S. Oak Ridge National Laboratory - Cyber Security and Information Intelligence Research Workshop. Synaptic Laboratories and the Gozo Business Chamber (EU) have co-founded the ICT Gozo Malta cluster of excellence. This cluster of excellence will work in close collaboration with key Government and private stakeholders and leading International companies to develop many of Synaptic Labs' innovative technologies. The Identifier Based Encryption functionality will be implemented as part of the ICT Gozo Malta Global-scale Cyber Security project and Exoskeleton extensions. The relationships between projects is visually illustrated here. |
| Last Updated on Friday, 18 March 2011 09:36 |

