• Florence Luy asks the question: "Is the writing on the wall for 1024-bit (RSA) encryption?"
    Dutch mathematician Hendrik Willem Lenstra: "The answer to that question is an unqualified yes."

    Florence Luy, Hendrik Lenstra, “A mighty number falls”, 21 May 2007, École Polytechnicque Fédérale de Lausanne

    Read more...
  • “Briefly and simply, assurance work makes a user or a creditor more confident that the system works as intended without flaws, without surprises, even in the presence of malice.” … “The major shortfall is absence of assurance or safety mechanisms in software.  If my car crashed as often as my computer does, I’d be dead by now.”

    Brian Snow, Former Technical Director of the US National Security Agency (NSA), "We need Assurance", AusCERT 2008

    Read more...
  • "Today’s systems must anticipate future attacks. Any comprehensive system – whether for authenticated communications, secure data storage, or electronic commerce – is likely to remain in use for five years or more. It must be able to withstand the future: smarter attackers, more computational power, and greater incentives to subvert a widespread system. There won’t be time to upgrade it in the field."

    Bruce Schneier, "Why Cryptography Is Harder Than It Looks", 1997
    Read more...
Home Proposals Assure Token home
Synaptic Assure Token Home

Achieve long-term information security with Synaptic Labs' Assure enabled smart card tokens!

Synaptic Labs' Assure line of security technologies will exploit the hardened processing environment of smart cards to deliver unprecedented levels of security to end-users and organisations:

  • Smart cards provide peace of mind and convenience for the card-holder by allowing them to safely transport their security and identity credentials from one machine to another.  The critical security operations will be performed entirely within the safety of the smart card, thereby preventing potential exposure on a compromised machine.  This limits the duration of exposure as a result of a security breach, for example when a card holder checks their e-mail on a compromised/hacked office computer.   When the card-holder removes the card, the ongoing security for that card holder is restored.
  • Smart cards provide peace of mind for security managers by providing assurances that all their users, and the users of every other organisation using Assure technologies have a common base-line level of security with respect to ID and Privacy management. Security managers can provide greater assurances to their organisations, for example when their users securely communicate using Assure technologies with contractors of an independent organisation that the risk of unintended identity theft and data exposure has been minimised.
  • Synaptic Assure enabled smart card tokens will automatically support all Assure enabled Applications.  An Assure Token purchased for use with Assure VPN Exoskeleton will automatically work with Assure SSL/TLS Exoskeleton.  A user does not require multiple smart cards.
  • Synaptic scalable technologies exploit pre-shared symmetric keys that offer greater security per bit than asymmetric key technologies (that do not rely on pre-shared secrets).  The symmetric techniques used by Synaptic will remain secure against currently anticipated quantum computing algorithms that may be developed in the near future.
  • Smart cards provide a secure platform for receiving symmetric secrets from several independent security service providers. These security providers enable high-assurance key exchange and identity operations to be performed between a practically unlimited number of users (Synaptic Enterprise and Universal key exchanges).  The use of multiple independent service providers prevents against single points of security failure compromising the security of users of Synaptic Labs' Assure technologies.
  • The use of online key exchange servers allows for future and backwards interoperability between devices running different versions of the Assure protocols.
  • Organisations will be able to run their own key-exchange server and set policies that enforce strict access control and auditing of all secure communications.  The design should enable all smart cards managed by that organisation to be instructed to check the latest security compliance rules for every security operation, ensuring real-time visibility and strict access control measures. This 'centralised' auditing mechanism should be available for all Assure products.
  • Strict security policies will be enforced by the trusted Assure software installed on the smart card.  It is not possible to 'disable' auditing by compromising the host machine the smart card is connected to.  This feature is important in enterprise environments.

 


Last Updated on Friday, 12 June 2009 14:48