• No results found

IT-Security News Data theft damage amounting to millions

N/A
N/A
Protected

Academic year: 2021

Share "IT-Security News Data theft damage amounting to millions"

Copied!
28
0
0

Loading.... (view fulltext now)

Full text

(1)

IT-Security News

Data theft damage

amounting to millions

Mobile Data Security now even

safer, faster and more robust

A lot of companies and authorities are

conscious about dangers and risks

unsecured data storage devices can

bring. However, the existing security

solutions are usually not well known or

available encryption technologies are

not used because they are too

compli-cated and complex.

With the DIGITTRADE High Security

HDD / SSD HS256 S3 these problems

belong to the past.

An easy operation combined with the

utmost security as a fast USB 3.0 port

and a durable aluminum enclosure

make the HS256 S3 to the most

secure portable storage

device on the market...

The theft of mobile devices is booming.

According to a study of the market

research institute IDC do 92% of all

European companies have lost a

note-book with data by theft at least once.

The damage from such a theft is higher

by a multiple than the replacement of

the hardware. In addition to the big

loss of image are sensitive financial

damage direct consequences.

The Ministry of Health of Alaska

recently had to pay a penalty equivalent

to € 1.37 million because unkown

persons had stolen an unsecured USB

hard drive with data from over 500

patients from the car of an employee.

Each data loss costs average 3.4 million

euros ...

Simple and extremely secure

-the newest external hard drive

HS256 S3 with two cryptographic

keys, sturdy

(2)

Secure encrypted data

Encryption Access Control

Security HDD

XOR encryption

128 bit AES in ECB mode

256 bit AES in CBC mode

256 bit AES in XTS mode

RFID token

fingerprint reader

enter password by keyboard

PIN

smart card + PIN

Who generated it?

Where is it stored?

How can it be destroyed?

1-2-3-4-5-6-7-8 smart card + 8-digit PIN Authentication ...invoice.pdf crm.sql... ...emails.pst fina... ...J!$T%ä... ...u%r\I6... Hardware Crypto-Engine totally encrypted or RFID key

(3)

The most important criteria

Data privacy and data security are extremely sensitive subjects for companies and government. Again and again, business pro-cesses requires the mobile availability of research, financial, customer and account information. For the storage and the transport of the data a company must be able to rely on absolute security. To ensure this, the main criteria are:

Encryption

The choice of an appropriate encryption is essential for data security. For high standards of data security, it is recommended to use at least an AES encryption with a key length of 256 bit in CBC or XTS mode.

Access control

The access control can range from a simple password to complex multi-factor authentication methods. A complex access method with a two-factor authentication (e.g. with smartcard and PIN) offers a very high level of data security.

Administration of the cryptographic key

It should be known, how the cryptographic key was produced and if during the production or on the way to the user a copy of the key could be made. It‘s also important to know where and how safe the key is stored for use. In addition it should be checked if the cryptographic key can be destroyed if necessary. Highest security provides storage devices where the cryptographic key is stored externally and the user can create, change and destroy the key himself.

(4)

Unique selling points of the DIGITTRADE security storage devices

• widest portfolio of encrypted storage devices including high secure external HDD/SSD • the storage devices are aligned for different security requirements

• variety range: from a secure basic solution for private user to professional solutions for

compa-nies and government

(5)

Overview of the DIGITTRADE security storage devices

The DIGITTRADE GmbH develops and produces external hard drives, SSDs and USB sticks with hardware encryption to protect business and private data extensively and protectetd against unauthorized access.

DIGITTRADE USB Security Stick USS256 – Secure solution for companies and private user

Access control and protection by password, 256 bit AES hardware encryption in CFB mode, encrypted storage of the AES key in the flash memory

DIGITTRADE RFID Security HDD/SSD RS64 - Secure basic protection for private user

Triple protection for your data: RFID access control, XOR hardware encryption, S.M.A.R.T. lock HDD lock, encrypted storing of the cryptographic key on the HDD

DIGITTRADE RFID Security HDD/SSD RS128 – Secure solution for private user

RFID access control, 128 bit AES full disk hardware encryption in advanced ECB mode, encrypted storing of the cryptographic key on the HDD

DIGITTRADE RFID Security HDD/SSD RS256 – Secure solution for companies and private user

(6)

Unique selling points of the DIGITTRADE security storage devices

• governmental certified products: BSI, ULD and EuroPriSe data privacy seals

(7)

Overview of the DIGITTRADE security storage devices

DIGITTRADE High Security HDD/SSD HS128 and HS256 – Professional solution for companies

2-factor authentication by smartcard and PIN code, certified full disk hardware encryption according 128 bit AES in ECB mode or 256 bit AES in CBC mode, external and encrypted storing of the cryptographic key on the smartcard

DIGITTRADE High Security HDD/SSD HS256S – Professional solution for government and companies

Further development of the DIGITTRADE HS256 - certified with ULD- and EuroPriSe privacy seal - provides the possibility to ad-ministrate the cryptographic key by the user (create, change, copy and destroy at risk). Complete hardware encryption of all data with 256 bit AES in CBC mode. All security features are completely integrated into the hard drive.

DIGITTRADE High Security HDD/SSD HS256 S3 – Professional solution for government and companies

(8)

DIGITTRADE USB Security Stick USS256

secure solution for companies and private user

Features:

• access control by password

• 256 bit AES hardware encryption in CFB mode • encrypted storing of the AES key in the flash

memory

• epoxide resin case protects the hardware against humidity and manipulations

• password misentry count is choose freely • automatically delete of data after preset number

of failed attempts of password entries is reached • indicator for password security

• write protection switch for safe usage on other computer

• “plug & play“- for all Windows OS with USB 1.1 and 2.0

• up to 16 GB storage space • 2 years guarantee

(9)

DIGITTRADE USB Security Stick USS256

destruction mechanism. If an unauthorized access occurs and a preset number of failed attempts of password entries is reached, the data stored on the stick will be destroyed and the USS256 will reset to factory defaults.

The epoxide resin case protects the hardware against humidity and manipulations.

With the DIGITTRADE USB Security Stick USS256 it‘s a waltz to guarantee a high level of security for your data.

This data storage medium

impres-ses with its elegant and robust design.

The USS256 offers a storage capacity of up to 16 GB. Due to its numerous security features this stick offers a high degree of security for your data.

At home, at the office or during transport the USS256 protects your sensitive data against unwanted looks. All data is stored by a 256 bit encryption according to AES in CFB mode. Thereby all data are protected from unwanted views even in case of loss of the device.

The integrated high-speed AES hardware-based encrypti-on module operates independently of any software and is resistant to cold boot and similar attacks. The authentica-tion works by password entry.

(10)

DIGITTRADE RFID Security HDD RS64

secure basic protection for private user

Features:

• RFID access control

• XOR full disk hardware encryption

• S.M.A.R.T. lock HDD lock (it activates an ATA password which prevents a readout of the HDD outside of the security enclosure)

• encrypted storing of the cryptographic key on the HDD

• no access to the DIGITTRADE Security HDD and your data without one of the two included RFID key

• all data will be stored automatically encrypted from the hardware encryption module in real-time

• bootable and independent from operating sys-tem

• compatible to USB 1.1 and 2.0

• available with 500GB, 1TB & 2TB as HDD and 120GB, 250GB, 500GB & 1TB as SSD

(11)

The user authentication take place by RFID access control with the included RFID keys. To lock or unlock the DIGITTRADE RS64 just keep the RFID key over the RFID reading device integrated in the HDD.

Thanks to the combination of the hardware-based

encryption module and RFID access control the security storage device works independent from any operating sys-tem and is usable flexible.

All data stored on the DIGIT-TRADE RS64, is protected against unauthorized access by three essential safety measures. The combination of data encryp-tion, S.M.A.R.T. lock and RFID access control offers private users and small companies a secure basic protection for mobile data.

The integrated hardware encryption module stores data en-crypted and in real-time.

The S.M.A.R.T. lock function is automatically activated, if the HDD is removed from the enclosure, turns off or locked by the RFID key. In this case an ATA password will allocates independently to prevent a readout of the HDD outside the enclosure. The ATA password is not stored at any time and therefore it can‘t readout. The unauthorized access to your data will be aggravated significantly.

(12)

DIGITTRADE RFID Security HDD RS128

secure solution for private user

Features:

• RFID access control

• 128 bit AES full disk hardware encryption in advan-ced ECB mode

• encrypted storing of the AES key on the HDD • no access to the DIGITTRADE Security HDD and

your data without one of the two included RFID key • all data will be stored automatically encrypted

from the hardware encryption module in real-time

• bootable and independent from operating system

• compatible to USB 1.1 and 2.0

• mini USB and integrated USB connector • available with 500GB, 1TB & 2TB as HDD and

(13)

DIGITTRADE RFID Security external HDD/SSD RS128

Thanks to the combination of the hardware-based

encryption module and RFID access control the security storage device works independent from any operating sys-tem and is usable flexible.

The DIGITTRADE RS128 RFID Security HDD protects private and business data reliable against

unwanted looks security, whether at home, at the office or during transport.

The encryption of all data take place with 128 bit AES in ad-vanced ECB mode. In the process every sector is encrypted with a new AES indicator.

The integrated hardware encryption module stores data encrypted and in real-time.

The user authentication take place by RFID access control with the included RFID keys. To lock or unlock the DIGITTRADE RS128 just hold the RFID key over the RFID reading device integrated in the HDD.

(14)

DIGITTRADE RFID Security HDD RS256

secure solution for companies and private user

Features:

• RFID access control

• 256 bit AES full disk hardware encryption in XTS mode

• encrypted storing of the AES key on the HDD • no access to the DIGITTRADE RFID Security HDD

and your data without one of the two included RFID key

• all data will be stored automatically encrypted from the hardware encryption module in real-time

• integrated silicone Anti-Shock protectors

• sturdy aluminium enclosure protects for electronic and mechanical influences

• bootable and independent from operating system • compatible with USB 3.0 and 2.0

• available with 500GB, 1TB & 2TB as HDD and 120GB, 250GB, 500GB & 1TB as SSD

(15)

The data transmission and power supply can be made via a fast USB 3.0 connection.

Thanks to the combination of the hardware-based

encryption module and RFID access control the security storage device works independent from any operating sys-tem and is usable flexible.

The DIGITTRADE RFID Security HDD RS256 is a secure so-lution for companies and private user.

The computer magazine CHIP appreciated the mobile RFID Security HDD with the test result „excellent“ (6/2012) and the PC WELT magazine has choosen the RS256 to the award winner and the „best 2.5-inch hard drive with USB 3.0“ (7/2012).

All data on the DIGITTRADE RS256 is stored by a 256 bit full disk encryption according to AES in XTS mode. The integrated hardware encryption module stores all data encrypted and in real-time.

The user authentication take place by RFID access control too. Thereby the access is only with one of the two inclu-ded RFID keys possible.

In addition the smart and sturdy aluminium enclosure pro-tects the RS256 against electrical and mechanical influen-ces. The specially developed silicone protectors increase the resistence against to concussions and impacts.

(16)

DIGITTRADE High Security HDD HS128/HS256

professional solution for companies

Certified by The National Institute of Standards and Technology of the United States of America (NIST)

Features:

• 2-factor authentication by smart card and 8-digit PIN code

• certified full disk hardware encryption according to AES 128 bit in ECB mode or AES 256 bit in CBC mode

• external and encrypted storing of the crypto-graphic key on the smart card (prevents readout of the key from the HDD)

• access protection onto the smart card with the 8-digit PIN

• all data will be stored automatically encrypted from the hardware encryption module in real-time

• bootable and independent from operating system

• compatible with USB 1.1, USB 2.0 and FireWire 100 / 200 / 400 / 800

• available with 500GB, 1TB & 2TB as HDD and 120GB, 250GB, 500GB & 1TB as SSD

(17)

the DIGITTRADE HIGH SECURITY HDD combines the be-nefits of mobile data media with highest security standard for data privacy.

The DIGITTRADE High Security HDDs/SSDs uses the worldwide unique 2-factor authentication to access to the data. The 2-factor authentication works according to the “having and knowing“ principle:

Factor 1 (Having): verifies, if the user has a smart card with the correct AES key. This verifi cation is done by inserting the smartcard into the hard drive enclosure.

Factor 2 (Knowing): verifies, if the user knows the correct 8-digit PIN and consequently is authorized to use this smart card. This verification is done by enter the 8-digit PIN. In case of any manipulation the smart card will be irrevo-cably destroyed and disabled. In that case the access to the data is prevented.

If the HS128/HS256 was successful unlocked by smart card and PIN, the data is transmitted as a normal hard disk – without loss of time or an additional program.

Thanks to the full disk hardware encryption according to the AES and the two-factor authentication,

(18)

DIGITTRADE High Security HDD HS256S

professional solution for government and companies

Certified by the Independent Centre for Privacy Protection Schleswig-Holstein with the ULD and the European Data Privacy Seal EuroPriSe

Features:

• 2-factor authentication by smart card and 8-digit PIN code

• 256 bit AES full disk hardware encryption in CBC mode

• external and encrypted storing of the crypto-graphic key on the smart card

• administration of the cryptographic key by the user (create, copy, change and destroy at risk) • access protection onto the smart card with the

8-digit PIN

• smart card NXP J3D081 v2.4.2 R2 certified by BSI according to EAL5

(Certification ID: BSI-DSZ-CC-0784-2013) • bootable and independent from operating system

• compatible with USB 1.1, USB 2.0 and FireWire 100 / 200 / 400 / 800

• available with 500GB, 1TB & 2TB as HDD and 120GB, 250GB, 500GB & 1TB as SSD

(19)

DIGITTRADE High Security external HDD/SSD HS256S

The DIGITTRADE High Security HS256S is Europe‘s first external hard drive that has the ULD Privacy Seal and Eu-ropean Privacy Seal. Thus, it is currently the only existing external hard drive, which is approved for the storage of personal data and facilitates the data protection use accor-ding to the Federal Data Protection Act. In addition, it has been developed in accordance with the latest requirements of the Federal Office for Information Security (BSI) to porta-ble storage media devices.

The stored data are as to the privacy of them safe from access of unauthorized persons, even if the DIGITTRADE HS256S got stolen, lost or misplaced and also during logi-cal and physilogi-cal attacks on them.

The DIGITTRADE HS256S ensures the privacy of the stored data with these security features:

- Encryption - Access control

- Administration of the cryptographic key

Besides the proven 256 bit AES hardware encryption in CBC mode and the 2-factor authentication by smart card and PIN the HS256S provides the ability to administrate the cryptographic key directly on the device independent from your computer or software. The user is able to do the fol-lowing things with the cryptographic key: create, change, copy and destroy at risk.

The cryptographic key which is needed to de- and encrypt is created and stored encrypted on the smart card. In that case the cryptographic key is physically separated from the stored data. Therefore it‘s impossible to read it out or to decrypt the stored data.

(20)

DIGITTRADE High Security HDD HS256 S3

professional solution for government and companies

In certification process by the Federal Office for Information Security (BSI) according to Common Criteria with EAL2

Features:

• 2-factor authentication by smart card and 8-digit PIN code

• 256 bit AES full disk hardware encryption in XTS mode with two cryptographic keys • external and encrypted storing of the

crypto-graphic keys on the smart card

• administration of the cryptographic keys by the user (create, copy, change and destroy at risk) • access protection onto the smart card with the

8-digit PIN

• smart card NXP J3D081 v2.4.2 R2 certified by BSI according to EAL5

(Certification ID: BSI-DSZ-CC-0784-2013) • elegant and sturdy aluminum enclosure • bootable and independent from operating system

• compatible with USB 3.0 & USB 2.0

• available with 500GB, 1TB & 2TB as HDD and 120GB, 250GB, 500GB & 1TB as SSD

(21)

DIGITTRADE High Security external HDD/SSD HS256 S3

The DIGITTRADE High Security HS256 S3 is the further de-velopment of the DIGITTRADE HS256S and is safer, faster and more robust due to their properties.

It was developed in accordance with the latest require-ments of the Federal Office for Information Security (BSI) to portable storage devices and is in the certification process by Commom Criteria EAL2.

The stored data are as to the privacy of them safe from access of unauthorized persons, even if the DIGITTRADE HS256 S3 got stolen, lost or misplaced and also during lo-gical and physical attacks on them.

The DIGITTRADE HS256 S3 ensures the privacy of the stored data with these security features:

- Encryption - Access control

- Administration of the cryptographic key

Besides the proven 2-factor authentication by smart card and PIN all data are stored with 256 bit AES in XTS mode encrypted with two cryptographic keys.

In addition the HS256 S3 also offers the ability to admi-nistrate the two cryptographic keys directly on the device independent from your computer or software. The user is able to do the following things with the cryptographic keys: create, change, copy and destroy at risk.

The cryptographic keys which are needed to de- and enc-rypt are created and stored encenc-rypted on the smart card. In that case the cryptographic keys are physically separated from the stored data. Therefore it‘s impossible to read it out or to decrypt the stored data.

In addition, the HS256 S3 has an elegant and sturdy alumi-num enclosure which protects them well against mecha-nical influences and electromagnetic waves and improves the resistance to vibration and shock.

(22)

DIGITTRADE Smartcard Manager 2

Administration software for High Security hard drives,

smart cards and users

Features:

• Central:

Administration of all High Security HDD/SSD • All in One:

Registration of all users, smart cards and hard drives in the company

• Manageable:

Illustration of the whole company structur

System requirements:

Operating system: minimum Win Vista SP2 CPU: minimum 1.0 GHz for x86

or 1.4 GHz for x64

RAM: minimum 512 MB

Hard drive space: minimum 100 MB

Software: Microsoft® SQL Server 2012

Express LocalDB & Microsoft®

(23)

DIGITTRADE Smartcard Manager 2

With the DIGITTRADE Smartcard Manager 2 you keep a central overview of all used DIGITTRADE High Security dri-ves, smart cards and cryptographic keys. By the illustration of the company structure employees, departments and lo-cations can be assigned to the particular information.

(24)

Examples special application possibilities of the HS256S & HS256 S3:

• Secure and cheap data transport:

If sensitive data should get from one location to another location it is possible to send the HS256 S3 easily by post. The matching smart cards are lodged at the sender and the receiver of the data, the PIN is known by both. If the HS256 S3 get lost while the transport no one is able to access to the data because the cryptographic key is not available and only on the smart cards.

(25)

Multiple application possibilities of the DIGITTRADE security storage devices

Safe shipping with security bags

To avoid manipulation during shipping, there is the possibi-lity to use a special security bag from DIGITTRADE. These bags have special safety indicators which displays manipu-lation attempts by cold, heat and solvents.

Travelling and outside appointment

Because of the full disk hardware encryption no one will be able to access to data if the security storage device gets lost.

Business secret

It is possible to control which persons are able to access to the security storage devices by selective handover of the authentication features (smart card and PIN, RFID-key).

Data security against break-in

There is no access to the encrypted data if somebody breaks-in at the office.

Bootable

All data, programs and operating software can be saved and started directly from the security storage device. No tracks remain on the used PC or Laptop.

Independent from operating systems

Because of the hardware encryption the security storage device can be used on every device that supports USB (computer, multimedia devices, machines etc.)

Hardwareverschlüsselte Speichermedien

RFID Security RS128 externe USB HDD / SSD

Security USB Stick USS256 High Security HS256S externe USB HDD / SSD

High Security HS128 externe USB HDD / SSD

DIGITTRADE SECURITY DIGITTRADE SECURITY DIGITTRADE SECURITY DIGITTRADE SECURITY DIGITTRADE SECURITY DIGITTRADE SECURITY DIGITTRADE SECURITY

40

1V0002343 DIGITTRADE SECURITY DIGITTRADE SECURITY DIGITTRADE SECURITY DIGITTRADE

SECURITY DIGITTRADE SECURITY DIGITTRADE SECURITY DIGITTRADE SECURITY

DIGITTRADE

DIGITTRADE SECURITY DIGITTRADE SECURITY DIGITTRADE SECURITY DIGITTRADE SECURITY

DIGITTRADE SECURITY DIGITTRADE SECURITY DIGITTRADE SECURITY DIGITTRADE SECURITY

Stellen Sie sicher, dass diese Sicherheitsverpackung unbeschädigt ist. Bei Beschädigungen kontaktieren Sie bitte Ihren Verkäufer. Please make sure that the security packaging is undamaged.

If it is damaged, please contact your supplier.

Produktname / product

(26)

Service and Support

DIGITTRADE GmbH

Ernst-Thälmann-Str. 39

06179 Teutschenthal

Web:

www.digittrade.de

Phone:

+49 / 345 / 2 31 73 53

Fax:

+49 / 345 / 6 13 86 97

E-Mail:

support

@

digittrade.de

DIGITTRADE is member of the Federal Association for Information Technology,

Telecommunications and New Media (BITKOM) as well as in the IT Security

Association Germany (TeleTrusT)

(27)
(28)

The loss of costumer data can be expensive

The German Federal Data

Protection Act (BDSG)

implement the DIRECTIVE 95/46/EC

of the European Parliament and of the

Council of 24 October 1995 “on the

protection of individuals with regard to

the processing of personal data and on

the free movement of such data” into

the German law and control together

with the data protection acts of the

federal states the handling of personal

data which are processed manually or

in IT systems.

§ 42a Obligation to notify in

case of unlawful access to

data

In case of unlawfully disclosed data to

third parties the private body shall

notify the competent supervisory and

the data subjects without delay. Such

notification may be replaced by public

advertisements of at least one-half

page in at least two national daily

newspapers.

174 million stolen data in

2012!

174 million data - the second highest

amount of stolen data since 2004. This

is a result of 855 reported delicts from

2011 to 2012.

§ 823 (1) BGB

Liability in damages

A person who, intentionally or

negli-gently unlawfully injures the life, body,

health, freedom, property or another

right of another person is liable to

make compensation to the other party

for the damage arising from this.

§ 43 (3) BDSG Provision

concerning fines

Administrative offences may be

puni-shed by a fine of up to € 50,000 in the

case of subsection 1, and a fine of up to

€ 300,000 in the cases of sub-section 2.

§ 9 BDSG Technical and

organizational measures

All kind of data must be protected in a

sufficient degree against loss,

manipu-lation and danger.

§ 7 BDSG Compensation

If a controller harms a data subject

through collection, processing or use of

his or her personal data which is

unla-wful or improper under this Act or

other data protection provisions, the

controller or its supporting

organizati-on shall be obligated to compensate the

§ 44 (1) BDSG

Criminal offences

References

Related documents

prospective trial comparing autologous bone marrow transplantation with conventional chemotherapy, five-year overall survival favored the transplant group (52%

Rigshospitalet, Copenhagen, Denmark; Karolinska Institutet, Stockholm, Sweden; Genmab A/S, Copenhagen, Denmark; Dana-Farber Cancer Institute, Boston, MA, USA... • Genmab:

'’"According to Carl Brun, by adopting an insider perspective, the researcher gains direct interaction with the topic w hich is being researched and with

Decide which party or person you want to vote for on the peach voting paper. Decide which person you want to vote for on the purple

During the year under review, the company did not receive any notices within the meaning of Section 15a of the WpHG (Directors’ Dealings). In addition to the disclosure

When producing at the clinker benchmark level in terms of clinker carbon intensity (B K =766 kgCO 2 per ton of clinker), changing the clinker ratio or the clinker import ratio has

Existing financial institutions which develop carbon finance business, such as Societe Generale, Agricultural Bank, Bank of Beijing, Shanghai Pudong Development Bank, etc., which

Objectives: The aim of this article was to explore the extent to which wheelchair service delivery in a rural, remote area of South Africa was aligned with the