• No results found

Provable regulatory compliance!

N/A
N/A
Protected

Academic year: 2021

Share "Provable regulatory compliance!"

Copied!
39
0
0

Loading.... (view fulltext now)

Full text

(1)
(2)

Secure Cloud

Computing

(3)

Secure Cloud

Computing

Secure Cloud

Storage

(4)

The first complete security

solution that lets you

take advantage of Public Clouds

while

proving

compliance to

(5)

Encryption

Tokenization

Key Management

Cryptographic

hardware module

Fully integrated

Reduce scope of

compliance audits

Manage

trillions

of

keys/objects

Fully operational in

48 hours or less

FEATURES

(6)

BEFORE

KeyAppliance

System-1

Sensitive

Data

11001011010

System-4

Sensitive

Data

11001011010

System-2

Sensitive

Data

11001011010

System-5

Sensitive

Data

11001011010

System-3

Sensitive

Data

11001011010
(7)

System-1

Sensitive

Data

11001011010

System-1

Sensitive

Data

11001011010

System-1

Sensitive

Data

11001011010

System-1

Sensitive

Data

11001011010

System-1

Sensitive

Data

11001011010

Scope of PCI-DSS Audit

(8)

System-1

Sensitive

Data

11001011010

System-2

Sensitive

Data

11001011010

System-3

Sensitive

Data

11001011010

System-4

Sensitive

Data

11001011010

System-5

Sensitive

Data

11001011010

KeyAppliance

11001011010 11001011010

Scope of PCI-DSS Audit

(9)

8 GB DRAM

4 Core

64-bit CPU

certified HSM

Or TPM

Dual Gigabit

Ethernet

Automatic

Key Management

Split-Knowledge

Control

Highly

Available

Enterprise

Scalability

Simple

Webservice API

Active Directory

Integration

Graphical

Admin Console

LOWEST COST EKM

appliance.

GUARANTEED!

(10)

ARCHITECTURE

Crypto-Module

Internal DB 6 C/C++ Application Java Application Application Server 2 3 LDAP Server 4 5

Client Applications

7

Key Appliances

Crypto-Module

Internal DB 6 Application Server 2 3 LDAP Server 4 5 RPG Application Ruby/PHP Application

Network

1 7
(11)

SECURE CLOUD COMPUTING

E-COMMERCE –

PUBLIC CLOUD

Enterprise

Web

Application

CCN

Name

3

CCN

Token

4

Token

5

1

2

Customer ID

Billing Address

Phone

E-mail address

Order Detail

Customer ID

Name

Credit Card Number

Card Expiry Date

Card Verification Value

Amount

WebApp

Public Cloud

Customer ID

Billing Address

Phone

E-mail address

Order Detail

Token

(12)

SECURE CLOUD COMPUTING

E-COMMERCE -

VPDC

Enterprise

Web

Application

CCN

Name

3

CCN

Token

4

WebApp

Customer ID

Billing Address

Phone

E-mail address

Order Detail

Token

VPDC at

provider's

premises

Token

5

1

Customer ID

Name

Credit Card Number

Card Expiry Date

Card Verification Value

Amount

2

Customer ID

Billing Address

Phone

E-mail address

Order Detail

(13)

Encryption

Decryption

Key generation

Key escrow and

recovery on

StrongAuth

KeyAppliance

Automatically transfer

files to public clouds,

VPDC, NAS

Reduce cost of

storage infrastructure

FEATURES

(14)

Automatic

Key Management

Integration to

Public Clouds

Highly

Available

Enterprise

Scalability

Simple

Webservice API

Active Directory

Integration

Graphical

Interface

FEATURES

Java-based

Free and Open-Source Software

(15)

Ciphertext

Public

Cloud or

VPDC

C/C++/C# Application Java Application

Plaintext

5 1 1 2 4

Key

3

Private SAN or NAS

(16)

Ciphertext

Public

Cloud or

VPDC

C/C++/C# Application Java Application

Plaintext

1 5 5

Key

3

Private SAN or NAS

DECRYPTION MECHANICS

(17)

SECURE CLOUD COMPUTING

HEALTHCARE –

PUBLIC CLOUD

Hospital

Web

Application

PII Keys

2

PII

3

Tokens

7

X-Ray

8

Key

9

Token XENC File

10

5

PII

1

Patient ID Tokens Non-PII Data

XENC File WebApp

6

Lab

Patient ID Tokens Non-PII Data X-Ray Tokens

4

(18)

SECURE CLOUD COMPUTING

HEALTHCARE -

VPDC

Patient ID Tokens Non-PII Data

XENC File WebApp

VPDC at

provider's

premises

Hospital

Web

Application

PII Keys

2

PII

3

Tokens

7

X-Ray

8

Key

9

Token XENC File

10

5

PII

1

6

Lab

Patient ID Tokens Non-PII Data X-Ray Tokens

4

(19)

SECURE CLOUD COMPUTING

FOR E-COMMERCE

(20)

WebApp

Public Cloud

1

Customer ID

Billing Address

Phone

E-mail address

Order Detail

SECURE CLOUD COMPUTING

E-COMMERCE - 1

Customer ID

Billing Address

Phone

E-mail address

Order Detail

Enterprise

Web

Application

(21)

Enterprise

Web

Application

SECURE CLOUD COMPUTING

E-COMMERCE - 2

Customer ID

Name

Credit Card Number

Card Expiry Date

Card Verification Value

Amount

2

WebApp

Public Cloud

Customer ID

Billing Address

Phone

E-mail address

Order Detail

(22)

SECURE CLOUD COMPUTING

E-COMMERCE - 3

WebApp

Public Cloud

Customer ID

Billing Address

Phone

E-mail address

Order Detail

Enterprise

Web

Application

CCN

Name

3

CCN

(23)

SECURE CLOUD COMPUTING

E-COMMERCE - 4

WebApp

Public Cloud

Customer ID

Billing Address

Phone

E-mail address

Order Detail

Enterprise

Web

Application

CCN

Name

4

Token

(24)

Enterprise

Web

Application

CCN

Name

SECURE CLOUD COMPUTING

E-COMMERCE - 5

Token

5

WebApp

Public Cloud

Customer ID

Billing Address

Phone

E-mail address

Order Detail

Token

(25)

SECURE CLOUD COMPUTING

E-COMMERCE –

PUBLIC CLOUD

Enterprise

Web

Application

CCN

Name

3

CCN

Token

4

Token

5

1

2

Customer ID

Billing Address

Phone

E-mail address

Order Detail

Customer ID

Name

Credit Card Number

Card Expiry Date

Card Verification Value

Amount

WebApp

Public Cloud

Customer ID

Billing Address

Phone

E-mail address

Order Detail

Token

(26)

SECURE CLOUD COMPUTING

E-COMMERCE -

VPDC

Enterprise

Web

Application

CCN

Name

3

CCN

Token

4

WebApp

Customer ID

Billing Address

Phone

E-mail address

Order Detail

Token

VPDC at

provider's

premises

Token

5

1

Customer ID

Name

Credit Card Number

Card Expiry Date

Card Verification Value

Amount

2

Customer ID

Billing Address

Phone

E-mail address

Order Detail

(27)

SECURE CLOUD COMPUTING

FOR HEALTHCARE

(28)

SECURE CLOUD COMPUTING

HEALTHCARE - 1

Hospital

Web

Application

PII

1

WebApp

Lab

(29)

SECURE CLOUD COMPUTING

HEALTHCARE - 2

Hospital

Web

Application

2

PII WebApp

Lab

(30)

SECURE CLOUD COMPUTING

HEALTHCARE - 3

Hospital

Web

Application

PII

3

Tokens WebApp

Lab

(31)

SECURE CLOUD COMPUTING

HEALTHCARE - 4

Hospital

Web

Application

PII WebApp

Lab

Tokens

4

(32)

SECURE CLOUD COMPUTING

HEALTHCARE - 5

Hospital

Web

Application

PII

5

Patient ID Tokens Non-PII Data

XENC File WebApp

Lab

Patient ID Tokens Non-PII Data
(33)

SECURE CLOUD COMPUTING

HEALTHCARE - 6

Hospital

Web

Application

PII Patient ID Tokens Non-PII Data

XENC File WebApp

6

(34)

SECURE CLOUD COMPUTING

HEALTHCARE - 7

Radiograph:: Courtesy Diego Grez

Hospital

Web

Application

PII

7

X-Ray Patient ID Tokens Non-PII Data

XENC File WebApp

(35)

SECURE CLOUD COMPUTING

HEALTHCARE - 8

Hospital

Web

Application

PII

8

Key Patient ID Tokens Non-PII Data

XENC File WebApp

(36)

SECURE CLOUD COMPUTING

HEALTHCARE - 9

Hospital

Web

Application

PII Keys

9

Token Patient ID Tokens Non-PII Data

XENC File WebApp

(37)

SECURE CLOUD COMPUTING

HEALTHCARE - 10

Hospital

Web

Application

PII Keys XENC File

10

Patient ID Tokens Non-PII Data

XENC File WebApp

(38)

SECURE CLOUD COMPUTING

HEALTHCARE –

PUBLIC CLOUD

Radiograph:: Courtesy Diego Grez

Hospital

Web

Application

PII Keys

2

PII

3

Tokens

7

X-Ray

8

Key

9

Token XENC File

10

5

PII

1

Patient ID Tokens Non-PII Data

XENC File WebApp

6

Lab

Patient ID Tokens Non-PII Data X-Ray Tokens

4

(39)

SECURE CLOUD COMPUTING

HEALTHCARE –

VPDC

Patient ID Tokens Non-PII Data

XENC File WebApp

VPDC at

provider's

premises

Hospital

Web

Application

PII Keys

2

PII

3

Tokens

7

X-Ray

8

Key

9

Token XENC File

10

5

PII

1

6

Lab

Patient ID Tokens Non-PII Data X-Ray Tokens

4

References

Related documents

• Obtain as much information as possible: the credit card number, name of bank, full name, address, expiry date, CVV2/CVC2 and contact telephone number

This error appears when the address in the Billing Information section of the order entry form does not match the Card Verification Number (CVN) on file with the credit card

• The IVlcGili E-payment gateway transmits the creditjdebitjpre-paidcard information (credit card number, expiry date, card verification code or value) to the

In this case, the duration rule was not a very accurate measure of the sensitivity of bond prices, in the sense that for a 2% yield change, the duration rule underestimated the

This payment form will gather information from your customer such as the name displayed on their credit card, card number, expiration date, billing and shipping address, as well

Both the phone number and E-Mail address would be used by the credit card processor to contact you if there were a doubt about any credit card authorization.. For this reason it

Card-Not-Present fraud setting prompting merchant to key enter the street number and zip code for the customer’s billing address of the credit card.. Card-Not-Present fraud

We have determined that the information involved in this incident included customer name, credit or debit card number, card expiration date, CVV, email address, account