An introduction
to cryptosoft
Cryptosoft is building trust in the Internet of Things and M2M by simplifying the
processes that a company needs to go through to deliver a robust, scalable and easy
to use policy based encryption service that operates within existing workflows.
Through the Cryptosoft platform, we provide our customers with dramatic and disruptive capabilities to secure their most important asset: their data, as it moves from device to device. Cryptosoft’s distributed agent architecture presents a single, simple abstraction of otherwise complex encryption and authentication methods, providing an opportunity to dramatically simplify and reduce the costs associated with solving modern day data security challenges. Cryptosoft directly addresses the universal challenge of securing information within an increasingly connected world to ensure integrity, privacy and compliance.seAmless end-to-end dAtA centric
security for every iot ecosystem
the mArket opportunity
Established big name security vendors have all done a pretty good job of making encryption services ubiquitous and easy for securing user initiated data such as email; what they haven’t
done is deliver an enterprise strength solution that simplifies the management and provisioning of security services into automated information flows. As a direct response many customers have
built their own management capability using a combination of third party toolsets and bespoke
coding. This approach does not scale, leaves organisations open to risk, and ultimately is not fit
for purpose.
cryptosoft fills A gAp in the mArket
Cryptosoft has responded to a gap in the market and delivers a data centric approach to
securing information within IoT, eliminating today’s dependency placed on inadequate transport
level security models. We do this without disrupting existing workflows or re-coding existing applications, using a standards-based platform that delivers same day value. We are completely hardware, software and security system agnostic providing ultimate flexibility for securing
information wherever it resides.
Many organisations have adopted Cryptosoft as the standard platform for provisioning Security as a Service within their IT ecosystem, shortening deployment times, simplifying architecture and reducing business risk.
the cryptosoft plAtform
Cryptosoft has been built from the ground up over the last three years based on our first hand experience of the
challenges faced by organisations to secure their information assets in an automated, transparent, scalable fashion. Cryptosoft is built on a proven technology foundation called Spring, which ensures we have the ability to offer an
unparalleled level of agility and flexibility in any given use case.
dAtA AdAptors
We believe security should revolve around the data that is why we make it easy for you to secure this all-important
asset, in storage and in transit. The key to this is our ability to transparently consume data payloads without
disrupting existing business processes or information workflows. Importantly, our distributed agent architecture
ensures this is achieved end to end.
restful Api’s
Our agents can consume data synchronously or asynchronously at the application layer via our simple REST API. Minimal configuration changes are required to securely wire an existing information flow using this method.
gAtewAy proxy
Our gateway agents process data transparently by proxying HTTP or MQTT protocols without impacting
performance (up to 10,000 connections per second introduces <2ms of latency with 1k payload), this includes encryption or decryption of the data.
file collectors
Where an API or gateway based approach is not feasible we also have the ability to collect data at a file system level using SMB, FTP or SFTP. Collection and delivery of data can also be facilitated directly into cloud based storage systems such as Amazon S3, Azure and Dropbox.
policy
Securing your data should be easy; Cryptosoft policies are central to making this happen by using simple rules to determine how your data is secured. Whether using our native web console or dynamically constructing policy from your own console
or application via our RESTful API, our platform makes this process simple and quick. Transparent, seamless deployment to
our distributed agents then ensures your data is secured end to end.
encryption & decryption
Although at the heart of what we deliver, Encryption and Decryption is simply a data transformation output from our
platform. Cryptosoft takes an agnostic approach to the use of encryption algorithms and security protocols. Wherever
possible we provide customer choice in the use of native algorithms providing transparency and flexibility in downstream
decryption of data.
Cryptosoft supports a number of symmetric and asymmetric key methods, from traditional
on-premise or managed PKI solutions through to a tightly coupled Dynamic Device Key Generation (DDKG) model that provides scale demanded by IoT deployments. Once again we believe customer choice is paramount given that significant
investments in this area may have already been made.
AuthenticAtion
Remember how the address space limitations of IPV4 threatened to grind Internet growth to a halt? Our current reliance on X.509 endpoint certificates has the potential to cripple IoT in the same way. The key management, deployment, expiration tracking and security vulnerabilities associated with static endpoint certificates make them untenable as a
scalable security solution for endpoint authentication and encryption for the estimated 50 billion devices that will be deployed by 2020.
For IoT growth, performance and scale, it requires a device authentication solution that eliminates the need for endpoint
certificate deployment and management. We can leverage advanced, M2M authentication to deliver on-the-fly key and certificate generation for mass-scale IoT deployments that eliminate theft and duplication vulnerabilities associated with static certs while preventing device spoofing and cloning.
plug & plAy
The Cryptosoft platform is ‘plug & play’ and eliminates the need for complex customised code to provision security to IoT applications and connected devices.
Quickly configured
The solution is up and running in a very short time frame with little upfront investment in technology infrastructure.
Best prActice ApproAch
Customer data traversing the network from device to device is
encrypted in a best practice, data-centric fashion. Customers can
focus on their core business whilst instantly reducing the attack surface for modern day threats.
compliAnce Achieved
Organisations are able to easily achieve compliance with the rapidly
evolving security legislation using Cryptosoft. Global brands remain
protected and outsider threats are mitigated. Using a single, standard based platform organisations are able to consolidate technologies and drive down costs.
flexiBle Business model
The Cryptosoft Platform’s API’s allow it to securely transfer data
to a broad range of different systems and services, allowing the
Provider to support different business models and SLA’s in a single
architecture.
stAndArdised And
repeAtABle ApproAch
The solution provides a simple and repeatable approach to solving data security problems of IoT projects by providing a standard approach to encryption and key management.