Latest news
At RSA Conference 2013 in San Francisco, Allegro announced the addition of the FIPS 140-2 compliant Allegro Cryptography Engine (ACE) to the RomPager suite of embedded internet toolkits. Specifically engineered for the rigors of embedded computing, ACE makes embedding standards-based security protocols into resource sensitive embedded systems such as military, energy and healthcare embedded applications fast, easy and reliable while decreasing time to market.
Billions of embedded systems are quietly working behind the scenes of almost all modern technologies, from automobiles and factory floors, healthcare networks and new medical devices, defense and energy markets to space exploration missions. Increasingly, these critical embedded systems are built from commercial products, and often incorporate standards-based network connectivity.
Early networked desktop PCs and servers were unprepared to address the new security implications of network connectivity. The same is true for many of today’s embedded systems which presents a significant new security concern that must be addressed immediately and systematically.
Within the government, the National Institute of Standards and Technology (NIST) and National Security Agency (NSA) have taken steps to ensure security and compatibility between communicating computers by defining Federal Information Processing Standards (FIPS). Working together they have specifically identified a set of guidelines (FIPS 140-2) for cryptographic-based security systems to protect sensitive information in computer and telecommunication systems, whether desktop or embedded, and asserted the requirement that vendors must comply to these standards to sell and support the government or its contractors.
In addition to the government systems market, the FIPS 140-2 standards have been adopted by the financial (Check21, etc.), energy (Smart Grid) and healthcare (HIPAA, HITECH, etc.) industries to safe-guard their data.
ACE is a cryptographic library module specifically engineered to meet the needs of embedded computing systems in addition to fulfilling the requirements needed for FIPS 140-2 validation.
The module provides embedded systems developers with a common software interface to enable bulk encryption and decryption, message digests, digital signature creation and validation, and key generation and exchange.
In 2005, the NSA defined a set of cryptographic algorithms that when used together, are the preferred method for assuring the security and integrity of information passed over public networks such as the Internet. Today, Suite B is globally recognized as an advanced standard for cryptography that defines algorithms and strengths for encryption, hashing, calculating digital signatures and key exchange.
ACE includes a platform independent, government-certified implementation of the NSA Suite B defined suite of cryptographic algorithms.


Spotlight

The security of WordPress plugins
Posted on 18 June 2013. | Checkmarx’s research lab identified that more than 20% of the 50 most popular WordPress plugins are vulnerable to common Web attacks, such as SQL Injection.

Information security executives need to be strategic thinkers
Posted on 17 June 2013. | George Baker, the Director of Information Security at Exostar, talks about the challenges in working in a dynamic threat landscape, offers tips for aspiring infosec leaders, and more.

Large orgs in denial about own security breaches?
Posted on 14 June 2013. | Over two thirds (66%) of large organizations said they either had not experienced a security incident in the last 12-18 months or were unsure if they had.

Vulnerability scanning with PureCloud
Posted on 12 June 2013. | nCircle PureCloud is a cloud-based network security scanning product built upon the companies' vulnerability and risk management system IP360.

Reactions from the security community to the NSA spying scandal
Posted on 11 June 2013. | Read on for comments on this scandal that Help Net Security received from a variety of security professionals and analysts.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.







