Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.


03:00 AM

Multivendor Management Locked Up

Key management partnerships have yet to deliver the goods

NeoScale has teamed up with Symantec, Optica Technologies, and Entrust in an attempt to make good on its promise to manage encryption keys from different vendors. But whether this initiative can develop quickly enough to satisfy user demand remains to be seen.

Optica, which makes mainframe connectivity devices, and software specialist Symantec have agreed to share their encryption keys with NeoScale's KeyVault device at a time when users are clamoring for better key management from their technology suppliers. (See All Keyed Up With NeoScale and NeoScale Centralizes Management.)

At this stage, however, it is still unclear exactly when users will actually be able to make use of the key sharing features promised by NeoScale et al.

For its part, Optica is expected to offer joint key management to its customers sometime later this year, although the company did not return Byte and Switch's call for comment. Symantec has given no indication of when its customers will be able to store their keys on KeyVault, which handles the encryption keys associated with NeoScale's own CryptoStor appliances.

Back in March, NeoScale claimed to be the first vendor to open up its key management APIs to third parties, though archrival Decru (now part of NetApp) followed suit four months later with a similar initiative centered on its Lifetime Key Management appliance. (See Decru Picks Key Partners and File Security Gets All Cryptic.) At that time, Decru announced partnerships with Symantec and Quantum to share encryption keys -- but the vendors are still working to integrate their products.

Meanwhile, faced with a slew of compliance pressures, firms are crying out for the ability to share keys across different devices. At the same time, they face a potential crisis regarding those keys. A recent Byte and Switch Insider report, "Storage Encryption: State of the Art," warned that problems surrounding the enforcement of encryption could, ironically, threaten the security of many organizations. If keys wind up being manually managed, which is increasingly common, gaps can arise that expose data to security holes and errors. (See Insider: Encryption Means Planning.)

Clearly, there is a pressing need for vendors to start turning their key management efforts from marketing hype into product reality. "Key management is a worrying issue," says an IT manager from a New York-based financial firm, who asked not to be named, adding that regulatory requirements are forcing him to encrypt more and more applications.

"A centralized repository would make it easier to manage keys," adds an IT director from a Connecticut-based HR services firm, who also asked not to be named. "If you need a key quickly, having [keys]in a central location will speed up that process."

Against this backdrop, both users interviewed by Byte and Switch said they want to see more than just a handful of vendors involved in key management efforts. "Ideally, we would want to see more offerings, because that increases the functionality [available to us]," explains the IT director.

"I would like to have multiple vendors involved in key management," adds the IT manager from the financial sector. "It's common sense, and it could even drive the price of key management products down."

"For users, the more choices they have for [key] integration, the better," agrees Jon Oltsik, senior analyst at the Enterprise Strategy Group. "There are millions of encryption keys spread across the enterprise."

Both NeoScale and Decru, however, haven't delivered the goods on announced partnerships, let alone unannounced ones. Still, both suppliers insist they are courting additional partners. (No names are offered.)

NeoScale VP of marketing Dore Rosenblum, for instance, claims the firm is working with "20 plus" vendors, including companies active in Information Lifecycle Management (ILM) and identity management. More partner announcements will be made "in the next quarter or so," he told Byte & Switch.

Over at Decru, Michele Borovac, the firm's director of marketing, says the vendor is "in discussion with many, many, other companies," around the issue of key management.

At this stage, NeoScale has three announced partners to Decru's two. As well as the key-sharing deals with Optica and Symantec, PKI specialist Entrust plans to import its digital certificates onto the KeyVault device as part of an effort to lock down users' internal security. "By working with Entrust, we're able to validate that the device connecting into KeyVault is the device that it says it is," explains Rosenblum.

In reality, however, the ability to validate network devices is still some way off. Although NeoScale customers can currently use Entrust certificates for authenticating users accessing the device via the Web, Rosenblum told Byte & Switch that authentication of other network devices will probably be available early next year.

— James Rogers, Senior Editor, Byte and Switch

  • Decru Inc.
  • The Enterprise Strategy Group (ESG)
  • Entrust Inc.
  • NeoScale Systems Inc.
  • Network Appliance Inc. (Nasdaq: NTAP)
  • Symantec Corp. (Nasdaq: SYMC)


    Recommended Reading:

    Comment  | 
    Print  | 
    More Insights
  • Comments
    Threaded  |  Newest First  |  Oldest First
    COVID-19: Latest Security News & Commentary
    Dark Reading Staff 8/3/2020
    'BootHole' Vulnerability Exposes Secure Boot Devices to Attack
    Kelly Sheridan, Staff Editor, Dark Reading,  7/29/2020
    Out-of-Date and Unsupported Cloud Workloads Continue as a Common Weakness
    Robert Lemos, Contributing Writer,  7/28/2020
    Register for Dark Reading Newsletters
    White Papers
    Cartoon Contest
    Current Issue
    Special Report: Computing's New Normal, a Dark Reading Perspective
    This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
    Flash Poll
    The Threat from the Internetand What Your Organization Can Do About It
    The Threat from the Internetand What Your Organization Can Do About It
    This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
    Twitter Feed
    Dark Reading - Bug Report
    Bug Report
    Enterprise Vulnerabilities
    From DHS/US-CERT's National Vulnerability Database
    PUBLISHED: 2020-08-03
    Wowza Streaming Engine through 2019-11-28 allows XSS (issue 1 of 2).
    PUBLISHED: 2020-08-03
    Wowza Streaming Engine through 2019-11-28 has Insecure Permissions.
    PUBLISHED: 2020-08-03
    IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
    PUBLISHED: 2020-08-03
    IBM Cognos Analytics 11.0 and 11.1 is vulnerable to privlege escalation where the "My schedules and subscriptions" page is visible and accessible to a less privileged user. IBM X-Force ID: 167449.
    PUBLISHED: 2020-08-03
    IBM Financial Transaction Manager 3.2.4 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 177839.