Patrick Townsend & Associates has announced that it has successfully completed the NIST AES validation certification of its Alliance AES Encryption products that run on a variety of enterprise server platforms. The certification covered every NIST-approved encryption key size, and every NIST-approved mode of encryption, on nine enterprise server platforms including Windows, Linux, UNIX, IBM iSeries/System i, and IBM zSeries mainframe. The result is a suite of certified AES encryption solutions that work on heterogeneous operating systems, help insure confidence in enterprise data protection efforts, and interoperate with customer and vendor data encryption solutions.
As enterprise customers struggle to meet data security regulations, they encounter numerous problems of compatibility between different encryption solutions. Aggravating these concerns is the need to evaluate different vendor claims about their encryption solutions. Customers ask, are solutions really secure? Will they work with other vendor solutions? Will the vendor be able to stand behind us in the event of a loss? The NIST AES certification process helps answer these questions, and the Alliance AES encryption solutions have met the rigorous testing requirements of the NIST AES Validation process.
Patrick Townsend, President of Patrick Townsend & Associates, says, "In the rush to meet PCI and privacy notification regulations, enterprise customers are finding it difficult to evaluate vendor solutions. The NIST AES validation program is one way customers can build confidence in a vendor's encryption solution. The testing and validation process is carried out by an independent testing lab, and approved by NIST. By certifying Alliance AES encryption on all key sizes and modes of encryption, and on all of the major enterprise server platforms, we provide the confidence that our customers need in an encryption solution."
Companies are often cast into a chaotic state when a data loss occurs. IT staff need to be able to work with law enforcement, customers, and stakeholders quickly and efficiently to convey confidence in their data security solutions. In one study, the NIST CMVP testing program found that 50 percent of the modules were found to have security flaws and 25 percent of algorithms used were found to be incorrectly implemented. Law enforcement professionals know that not everything called "encryption" really meets minimal standards. An enterprise that uses NIST certified solutions will help minimize questions about the quality of their encryption solution.
Paul Ohmart, the project manager for certification, said, "Data encryption is always about cross-platform compatibility. Enterprise customers don't want to send sensitive information in the clear between internal servers, or between their internal systems and external customer and supplier systems. This exposes the data to loss. By supplying certified encryption solutions on Windows, Linux, UNIX, iSeries, and zSeries platforms with the same encryption API set, we provide customers with cross-platform support using exactly the same APIs. This reduces cost, shortens data security project times, and mitigates against data loss."
Standard AES encryption supports multiple key sizes and five modes of encryption. Many data security vendors support only one key size, and one or two modes of encryption. This leaves gaps in the security implementation. A solution that only supports Cipher Block Chaining (CBC) mode, for example, will not be able to handle Electronic Code Book (ECB) or Output Feed Back (OFB) modes of AES encryption. The Alliance AES encryption solution protects against these incompatibilities by supporting all standard encryption key sizes and all modes of encryption. The Alliance solution will interoperate with any other vendor's encryption products based on the AES standard.
The Company
Patrick Townsend & Associates is a privately held Washington State corporation providing encryption and data security products to the enterprise customer. The company has over 700 customers worldwide who are achieving regulatory compliance. The company can be reached at (360) 357-8971 or www.patownsend.com.
LATEST COMMENTS
MC Press Online