| By Application Security | Article Rating: |
|
| February 15, 2013 02:25 PM EST | Reads: |
1,405 |
Intel Expressway Service Gateway and RSA DPM: Security without pain
Top security threats for 2013 include “hacktivism” attacks, botnet malware, distributed denial of service attacks, and identity theft. The problems are well known and yet there is still resistance to spending the capital on prevention measures. Intel® Expressway Service Gateway (ESG) and RSA Data Protection Manager (DPM) have partnered to provide a painless way to protect web services and sensitive data from threats.
The beauty of the solution is that existing services do not need to be modified. Service delivery of tokenization and key management is abstracted, secured and simplified. The Expressway Service Gateway provides features made to integrate, mediate, secure, and scale services in a dynamically changing Enterprise application perimeter that may include multiple security domains. Once deployed to the network edge in a software or hardware form factor, our service gateway combined with the DPM can safely expose existing REST APIs or SOAP web services. High speed data mediation capabilities for XML, JSON, binary, and legacy data enable existing web services to be exposed as REST APIs to meet growing mobile service demands.
Tokenization in the Expressway Service Gateway
When acting as a tokenization solution, ESG in conjunction with DPM can provide PCI Compliance through the configuration of a proxy tokenization and detokenization service. This configuration provides security without modification to existing services. Data is proxied through the service gateway and tokenized before it reaches existing services. All systems behind ESG are out of scope since PAN data never reaches them, only the tokenized data. In reverse, when data needs to be transmitted out with the original PAN data it can be securely proxied through the service gateway and the tokens are replaced with the original PANs. ESG supports a wide range of protocols, HTTP(S), JMS, IBM MQ, FTP(S), FILE, SFTP, RAW TCP/IP(S), and CUSTOM which allows it to handle the various types of traffic that needs to be tokenized/detokenized on the way in and out of a customer’s data center.
For retail applications, PCI Compliance can be achieved by intercepting url-encoded web requests containing PAN data, tokenizing and forwarding to the existing backend with no change needed to the back-end service. Bulk tokenization requests, transmitted over SFTP, can be proxied to allow for tokenization. ESG can batch large requests to run in parallel in order to optimize performance. The concepts applied to PAN data also work to secure patient health information (PHI) for healthcare applications.
Data Encryption Services
When working in conjunction with DPM for key management operations, ESG acts as a secure proxy gateway to sign/verify/encrypt/decrypt data as it enters or leaves a customer’s Data Center. The advantage here is that customers do not need to modify existing services to gain this functionality. It also allows larger amounts of data to be encrypted vs. smaller PAN credit card type numbers. It is extremely flexible and desired key and Token behavior can be set to each application needs. The data center encrypt/decrypt/sign/verify use case can be applied to cloud applications too. Requests to store data in the cloud can be intercepted and encrypted/decrypted with no modification to the cloud storage services.
Visit with our application security specialists at the RSA Conference – 2013 to learn more about how easy security can be.
Resources
Read the Intel Expressway Service Gateway data sheet
Read the details on the Secured by RSA configuration
The post Intel Expressway Service Gateway and RSA DPM appeared first on Security Gateways@Intel.
Read the original blog entry...
Published February 15, 2013 Reads 1,405
Copyright © 2013 SYS-CON Media, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
More Stories By Application Security
This blog references our expert posts on application and web services security.
- Cloud People: A Who's Who of Cloud Computing
- Cloud Expo New York: Rethink IT and Reinvent Business with IBM SmartCloud
- Session Topics: 12th Cloud Expo / Cloud Expo New York
- Commander of U.S. Cyber Command and National Security Agency Director, General Keith Alexander, To Keynote Day One of Black Hat USA 2013
- Cloud Business Solutions, Social Media, and Platform Systems of Engagement Market Shares, Strategies, and Forecasts, Worldwide, 2013 to 2019
- Cloud Expo New York: Security for Cloud Computing
- MicroStrategy Announces General Availability of MicroStrategy 9.3.1
- Cloud Expo | IBM & OpenStack Together: Accelerating Cloud Adoption & ROI
- MicroStrategy Announces General Availability of MicroStrategy 9.3.1
- Cloud Computing – The Perfect Match for Big Data
- Research and Markets: Global Platform-As-A-Service Market Expected To Post Revenue of US$6.45 Billion in 2016 According To Latest Report
- IBM Named “Diamond Sponsor” of Cloud Expo New York
- Cloud People: A Who's Who of Cloud Computing
- State and Local Governments Adopt Microsoft Dynamics CRM to Improve Citizen Service Delivery
- Cloud Expo New York: Rethink IT and Reinvent Business with IBM SmartCloud
- Session Topics: 12th Cloud Expo / Cloud Expo New York
- ACI Worldwide Empowers Financial Institutions to Increase Efficiency of Card Issuing and Account Management
- Cimtrek announces the general release of its Lotus Notes migrator for Microsoft’s SharePoint platform
- Commander of U.S. Cyber Command and National Security Agency Director, General Keith Alexander, To Keynote Day One of Black Hat USA 2013
- Cloud Business Solutions, Social Media, and Platform Systems of Engagement Market Shares, Strategies, and Forecasts, Worldwide, 2013 to 2019
- Cloud Expo New York: Security for Cloud Computing
- MicroStrategy Announces General Availability of MicroStrategy 9.3.1
- Velocity Technology Solutions Introduces IBM Power Systems Universal Cloud Services at COMMON 2013
- AMAX Launches StorMax(TM) CFS, powered by IBM(R) General Parallel File System(TM) (GPFS(TM))
- Java vs C++ "Shootout" Revisited
- Where Are RIA Technologies Headed in 2008?
- WebSphere Application Server Java Dumps
- Unveiling the java.lang.Out OfMemoryError
- How To Deploy Scalable WebSphere Applications Using "Maven" Build Tool
- Breaking News: New Internal IBM Report Says "Another Flawed Study"
- Profiles for WebSphere Application Server 6.0
- Last Exclusive JDJ Interview With "IBM's" John A. Swainson, Now CA's Newly Appointed CEO
- Automated Deployment of Enterprise Application Updates
- Developing Java and Web Services Applications on Rational Application Developer V6
- Your Guide to Portal Clustering in WebSphere Portal Server 5.1
- How to Create a Simple Java J2ME Application for BlackBerry



















