디스크 및 테이프 스토리지
Storage security has become the most important issue for IT managers due to the loss of smartphones, laptops, data being recovered from surplus computer disk drives and even tapes being misplaced by otherwise reputable companies offering off-site storage services. It is now clear that the industry must respond with a comprehensive security standard for data at rest and Elliptic has developed highly-integrated solutions which span all aspects of storage security.
The IEEE has ratified the disk security standard - 1619-2007. The security model works for RAID arrays where a disk might be physically removed by an insider intent upon accessing sensitive corporate information and applies equally well to single SATA or EIDE drives. The standard was updated to replace the LRW-AES cipher as LRW-AES exhibited vulnerability to certain attacks. The latest algorithm is referred to as the XTS-AES (and in some contributions as the AES-XTS) algorithm. It has also been ratified by NIST for inclusion as an approved mode under FIPS 140-2 which would permit it to be used in government applications.
The following cores can be applied to disk security applications:
- CLP-600: Security Protocol Accelerator
- CLP-47: Configurable XTS-AES Core
- CLP-45: Configurable Look Aside AES Core
The IEEE Std 1619.1-2007 - Standard Architecture for Encrypted Shared Storage Media, is also ratified and is targeted at encrypting information stored on tape for back-up purposes. It specifies the implementation of either AES-GCM or AES-CCM as the symmetric encryption cipher for this standard. Elliptic offers a variety of solutions for these algorithms ranging in performance from 100 Mbps up to 40+ Gbps depending on the class of tape drive being targeted.
The following cores can be applied to tape storage security applications:
- CLP-200: Pipelined GCM-AES Core Core
- CLP-45: Configurable Look Aside AES Core
- CLP-24: High Throughput AES-GCM Core
- CLP-20: High Throughput AES-CCM Core
Storage applications must have sophisticated key management designs. This in turn will frequently leverage encrypted key blobs which can be stored in memory such as RAM caches, Flash or on tape and disk. To facilitate the secure storage of key blobs, NIST and the IETF have developed an algorithm for key wrapping that uses the advanced encryption standard. The CLP-34 implements the AES key wrap (encryption) and key unwrap (decryption) algorithms.
Elliptic also offers Ellipsys Cryptography Middleware in support of storage applications, including key management. The middleware is split into the symmetric algorithms such as AES and SHA and the asymmetric RSA and ECC algorithms used in authentication and key exchange. The middleware is licensed as C source code.
- ESS-01: Symmetric Middleware
- ESS-02: Asymmetric Middleware
주요 제품
ETS-020: tVault HDCP
A proven HDCP-based content protection solution that provides robust security inside Trusted Execution Environments (TEEs) and enforces the protection of sensitive information to ensure that it is stored, processed and accessed only by authorized applications.The solution integrates seamlessly within frameworks such as ARM TrustZone™, where the critical security components are embedded in a trusted and secure OS environment. The non-critical components are executed by the rich OS, such as Android.
CLP - 630: 멀티 패킷 관리자 보안 엔진
고기능적이고 독특한 보안 프로토콜 가속기는 고용량 무선 및 네트워크 응용 소프트웨어의 데이터를 효율적으로 처리하기 위해 특별히 설계되었습니다. 이 엔진은 여러 활성 연결 및4G LTE - 고급 무선 셀룰러 기지국과 펨토셀 등 다양한 내용의 상당한 트래픽 로드를 다루는 응용 소프트웨어에 완벽히 적합합니다.





