Overview & Applications
QUANTUM-SAFE Network Encryption Security | ||||||||||||
Quantum-Safe cryptography provides the ultimate protection in long-term data encryption security in a post-quantum world. Provide unparalleled protection for data with long-term sensitivity and value with the addition of its Quantum Key Generation, Quantum Key Distribution (Quantum Cryptography) and Quantum-Safe Network Encryption features. Assurance that your investment keeps pace with cryptographic advances. Engage Black's BlackDoor DUO network encryptors ensure the protection of data in transit, offering the best combination of network performance with quantum-safe security. The BlackDoor DUO platform encrypts Ethernet traffic up to 100Mbps Full Duplex (200Mbps aggregate wire speed) on local and storage area networks for data back-up and recovery, as well as on fully meshed global WAN networks for international operations. COST-EFFICIENCY Engage Black encryptors provide excellent total cost of ownership through a combination of network bandwidth savings, ease of network management and reliability. Longevity, interoperability, backward compatibility, minimal installation and management costs and solution flexibility all contribute to a rapid return on investment. Other cost benefits include, low power consumption minimal rack space use and combined rack space/power utilisation efficiency. The BlackDoor DUO Encryptor supports Point to Point and Multipoint information assurance configurations with unique dynamic keys. The BlackDoor DUO Encryptor is designed for wireline or wireless backbone configurations. The BlackDoor DUO meets stringent security requirements while reducing overall network complexity in applications including:
| ||||||||||||
The BlackDoor DUO Encryptor transparently encrypts Ethernet Voice, Video or Data packets, that are destined for a device located on a remote network or a different local network segment. Data packets are AES encrypted at the Link, Network or Transport Layer and then tunneled, bridged or routed to the destination network. At the destination network the packets are decrypted and the original Ethernet packets are securely delivered to the destination Ethernet device. Layer 2 encryption ensures protection of all traffic on the network as well as concealing the network architecture. Engage Black devices use state-of-the-art AES 256 bit encryption, with the optional GCM mode providing data integrity on a per-packet level as well as confidentiality. The transport security feature masks the data flows on the network to ensure that traffic patterns do not reveal critical information.
| ||||||||||||
Point to Point “Plug-and-Encrypt” Installation | ||||||||||||
The BlackDoor DUO is a plug-and-encrypt installation for the payload of layer 2 and MPLS point to point network connections. The payload of the Ethernet Packets entering the clear text LAN1 are AES encrypted and sent out LAN2 to the Egress Ethernet. Ethernet packets AES decryption requires a unique 256 bit key. | ||||||||||||
The Change to Connectionless Networks | ||||||||||||
Ethernet networks are being used for larger scale networks and as a replacement for traditional telco data services. Both private enterprises as well as service providers see the proliferation of Ethernet as a backhaul medium as an advantage for their network expansion. However, Ethernet at this scale can also lead to potential issues as the network is no longer as secure as a connection-oriented infrastructure. Security interfaces are required at all network access points to assure data packets as well as address information is encrypted and protected. These interfaces might be less robust software solutions or for a higher level of network security, plug-and-play encryption appliances. These interfaces might be less robust software solutions or for a higher level of network security, plug-and-play encryption appliances. The Engage BlackDoor DUO offers an effective, easy-to-install solution to solve this problem. The BlackDoor DUO can be added to existing equipment sites for upgrade of security or it can be installed with new systems to add AES encryption to non-secure equipment. It works in both point-to-point as well as point-to-multi-point configurations. | ||||||||||||
MANAGEMENT & MONITORING Engage Black allows easy implementation and monitoring of enterprisewide security policies for audit and compliance. Simple provisioning and scalable management are enabled, either locally or remotely via secure connections (inband or out-of-band). Engage Black acts as the Certificate Authority by signing and distributing X.509 certificates to the encryptors, as well as accepting third party certificates. It is compatible with SNMPv3 compliant network management tools (eg NetView, OpenView, Tivoli). Flexible policy engine with secure local & remote provisioning & management (SNMP v3) In-field firmware upgrades SNMPv1/2 monitoring (read-only)) Support for external (X.509v3) CAs CRL and OCSP (certificate) server support
Compatible with P2P and multi-point architectures Quantum TRNG for high-quality encryption keys
Quantum Key Distribution (QKD) server to ensure that the solutions are quantum-safe for the long-term protection of sensitive data. This also ensures investment-protection of the encryptors. Such quantum cryptography is provably secure, ensures anti-eavesdropping detection and provides long-term forward secrecy against brute force hacking and attacks by quantum computers. | ||||||||||||
SECURITY & ENCRYPTION Tamper resistance & anti probing barriers AES-GCM mode for integrity AES 128 or 256 bit keys IDQ Quantum Random Generator Support for Quantum Key Distribution Automatic seamless key management Policy based on MAC address or VLAN ID Encryption modes Certification
PERFORMANCE
OSI Layer Encryption It is important for an external encryption device to be able to handle encryption at multiple layers of the OSI model. The BlackDoor DUO Encryptor can interface to all layers with an internal bridge and router and provides secure data encryption at common throughput levels. | ||||||||||||
Layer 2 - Bridge Layer 3 - Router Tunnel - Equipment Interface MPLS Advanced Encryption Standard | ||||||||||||
Point-to-Point or Point-to-Multi-point Network Configurations The BlackDoor DUO transparently AES encrypts Ethernet networks with Ethernet Voice, Video or Data packets, that are destined for a device located on a remote network or a different local network segment, are AES encrypted at the Link, Network or Transport Layer and then tunneled, bridged or routed to the destination network. At the destination network the packets are decrypted and the original Ethernet packets are securely delivered to the destination Ethernet device. |
BlackDoor DUO Encryptor Applications | ||||||||||||
| ||||||||||||
| ||||||||||||
| ||||||||||||
Network to Multiple Network Access Points - Encryption with BLACKDOOR DUO Encryptor | ||||||||||||
Broadband Interoffice Ethernet Demand for interoffice bandwidth to support applications such as: VOIP, IPTV and Video on Demand, and the aggressive pricing from Ethernet Service providers are pushing Interoffice Ethernet into Multisite Enterprises. Encryption is required at all network access points to assure sensitive payload and address information is encrypted and protected when it traverses service provider networks Wireless Ethernet Encryption One of the most economical means to establish Gigabit Ethernet connectivity between line-of-site locations is Wireless Ethernet with Gigabit interfaces. The BlackDoor DUO facilitates encryption of the Egress Ethernet to externally located Wireless Gigabit and offloads encryption from the Radio and supports multi point installations. Connectionless Network Protocol Security Ethernet networks are being used for larger scale networks and as a replacement for traditional telco data services. Both private enterprises as well as service providers see the proliferation of Ethernet as a backhaul medium as an advantage for their network expansion. However, Ethernet at this scale can also lead to potential issues as the network is no longer as secure as a connection-oriented infrastructure. Security interfaces are required at all network access points to assure data packets as well as address information is encrypted and protected. These interfaces might be less robust software solutions or for a higher level of network security, plug-and-play encryption appliances. The Engage BlackDoor DUO offers an effective, easy-to-install solution to solve this problem. The BlackDoor DUO can be added to existing equipment sites for upgrade of security or it can be installed with new systems to add AES encryption to non-secure equipment. It works in both point-to-point as well as point-to-multi-point configurations at 200 mbps access speeds.
| ||||||||||||
OSI Layer Encryption | ||||||||||||
BLACKDOOR DUO Encryptor Benefits
|