|
innerGuard Inside establishes a security framework for companies building new or reengineering existing applications to reduce development time and accelerate time to market. With estimates as high as 70 percent of the total coding effort to build security related controls into applications, innerGuard Inside can dramatically reduce the time required to embed best practices security into virtually any type of application.
This modularized version of innerGuard allows companies to include seamless support for six aspects of security as follows:
- Authentication – A credential to validate a user's identity. A credential can be a password, smart card, or a biometric.
- Authorization – Based on a person's role, authorization allows a user to perform specific tasks within an application or business process.
- Confidentiality – Encrypts data so users can not view or use the data without the proper authority.
- Integrity – Verifies that the data transmitted was not altered in any way.
- Audit – Keeps an unalterable, meaningful log of every transaction that occurs at the business process level.
- Non-repudiation – Ensures that the person requesting an action and the data provided for that action are genuine.
They are also able to leverage innerGuard technology to dynamically omit sensitive and non-essential data from application transactions.
innerGuard Inside takes full advantage of industry accepted standards and algorithms as the surest way to guard against obsolescence while ensuring maximum supportability when building applications.
|
|
Standards
Industry standards supported by innerGuard Inside include:
- LDAP/JNDI – directory services
- X509v3 – Public Key Infrastructure (PKI)
- SAML – Web services security assertion
- XKMS – Web services key registration and discovery
- XACML - defining policies
- IPSEC - VPN level box-to-box communications
Algorithms
Algorithms provided with innerGuard Inside include:
- 3DES and AES – Data encryption algorithm for ensuring confidentiality
- MD5 and SHA1 — Both are message hashing algorithms to ensure the integrity of data
innerGuard Inside is preconfigured to support most common enterprise protocols including: HTTP/S, .NET, J2EE, TCP/IP, XML-RPC, CORBA/IIOP, SOAP, SMTP, TDS/SQL, FTP, WebSphere MQ, and RMI.
For more information please e-mail us at sales@cerebit.com.
|