Safe organizational private key tampering (the chief signatory).
Private key protection in three security layers.
Safe encrypted key lifespan management (access/export/backup/replace/delete, etc.).
Comda has many years experience in installing various HSM products for organizations with different needs, from storing private keys for digital certificate issuing systems to complex sealing systems. HSM products have efficient management characteristics which allows managing the component operation remotely, except for activities connected to the encryption itself, which require physical access and use through strong authentication, such as smart keys before the HSM itself.
As part of strengthening the component, it is situated in a protected box, requires multiple authentication and encrypts the keys in complex algorithms. As representatives of the world’s leading manufacturers in this field, and from its extensive activities, Comda enjoys widespread support and cooperation from the manufacturers, and in this way clients benefit from this advantage.
nCipher offers a line of hardware-based products to protect commercial applications in use in websites.
nCipher products integrate modularity, speed and user-friendliness, and are especially suitable for organizations operating commercial websites and various e-commerce services on Web servers in a safe channel through SSL protocol.
Transferring data safely in the SSL channel is fast and efficient, but the procedure to create the SSL channel, called the SSL Handshake, utilizes a large portion of the Web server’s resources. Therefore, many Web servers cannot withstand access to a large number of users in the website simultaneous. In standard Web servers, most of the CPU activity is used to perform SSL Handshakes and in many cases requires the organization to purchase numerous additional servers in order to withstand the load.
The most protected secrets in organizations are found in Web servers. The Web server’s private key exists only there and allows clients to verify that they have in fact reached the organization’s server and not an impersonated one. Only the server’s private key can create a SSL channel in the name of the specific server that the client has approached.
nCipher’s Hardware Security Modules (HSM) allow suiting the module to the client’s requirements, whether by accelerating transactions or protecting the private key completely. The HSM tools interface with all platform types, such as NT, all types of UNIX and Linux. In addition to each standard management module, it is suitable for connection to different computers and software, and comes in SCSI and PCI form.
nCipher offers a line of hardware-based products to protect commercial applications in use in websites.
nCipher products integrate modularity, speed and user-friendliness, and are especially suitable for organizations operating commercial websites and various e-commerce services on Web servers in a safe channel through SSL protocol.
Transferring data safely in the SSL channel is fast and efficient, but the procedure to create the SSL channel, called the SSL Handshake, utilizes a large portion of the Web server’s resources. Therefore, many Web servers cannot withstand access to a large number of users in the website simultaneous. In standard Web servers, most of the CPU activity is used to perform SSL Handshakes and in many cases requires the organization to purchase numerous additional servers in order to withstand the load.
As the demand for online privacy and protection increases, many organizations gradually appeal for an SSL channel industrial standard to protect their entire organization, from internal organizational communications, through sensitive digital contents, to e-commerce transactions.
Although the benefit to using SSL is clear, SSL operations greatly burden the resources of the servers and could cause the server resources and activities to slow down significantly to a snail’s pace in regular traffic conditions.
The nFast 800 allows 800 SSL communications per second. This PCI card works on Windows 2000 and Linux operation systems, and has the ability to offer more in improving Web server performance.
The nFast allows performing up to 300 communications simultaneously. It frees the CPU in e-commerce servers from bottlenecks caused by many simultaneous user requests, and in this way only 30% will be devoted to handling communications as opposed to 95% without the nFast module. The result is that most of the power is in the application itself. nFast is a hardware module to accelerate the SSL Handshake in the Web server. nFast 300 allows accelerating the SSL channel for Web servers in a wide range of operating systems. In addition, this PCI card supports unique API, such as BHAPI, to support Web-based applications which utilize these API abilities.