Noticias sobre Realsec, sistemas de cifrado y firma digital

Just another WordPress.com weblog

Cryptosec-RKL | Arquitectura y funcionalidad

Realsec presenta la arquitectura y funcionalidad del sistema Cryptosec-RKL, un sistema multivendor para la carga remota de las Claves Iniciales en cajeros.

Sistema multivendor para la carga remota de claves Iniciales en cajeros

La solución Cryptosec-RKL utiliza un modulo de seguridad tamper-resistant y tamper-responsive, en cuya memoria residirían las Claves Maestras de Transporte para las distintas entidades financieras adheridas al servicio de RKL. En cada uno de los Cajeros residiría un componente, que durante el arranque de la aplicación del Cajero, sería ejecutado por ella, si la condición de operatividad del cajero así lo determina (comprobando para ello si está inicializado con la jerarquía de claves correspondiente). Una vez recibida la activación por parte de la aplicación, el componente automáticamente iniciará una petición de carga de la clave inicial del Cajero hacia el Servidor Cryptosec-RKL (enlace a http://www.realsec.com/pdfProEs/Cryptosec-RKL.pdf).

El Servidor recibirá peticiones procedentes de la red de cajeros para la futura carga de la clave inicial. Finalizada la sesión de transmisión de la clave Inicial en cuestión, éste estará en condiciones para iniciar operaciones contra el Host de la manera habitual, sin necesidad de dialogar nunca mas con el Servidor Cryptosec-RKL (mientras el equipo en cuestión no sea reinstalado o decomisionado). En estos dos últimos supuestos, el proceso de petición de carga de claves será ejecutado de nuevo por la aplicación de cajero, de forma automática y transparente para el personal técnico o de la oficina.

Archivado bajo:Uncategorized , , , , , , , , , ,

EURO 6000

EuroSeismil   Encoding Firmware with Adapted Requirements

EURO6000, Systems of payment of the Confederated Savings Banks and leading company in the national market of the systems of payment, proposed, one year ago, the need to develop and make available an HSM system adapted to its functional and administrative requirements. Basically, the aim was to offer its associated savings banks a homogeneous, complete, stable and totally controlled system which would cover the different cryptographic needs of their specific financial ambit.

One of the crucial objectives of the project was for the system to be developed to be able to evolve over time and incorporate new functions in the future in a natural and non-traumatic way

EURO6000, after evaluating the professional qualification and capacity of the different companies and alternatives available on the market as a partner to approach this project, chose REALSEC, a company specialised in the development and implanting of encoding systems, and which, under the specifications of EURO6000 and with the support of its Cryptosec HSM, has collaborated in the development of a new firmware and of the necessary software modules to permit a LAN access to its cryptographic capacities.

Objectives of the project:

·   To resolve the cryptographic necessities of generation and storage of keys of the businesses that are members of EURO6000. From the most common tasks to the most complex and specialized ones.

·    To operate, generate, import and export both DES keys and RSA keys in agreement with the applicable standards.

·    To store the keys externally to the HSM to facilitate their management. In addition it allows the sorting by types in such a way that their capacities remain clear at the hour of the generation or importation.

·     To implement the security architecture designed by EURO6000.

·     To permit the access by the Net to operate in on-line and batch modes.

·     To present a console for administrative tasks of printing of PIN codes and keys.

System architecture

States of the HSM

The HSM shows three different states. Each state allows the execution of a precise series of functions which are its own. There are rules for the change of state which facilitate the transaction between them. This process of change is controlled by the administrator and the guardians.

·     Initialisation: is the initial state of the HSM. It allows the creation of users, loading of the master key, and, in general, the configuration of the module. The HSM automatically leaves this state once the conditions are right, moving on to the production state and not returning to the state of initialisation other than in the case of resetting the system.

·      Production: is the normal state of production of the system, where the tasks of the EURO6000 operative are performed.

·      Authorization: through the identification of the administrator and a series of guardians, it enters into the state of authorisation. This allows administrative tasks to be performed without ceasing to attend the cards ascribed to the state of production. The administrative tasks include the registering and de-registering of users, generation, importation and exportation of keys, print functions, and in general the configuration of the HSM.

Architecture of the storage of keys

It has already been mentioned that the keys are stored in a database external to the HSM. This is one of the requirements of EURO6000. As such, these keys are stored encoded. There is no single encoding key, rather there are many, as many as there are keys. In this way, the capacities of the keys are controlled: each operation expects a key of one type and not another.

The encoding keys are not introduced externally, rather they are generated in the HSM through an algorithm of diversification of a master key provided by the guardians. The algorithm of diversification is designed in such a way that the knowledge of one of the encoding keys does not put at risk either the other encoding keys or the master key.

Implemented functionalities.The system allows the recording, importation and exportation of DES keys, of single, double or triple key length. The operations of importation and exportation allow one to work both with transport keys and with key components and, in this case, allow their printing. It is also able to generate, import and export RSA keys of up to 2048 bits

Moreover, it provides the functions needed to complete the following operations:

Calculation/Verification of digital signature.

RSA Encoding/Decoding.

DES/TDES Encoding/Decoding of confidential data.

Authorization of EMV transactions.

Security treatment of the scripts.

EURO6000 MoneyCard and associated applications.

PIN functions.

Transport protection of PIN: Irreversible PIN.

Exportation of PIN’s.

Calculation of validation codes.

NIP functions (Mobipay).

Securing of messages.

Diversification of keys.Teletoll functions.

Current State of the Project

At this moment, ESFERA is already a reality in exportation, available for all of the Savings Banks Associated to EURO6000, that progressively and depending on their necessities are acceding to this new cryptographic system facilitated by EURO6000 and based on Cryptosec (encoding technology of the REALSEC company).

Archivado bajo:Uncategorized , , ,

Servidor de Carga Remota de Claves “Multivendor”

CRYPTOSEC-RKL: LA SOLUCION PARA LA AUTOMATIZACIÓN

Realsec lanza un Servidor de Carga Remota de Claves “Multivendor”, que implementa los esquemas de carga de los principales fabricantes de autoservicio. Los sistemas utilizados por el sistema bancario y los medios de pago representan un entorno comprometido con la seguridad, a nivel de sus proceso así como en las operaciones transaccionales.

Para lograr los objetivos de confidencialidad, integridad y evitar una malainterpretación de las transacciones electrónicas, los grandes servicios de medios de pago: Visa y Mastercard, han propuesto un marco de requerimientos y exigencias de seguridad, física y lógica, que se deben cumplir cuando se trata de aquello dispositivos de introducción y manejo del código PIN y también cuando hablamos de las técnicas de gestión y distribución de claves, algoritmos necesarios a la funcionabilidad de los sistema de pago.
Es nada más y nada menos que la actualización de las antiguas especificaciones establecidas por estas marcas a las

nuevas tecnologías y tendencias del mercado de los pagos.  Las nuevas técnicas a utilizar para transferir las claves a los Cajeros automáticos con la preservación de su integridad suponen la existencia de un sistema de carga remota de claves que funciona a través  de la criptografía de clave pública. Se trata pues de operar en un marco de seguridad de aceptación universal a nivel mundial y en el que Realsec, líder en sistemas criptográficos ofrece las máximos garantías de seguridad de su nuevo producto en materia de servidores de carga remota de claves “Multivendor”.  Cryptosec-RK. es una solución integrada de RKL (Remote Key Loading) o carga remota de claves para Cajeros, TPVs y PinPad. Cryptosec-RKL es un Servidor de carga remota de claves “Multi-vendor”, que implementa los esquemas de carga de los principales fabricantes de Autoservicio: Diebold, NCR, Wincorn y Fujitsu, etc. Es una plataforma independiente de la operativa funcional del sistema Host y de los Autoservicios que pueda tener cualquier Banco y no requiere de cambios hardware o software en ninguno de ellos. Cryptosec-RKL lleva integrado un modulo de seguridad “Tamper Resistant y Responsive” que maneja las Claves Master de Transporte para garantizar la máxima seguridad.

Más de veinte bancos y entidades españolas y de América Latina están empleando el servidor de carga remota de claves “Multivendor”  Cryptosec-RKL y algunos de ellos dispones de redes de cajeros de hasta 500 terminales. Apostar por un sistema así les ha hecho reducir costeos y recursos dedicados a estos procesos.

Archivado bajo:Uncategorized , , , , , , , , , ,

Cryptosign-Mail, el nuevo servidor seguro que Realsec introduce en el mercado español

Realsec introduce en el mercado español su nuevo servidor, Cryptosign-Mail, una herramienta que ofrece a las empresas seguridad. El producto está basado en la tecnología HSM y cuenta ya con el certificado FIPS y en proceso de certificación Common Criteria.

Archivado bajo:Uncategorized , , , , , , ,

Realsec | Cryptographic services

Realsec is specialised in the design, development and commercialisation of technology and systems of encoding and digital signature.
The company builds cryptographic systems and products of high security and reliability applied to Banking, Payment Systems, Defence, Public Administration and Industry and many other.

Realsec technology is working presently in large and medium-sized companies, and our products are commercialised by channel.

Our R&D research centres, design and develop encoding systems based on high technological innovation, and workes together with Universities and Technological Centres in Research projects, feasibility studies and the development of new solutions. Realsec is present in the Plataforma Tecnológica Española para la Seguridad y Confianza e-Sec within the AVANZ@ Plan of the Ministry of Industry.

Archivado bajo:Uncategorized