Privacy of information
A means of disguising a file results in that file being interpreted by intended parties only.
Proof of identity
The person generating or conveying a protected file implicates themselves when signing the file. This action results in non-repudiation.
Tamper detection
The ability of the recipient to verify that the information received has not been modified in transit. Any attempt to modify data or substitute a false message for a legitimate one will be detected.
Whilst many products offer excellent encipher and authentication capabilities, few actually provide total solutions based on the highly acclaimed public key infrastructure. Certificates may have to be obtained from other parties or the user is forced to operate in the security providers program to secure data, ever increasing training, and more potential points of failure.
Over complication of procedure results in poor uptake or even project failure of a very secure, proven technology.
The proportion of communication to be considered for security is normally small compared to every day correspondence, so why does everyone have to adopt new working practices to accommodate perceived added security?
The inclusion of email gateways to handle protected files imposes a high administrative burden; the attempt to improve automation has been known to incur additional delays in communication.
The benefit of listening to customers is the diving force behind In-Confidence, Quad Logic Systems’ suite of secure communication products. We provide a total solution, incorporating management and deployment for secure electronic communication.
The task is to identify that which is to be protected and apply sophisticated protection as seamlessly as possible. Quad Logic Systems provide software products which integrates your need for information security to produce working solutions.
Keeping information private is the primary role of electronic encryption techniques. If we wish to convey information to other parties discretely, cryptography provides a means to disguise the message and identify the originator. In-Confidence employs common, sophisticated cryptographic techniques to provide secure communication between users.
This document serves to outline secure communication scenarios and our product offerings.
Computing Practice
Secure computing practice begins at the workstation and is the responsibility of all users. Password protected screen savers, locking of the workstation whist away from the desk; both help prevent access to your information and prevent others using your identity. Beyond sensible working practice, we must consider the value of our data in the wrong hands and protect accordingly.
In-Confidence will always keep your secured files secure. Access to a protected file is only possible with the owner key and corresponding owner password. All keys deployed are unique; every user is assigned their own personal key. Leaving a personal computer accessible does not allow the unintended to view your protected information. Any attempt to create secure transmissions will be blocked by the same process thereby protecting your identity. Ease of use is the driving force for our software development; our products are continually tested by inexperienced computer users to ascertain this compliance. These operating characteristics are common throughout In-Confidence.
Security in the Company
The introduction of In-Confidence significantly enhances file security offered by network operating systems. Every participant is issued unique electronic ‘keys’ and initial passwords as the tools necessary to secure and read protected files. The credit card and pin analogy may be used here; both are required to perform a transaction.
Follow the same protection afforded to your credit card, the key you are issued represents your electronic identity for securing information, the initial password is under your control to change whenever you wish.
Sensitive information relating to human resources, financial or design may be rendered unreadable by others in a simple point and click exercise. A popular requirement is that selected information be available to a privileged few, perhaps department operatives or higher management. Secured files may exist on the workstation, removable media or networked drives, administrative staff will not be able to see content unless you permit by intention. The file selected for protection can be digitally signed as well as encrypted; this is particularly useful when the file is read by an intended recipient. Signing a file electronically is akin to adding a written signature to a document. This method also affords anti tampering protection so a recipient is informed if modification has been attempted.
The generation of keys, distribution and management are all provided by Quad Logic Systems support software, a complete solution. Third party X509 certificates may be utilised to provide operating keys but this invariably adds cost to project, a unique and efficient solution is for the owner to create their own. This process has been greatly simplified by our management software, the keys you create are unique; no other party holds duplicates. The issuance of keys is at your control and conformance criteria. Enforce policy and apply.
Client to Company Secure Communication
Speed and ease has resulted in email becoming a popular used and abused means of communication. The fact that using this medium is akin to sending a postcard is of little concern for the majority of information we convey, but if we could hide our message and prove its origin, email becomes a much better business tool.
The introduction of In-Confidence elevates email to a first class mail service where ‘Private and Confidential’ have true meaning. Protection is applied to a file which can then be attached to any email client program for transmission. Applying encryption and signing prevents unauthorised access to the information protected, even generating the email becomes a seamless operation. Existing software is not modified to provide these security functions, our products are used to enhance functionality when file protection is considered a requirement. Why tamper with email client software when the majority of your email messages are not considered sensitive?
If communication with your clients is structured by way of written forms, Quad Logic Systems can present digitised versions which receive error checking prior to submission, alleviating further correspondence through misinterpretation.
The generation of keys, distribution and management are all provided by Quad Logic Systems support software, a complete solution.
Business to Business Secure Communication
Deploying sophisticated cryptography so everyone can securely communicate with everyone poses enormous logistical problems. Trusting authorities and key distribution become security pitfalls; all aspects require careful consideration to deploy a workable, high confidence solution.
Many vendors supply a rental type service for this ability, but customers have indicated a preference towards ownership of a solution. Quad Logic Systems provide a complete package encompassing management, auditing, reporting, distribution and ease of use.
|