Security for Edge and Access Applications
SafeNet QuickSec™ for Access Networks is designed for
developers implementing security technology on edge and access devices.
Overview
Though there is an increasing number of access network technologies,
both wireline and wireless, all share a common need for privacy and access
control.
SafeNet QuickSec for Access Networks addresses all practical
IPSec layer problems found in access network applications regarding dynamic
addressing and configuration, integration to existing AAA ((Authentication
Authorization Accounting) infrastructure, support for legacy tunneling
technologies, NAT issues, and the need for multilayer stateful inspection
TCP/IP firewalling and attack prevention.
SafeNet's experienced technical support team and professional services
group are available to assist OEM's/ODM's during the implementation stage.
Flexible Implementation
Implementation is portable and versatile enough to support a variety of
applications from simple CPU-based designs to crypto co-processors and
high-performance network-processor-based configurations.
Firewall
Today protection against attacks is mandatory in gateway appliances that
connect LANs to the Internet. Incoming traffic needs to be inspected on
multiple layers to detect and prevent various attacks and probes ranging
from port scanning to known exploits for applications.
IPSec - Internet Engineering Task Force (IETF) has
endorsed vendor-independent network layer protocol for implementing end-to-end
security. IPSec is an application and media independent layer for bringing
security to heterogeneous networks.
Internet Key Exchange (IKE) - Session management and
authentication protocol of choice for IPSec data layer. SafeNet's IKE
implementation is among the first to introduce support for the latest
IETF standards.
X.509 PKI Client Functionality - X. 509 Public Key
Infrastructures provide a scalable solution for managing authentication
in networks with thousands of devices, such as centrally managed corporate
infrastructure with remote clients, or managed gateways in residential
access networks.
Features
- TCP/IP Firewall
- IPSec stack environments
- IPSec functionality based on IPSec and related IETF standards
- Deterministic memory usage with minimum run-time memory allocation
- Cross-platform portability based on clearly identified porting layers
- ANSI C source code product
- IPSec functionality including data plane and control plane components
Control Plane:
- IKE (Internet Key Exchange) protocol for session establishment and
authentication
- X.509 Certificate validation engine
- Management & configuration API for dynamic run-time Security Policy
configuration
Data Plane:
- IP flow oriented packet lookup
- Software implementation of IPSec transforms and necessary cryptography
- Integration to host TCP/IP stack via separate porting layer
- Well-defined model for offloading performance critical processing
path to NPUs
- Supports major cryptographic co-processors
- Slow path processing for IP fragments