fhs
Volume 9, Number 17 -- April 28, 2009

nuBridges Pushes 'Tokenization' with New Encryption Tool

Published: April 28, 2009

by Alex Woodie

System i security software vendor nuBridges last week unveiled a new product called nuBridges Protect Token Manager that puts a different spin on the problem of encryption in dispersed corporate environments. Instead of encrypting data as it rests in a company's various databases and applications, the product replaces the critical data values with a token that points back to a single database, thereby providing a more secure repository for sensitive data, as well as preserving data formats.

nuBridges is well versed in the field of encryption. The Atlanta, Georgia, software company, which targets the IBM Power Systems server as well as open systems platforms, has been developing traditional encryption software for years. And with the Payment Cardholder Industry Data Security Standard (PCI DSS) pushing new encryption mandates onto retailers, banks, and other parties that hold credit card data, nuBridges has been looking for ways to solve some of the unforeseen consequences that encryption is having on companies, and to drive the state-of-the-art for tokenization, which Gartner and other IT analysts see as the future of encryption.

One of these problems is the storage footprint formed by encrypted data. Having encrypted data, or "ciphertext," residing in multiple locations elevates the risk that data will be comprised through a mishandled key or other mistake. "The most effective and efficient approach to protecting critical data is to make sure it is stored in the clear in as few places as possible," says John Pescatore, vice president and analyst at Gartner. "Technologies that reduce the complexity of doing so are badly needed."

Tokenization is viewed as the solution to the encryption storage footprint problem, because it minimizes the number of places where unencrypted data is stored. With tokenization, instead of storing the unencrypted data locally, a token, or a surrogate value, is inserted in place of the original data. These tokens can then be passed around the network between applications, databases, and business processes safely, while leaving the encrypted data it represents securely stored in a central data vault, according to nuBridges.

But tokenization, as it is commonly used today, introduces its own set of problems. One of these is the referential integrity of databases when tokens and data values don't maintain a strict one-to-one relationship. Upper case and lower case letters, numbers, and characters are often used interchangeably, which creates problems. Tokenization is also often outsourced today, which is a cause for concern of the most security conscious.

nuBridges Protect Token Manager seeks to solve these two problems by maintaining a one-to-one relationship between tokens and encrypted data, and by allowing companies to keep tight reins over their encryption mechanisms. The software also helps to narrow the scope of PCI DSS audits by limiting the number of places sensitive data is kept.

The new software was written in Java, runs on any Java Virtual Machine, a company representative says. It supports multiple databases, including DB2/400 (DB2 for IBM i), Oracle, and Microsoft SQL Server. It also generates Syslog-compliant logs for integrating with security information and event management (SIEM) products, and also integrates with nuBridges Protect Key Manager for managing the lifecycle of encryption keys.

nuBridges Protect Token Manager is available now. Pricing is dependent on the size and type of server, and starts at $50,000. For more information, visit www.nubridges.com.




                     Post this story to del.icio.us
               Post this story to Digg
    Post this story to Slashdot


Sponsored By
PRODATA COMPUTER SERVICES

Simplify your iT!

DBU - super easy to use. The leading data access tool on the market.

DBU RDB - does the work for you. Analyze data on all your servers.
MySQL, Microsoft SQL Server, Oracle, DB2 databases and others.

RDB Connect - programmatic access to remote data! Full SQL access to
remote databases from all System i high-level languages.

Download your free trials NOW.
Order today and SAVE $500!
www.prodatacomputer.com
800.228.6318


Editor: Alex Woodie
Contributing Editors: Dan Burger, Joe Hertvik,
Shannon O'Donnell, Timothy Prickett Morgan
Publisher and Advertising Director: Jenny Thomas
Advertising Sales Representative: Kim Reed
Contact the Editors: To contact anyone on the IT Jungle Team
Go to our contacts page and send us a message.

Sponsored Links

Vision Solutions:  New white paper! Review the full range of Data Protection & Recovery options.
SafeData:  FREE White Paper - Best Bets for iSeries Rapid Recovery with Virtualization
Aberdeen Group:  Take the 2009 ERP in Manufacturing survey, get a free copy of complete report


 

IT Jungle Store Top Book Picks

Easy Steps to Internet Programming for AS/400, iSeries, and System i: List Price, $49.95
The iSeries Express Web Implementer's Guide: List Price, $49.95
The System i RPG & RPG IV Tutorial and Lab Exercises: List Price, $59.95
The System i Pocket RPG & RPG IV Guide: List Price, $69.95
The iSeries Pocket Database Guide: List Price, $59.00
The iSeries Pocket SQL Guide: List Price, $59.00
The iSeries Pocket Query Guide: List Price, $49.00
The iSeries Pocket WebFacing Primer: List Price, $39.00
Migrating to WebSphere Express for iSeries: List Price, $49.00
Getting Started With WebSphere Development Studio Client for iSeries: List Price, $89.00
Getting Started with WebSphere Express for iSeries: List Price, $49.00
Can the AS/400 Survive IBM?: List Price, $49.00
Chip Wars: List Price, $29.95


 
The Four Hundred
IBM Launches Power6+ Servers--Again

Power Systems Down A Bit in IBM's First Quarter

COMMON Europe Opens Up Global i Top Concerns Survey

Four Hundred Guru
Don't Ignore the View

Releasing File Member Locks With QSH

Trouble-Shooting i5/OS Printer Problems in a Warehouse Environment

Four Hundred Monitor
Four Hundred Monitor's
Full iSeries Events Calendar

System i PTF Guide
April 25, 2009: Volume 11, Number 17

April 18, 2009: Volume 11, Number 16

April 11, 2009: Volume 11, Number 15

April 4, 2009: Volume 11, Number 14

March 28, 2009: Volume 11, Number 13

March 21, 2009: Volume 11, Number 12

TPM at The Register
Sun says it's time for MySQL 5.4

Sun mates MySQL with more iron

IBMware priced 40% higher on Nehalem

Come on out, Power6+, you win

AMD pulls forward six-shooter Opteron cannon

IBM boasts Sun-HP server pact pillaging

AMD chases Nehalem with speedier Shanghai

Ex-Red-Hat brains decide to ride cloud

Unisys scratches labels off Dell Nehalems

VMware unmasks next-gen hypervisor

Big Blue defies server crash with Q1 profit

Canonical punts Ubuntu Jaunty Jackalope

King Larry launches Oracle-Sun combo at Big Blue, Cisco

HP pits Matrix against Cisco's California

THIS ISSUE SPONSORED BY:

Bytware
ProData Computer Services
Maximum Availability
Linoma Software
Guild Companies


Printer Friendly Version


TABLE OF CONTENTS
Twitter from an AS/400? Kisco Lets You Do It

nuBridges Pushes 'Tokenization' with New Encryption Tool

BCD Adds Features Throughout App Modernization Suite

Guardium Adds DB2/400 Support to Database Security Tool

Lawson Retrenches as it Reconnects with Customers

News Briefs and Product Shorts:

LANSA Acquires aXes Products; Customers Likely Candidates for RAMP . . . i OS Spool Files Go In, Structured XML Comes Out . . . CCSS Cracks Down on Long-Running Jobs . . . MySQL 5.4 Brings Scalability, Performance Improvements . . . QlikTech Develops a BI Client for iPhone . . .

Four Hundred Stuff

BACK ISSUES




 
Subscription Information:
You can unsubscribe, change your email address, or sign up for any of IT Jungle's free e-newsletters through our Web site at http://www.itjungle.com/sub/subscribe.html.

Copyright © 1996-2009 Guild Companies, Inc. All Rights Reserved.
Guild Companies, Inc., 50 Park Terrace East, Suite 8F, New York, NY 10034

Privacy Statement