You are on page 1of 2

Protection for Data-in-Transit

for Banking
Protecting Branch Banking Networks VPNs can be difficult to manage and are prone to performance
To ensure the privacy of branch voice, video and data challenges due to:
communications, financial institutions must protect their branch - High IPsec VPN overhead that reduces throughput
banking and interbank networks. Branches need to access - Shared CPU resource utilization for encryption that slows
voice-over-IP (VoIP), desktop virtualization, Active Directory, and firewall performance
software-as-a-service (SaaS) applications securely. - Application layer protocols that are impacted by IPsec and GRE
While companies are using IPsec and TLS Virtual Private - Chatty security protocols increasing latency
Networks (VPNs) to secure communications between branches, - Complex configuration of IPsec and GRE tunnels
corporate offices and hosted application services, encrypted - Security and compliance policies
VPNs are only as secure as the devices and methods used to
encrypt and decrypt the network traffic. Malicious actors target There is an urgent need for solutions that can withstand
system vulnerabilities that allow them to: persistent, sophisticated, and costly cyber threats without
compromising performance or flexibility. VPNs need to be
- Steal plaintext keys that reside in memory hardened to protect data at rest and in transit.
- Decrypt IPsec VPN tunnels
- Impersonate devices with stolen/predicted credentials Cyphre BTX Security Platform
- Compromise mission-critical data and applications Cyphre BTX is a hardware-based network encryption solution
for site-to-site communications that is delivered as an appliance.
Cybersecurity breaches continue to increase by attacking
Deployed at each site, BTX appliances leverage Cyphre’s
vulnerabilities in defense-in-depth security solutions that expose
patented BlackTIE® security engine that offloads encryption
unencrypted data in system memory, the CPU, network and
operations to hardware in a way that protects plaintext
storage. Attackers that gain access to a gateway or network
encryption keys from ever being exposed in the CPU or system
device, may be able to compromise backend systems and
memory.
customer data.

Branch Banking Networks Are Vulnerable to Attacks

Inbound and
Side Channel Attacks and Eavesdropping
Man-in-the-Middle Attacks

Corporate VPN Untrusted VPN Branch VPN Untrusted VPN Branch Edge & IIoT
Office Device Network Device Office Device Network Device Office

Cache Memory Attacks Fireware and Software Vulnerabilities

06/2020
Cyphre BTX appliances are available in multiple form factors to Cyhpre’s turnkey solution is comprised of:
protect remote, edge and cloud deployments. The BTX extends - Cyphre BTX Security Appliances available in multiple form
defense-in-depth approaches and provides: factors for data center or edge deployment
- Tamper-resistant hardware-based security that never exposes - Cyphre BlackTIE Technology hardware-based Security Engine
private keys and encryption keys to the CPU or memory that is integrated with the BTX appliance
- Resistance to side-channel, cache memory and MITM attacks - CyphreLink Application secure site-to-site encryption solution
- Better application performance over high latency, low that leverages BlackTIE
bandwidth links
By handling cryptographic operations in hardware and not
- Reduction of typical IP VPN packet overhead by more than exposing keys in the CPU and memory, Cyphre is able to ensure
50% trustworthy communications to protect critical assets.
- Offload of crypto operations to hardware to reduce CPU load
for encryption and decryption FIPS
- Simple VPN configuration and tunnel management VALIDATED

140-2
IT Schedule 70
- Support for any IP-based network

Cyphre, a RigNet company (NASDAQ:RNET), is a cybersecurity


company deploying disruptive data protection innovations by
enhancing industry standard encryption protocols with our
patented BlackTIE® technology.

For more information


visit our website www.cyphre.com
or contact us at info@cyphre.com

© 2020 RigNet. RigNet is a registered trademark of RigNet, Inc. Enabling Intelligence. Delivering Results.

You might also like