You are on page 1of 2

Protection for Data-in-Transit

for Electric Utilities


Protecting SCADA Communications VPNs can be difficult to manage and are prone to performance
To ensure the safety and reliability of power generation, challenges due to:
transmission, and distribution systems, utilities and operators - High IPsec VPN overhead that reduces throughput
must protect their supervisory control and data acquisition - Shared CPU resource utilization for encryption that slows
(SCADA) communications networks. To protect control system firewall performance
devices, organizations are integrating IPsec and TLS Virtual - Application layer protocols that are impacted by IPsec and GRE
Private Networks (VPNs) with new protocols such as Distributed
- Chatty security protocols increasing latency
Network Protocol Secure Authentication (DNP3-SA). Under
- Complex configuration of IPsec and GRE tunnels
the IEEE 1815-2012 DNP3 standard, DNP3-SA enables
authenticated master-outstation communications. - Security and compliance policies

Encrypted VPNs are only as secure as the devices and methods There is an urgent need for solutions that can withstand
used to encrypt and decrypt the network traffic. Malicious actors persistent, sophisticated, and costly cyber threats without
target system vulnerabilities that allow them to: compromising performance or flexibility. VPNs need to be
hardened to protect data at rest and in transit.
- Steal plaintext keys that reside in memory
- Decrypt IPsec VPN tunnels Cyphre BTX Security Platform
- Impersonate devices with stolen/predicted credentials Cyphre BTX is a hardware-based network encryption solution
- Compromise mission-critical data and applications for site-to-site communications that is delivered as an appliance.
Deployed at each site, BTX appliances leverage Cyphre’s
Cybersecurity breaches continue to increase by attacking
patented BlackTIE® security engine that offloads encryption
vulnerabilities in traditional security solutions that expose
operations to hardware in a way that protects plaintext
unencrypted data in system memory, the CPU, network and
encryption keys from ever being exposed in the CPU or system
storage. Attackers that gain access to an intelligent edge device
memory.
(IED), remote terminal unit (RTU), gateway or network device,
may be able to compromise the control systems and the quality
of performance data.

SCADA Networks Are Vulnerable to Attacks

Inbound and
Side Channel Attacks and Eavesdropping
Man-in-the-Middle Attacks

Power VPN Untrusted VPN Power VPN Untrusted VPN Outstation Edge & IIoT
Generation Device Network Device Distribution Device Network Device

Cache Memory Attacks Fireware and Software Vulnerabilities

06/2020
Cyphre BTX appliances are available in multiple form factors to Cyhpre’s turnkey solution is comprised of:
protect remote, edge and cloud deployments. The BTX extends - Cyphre BTX Security Appliances available in multiple form
defense-in-depth approaches and provides: factors for data center or edge deployment
- Tamper-resistant hardware-based security that never exposes - Cyphre BlackTIE Technology hardware-based Security Engine
private keys and encryption keys to the CPU or memory that is integrated with the BTX appliance
- Resistance to side-channel, cache memory and MITM attacks - CyphreLink Application secure site-to-site encryption solution
- Better application performance over high latency, low that leverages BlackTIE
bandwidth links
By handling cryptographic operations in hardware and not
- Reduction of typical IP VPN packet overhead by more than exposing keys in the CPU and memory, Cyphre is able to ensure
50% trustworthy communications to protect critical assets.
- Offload of crypto operations to hardware to reduce CPU load
for encryption and decryption FIPS
- Simple VPN configuration and tunnel management VAꢀIDATED

140-2
IT Schedule 70
- Support for any IP-based network

Cyphre, a RigNet company (NASDAQ:RNET), is a cybersecurity


company deploying disruptive data protection innovations by
enhancing industry standard encryption protocols with our
patented BlackTIE® technology.

For more information


visit our website www.cyphre.com
or contact us at info@cyphre.com

© 2020 RigNet. RigNet is a registered trademark of RigNet, Inc. Enabling Intelligence. Delivering Results.

You might also like