★ wanayoo — archive 1999 http://www.ibm.com/security/library/wp_pc-chip.htmlNouvelle recherche | Portail wanayoo
IBM ShopIBM Support Download
HomeNewsProductsServicesSolutionsAbout IBM
Search 
IBM : Security : Library : Papers

MOTHERBOARD Security on a PC Chip

 

Security on a PC Chip:
New Technology from IBM Secures Personal Computers

As more and more business start to use computers and the internet for business, we have seen more examples of security violations and a growing concern about security How can the doors to a large enterprise be cracked open with a few smart keystrokes on a personal computer? That's a tough question, and a big part of the problem has been that PCs have never been good at keeping secrets.

IBM has defined a higher standard for PC security with groundbreaking technology that locks PC security right inside the hardware. The new embedded Security Chip, the cornerstone of a complete hardware and software package called IBM Client Security Solutions, is inside the new IBM PC 300PL and IntelliStation personal computer.

Enterprises will use the new plug-and-play system to secure their internal environment and e-business communications, while providing employees and business partners appropriate access to data.

Hardware-enabled security at low cost

"This is the first time PC security has been integrated into a chip embedded on the system board," says Stewart Van Graan, large enterprise segment manager for commercial desktop marketing in IBM's Personal Systems Group. "It offers a low-cost hardware solution and turns a normal PC into a more secure client."

The embedded Security Chip offers functions similar to a smart card at no extra cost. It stores the user's PIN and other user verification information in an reliably encrypted form on the hard disk drive. To decrypt this information, it requires the use of the master key which is kept in the embedded Security Chip.*

"Government agencies and the financial, health, and manufacturing industries will be the first to employ IBM's Client Security Solutions," predicts Dhruv Desai, senior member of Commercial Desktop Development in Raleigh, North Carolina, and chief architect of the chip. "If you're a big bank approving a million-dollar transfer from the U.S. to the UK, the embedded security chip will verify who signed that request."

The health industry can use the product to better control which doctors and HMOs access patient records. Purchasing departments of large manufacturing firms will conduct e-business with suppliers with greater confidence when they submit orders using a digital signature stored on the embedded Security Chip. And government agencies can increase confidentiality of e-mail and gain better control over restricted databases.

More Security, Easier Management

Until now, companies had to install a separate smart card kit to bolster PC security. With all the security functionality now built into the embedded Security Chip, "the system is easier to manage and more reliable than previous solutions," says Van Graan.

The embedded Security Chip also uses Intel's 820 random number generator for producing private and public keys. The Intel 820 random number generator is a hardware component that can produce the high-quality random numbers required by today's advanced encryption algorithms. This represents a marked improvement over the software-based schemes that other systems still use.

"IBM looks at the 'total cost of ownership' for customers when designing its PCs," explains Van Graan. The 300PL includes management solutions to reduce administrative costs over its lifetime. With IBM Client Security Solutions now built into the 300PL and IntelliStations, large and medium-size enterprises will be able to cut administrative costs even further and increase their level of security at the same time.

About the chip and architecture

Desai and his team developed the embedded Security Chip by drawing upon IBM's expertise in mainframe and midrange security hardware.

The chip is a hardware component that communicates with the main processor of the IBM 300PL through a special interface. It is compatible with Microsoft operating systems and Web browsers, and the Netscape browser.

A few highlights: - Cryptographic services normally provided by popular browsers now are provided in the hardware by the embedded Security Chip.

- The embedded Security Chip's library of tools includes a hardware-based random number generator and functions for key encryption.

- A User Verification Manager identifies individuals using the system and determines access rights and privileges through passwords, in addition to UVM aware fingerprints and smart cards.

- The embedded Security Chip is part of IBM's Client Security Solutions, whose architecture for key management safeguards private objects - whether they be encryption keys, passwords or fingerprint templates.

Compatible with SecureWay Policy Director

User Verification Manager can communicate with SecureWay Policy Director - IBM's software for implementing security policies. For example, if the Policy Director permits only certain worldwide sales managers to update a company's sales database, IBM systems with the embedded Security Chip will enforce that rule and identify the authorized users.

The combination of IBM's Client Security Solutions and Policy Director is designed to save companies time. "Policy Director integrates your security policy into your company's software systems" says Austin-based Bob Kalka, IBM security product line manager. "Secure Client extends that integration right into the hardware on your desktop."

Client-Side Security on the Rise

"The major access device to company databases and programs is the PC," notes Desai. "If one of your end-points is not secure, your whole infrastructure is at risk." For that reason, many enterprises need to strengthen employee security on the PC.

Preventing unauthorized access is only one part of PC security, however. "Security is about giving people access to the information they need in a safe way," says Van Graan. For example, a company wants to make sure the payroll department -- not the marketing department -- has access to payroll data from its PCs.

Security on the client side is essential for business-to-business and business-to-consumer transactions over the Internet. When a purchasing department sets up an electronic relationship with suppliers, for instance, good PC security will ensure that all parties are protected with a confidential flow of information and verifiable digital signatures on agreements and contracts.

Physical security

For complete safety, companies also need physical barriers to computer crime. IBM offers solutions such as Alert on LAN, Alert on LAN II, AssetID, chassis-intrusion detection, and security keylocks to protect the physical integrity of the PC and complement other security features of IBM Client Security Solutions.

For more information on IBM Secure Client:

Client Security Solutions: http://www.pc.ibm.com/us/ibmpc/index.html

IBM physical PC security products:
http://www.pc.ibm.com/us/products/desktop/300pltour/protect.html

Additional IBM Security offerings: http://www.ibm.com/security

 
PrivacyLegalContact
---