HPE Software Unveils Industrys First FIPS-Validated Format-Preserving Encryption Solution
April 26, 2017 • News Advisory
HPE SecureData delivers first NIST-standardized data-centric security to neutralize data breaches and enable public and private sector collaboration
PALO ALTO, Calif., April 13, 2017 – Hewlett Packard Enterprise (HPE) today announced that HPE SecureData has achieved the industry's first Federal Information Processing Standard (FIPS) 140-2 validation of Format-Preserving Encryption (FPE). HPE SecureData with Hyper FPE delivers a NIST-standardized method of protecting data at-rest, in-motion, and in-use, and maintains the format, meaning, value and logic in the data. Now, government agencies and private contractors serving government customers, can leverage the same powerful and proven technology that has transformed cybersecurity in the private sector.
A major challenge faced by federal agencies, including those attacked by nation state adversaries, is the dependency on legacy applications and platforms with limited native data security options. HPE SecureData helps build data security into both new and legacy applications, de-identifying high-value data classes; for example, protecting classified information, or eliminating reliance on using Social Security Numbers for business processes. Security assurance is increased, while unleashing the utility of data for secure adoption of big data analytics such as Hadoop and other new applications and solutions.
"Government agencies set the high bar for protecting both their sensitive data and citizen data across multiple platforms and applications, both legacy and modern," said Albert Biketi, vice president and general manager, HPE Security Data Security at Hewlett Packard Enterprise. "With the HPE SecureData FIPS validation, government agencies and contractors can now use a standardized data security product with extensive enterprise deployments, neutralizing data breaches while liberating analytics and innovation."
HPE SecureData has the worlds first FIPS-validated AES-FF1 encryption configuration option to operate in strict FIPS mode. This enables public sector customers to take advantage of true FIPS-validated and approved cryptography when building compliance programs for regulations such as the Cybersecurity Act of 2015 data security requirements, DFARS CUI, and General Data Protection Regulations(GDPR).
HPE SecureData with Hyper FPE has the ability to "de-identify" virtually unlimited data types, from sensitive personally identifiable information (PII), to IDs, health information or classified data, rendering it useless to attackers in the event of a security breach. This allows government agencies to securely leverage the de-identified data for big-data analytics, and collaborate with shared data between other agencies or contractors. It also provides accelerated encryption speeds that enable government agencies to adopt new technologies, such as the cloud or Hadoop or invest in innovations such as IoT, all while lowering the risk of disclosing sensitive personal data or compromising high value data.
Full integration with HPE Atalla HSM
HPE SecureData is fully integrated with HPE Atalla HSM, a hardware appliance validated to FIPS 140-2 Level 3, offering organizations greater physical and logical data protection. HPE Atalla HSM stores and manages root keys, with centralized configuration and security policy enforcement, making it simple for customers to take a holistic approach to managing data protection.
HPE SecureData with FIPS validation is currently available globally, and delivers data security for governance, risk and compliance across public and private sector mission-critical systems for cloud, big data, IoT, payments, mobile data capture, and applications.
About HPE Security
HPE Security helps organizations protect their business-critical digital assets by building security into the fabric of the enterprise, detecting and responding to advanced threats, and safeguarding continuity and compliance to effectively mitigate risk. With an integrated suite of market-leading products, services, threat intelligence and security research, HPE Security empowers organizations to balance protection with innovation to keep pace with todays idea economy. Find out more about HPE Security at https://www.hpe.com/us/en/solutions/protect-digital.html.
Join HPE Software on LinkedIn and follow @HPE_Software on Twitter. To learn more about HPE Enterprise Security products and services on Twitter, please follow @HPE_Security and join HPE Enterprise Security on LinkedIn.
About Hewlett Packard Enterprise
Hewlett Packard Enterprise is an industry-leading technology company that enables customers to go further, faster. With the industrys most comprehensive portfolio, spanning the cloud to the data center to workplace applications, our technology and services help customers around the world make IT more efficient, more productive and more secure.
This document contains forward-looking statements within the meaning of the safe harbor provisions of the Private Securities Litigation Reform Act of 1995. Such statements involve risks, uncertainties and assumptions. If such risks or uncertainties materialize or such assumptions prove incorrect, the results of Hewlett Packard Enterprise could differ materially from those expressed or implied by such forward-looking statements and assumptions. All statements other than statements of historical fact are statements that could be deemed forward-looking statements, including any statements of the plans, strategies and objectives of Hewlett Packard Enterprise for future operations; other statements of expectation or belief; and any statements of assumptions underlying any of the foregoing. Risks, uncertainties and assumptions include the possibility that expected benefits may not materialize as expected and other risks that are described in Hewlett Packard Enterprises filings with the Securities and Exchange Commission, including but not limited to the risks described in Hewlett Packard Enterprises Registration Statement on Form 10 dated July 1, 2015, as amended August 10, 2015, September 4, 2015, September 15, 2015, September 28, 2015 and October 7, 2015. Hewlett Packard Enterprise assumes no obligation and does not intend to update these forward-looking statements.