Important News:SafeLogic's CryptoComply Achieves FIPS 140-3 Validation for 28 OEs and Receives Certificate #4781! Read the blog post!
The SafeLogic Blog
SafeLogic Announces PQC Early Access Program at RSA Conference 2024
May 6, 2024 •Evgeny Gervis
SafeLogic today announced the launch of an Early Access Program (EAP) for its next-generation cryptographic software modules that include comprehensive support for all the PQC algorithms NIST is planning to standardize in the summer of 2024. Available now, these modules will allow SafeLogic customers to test and experiment with PQC algorithms and capabilities such as cryptographic asset discovery, cryptoagility, and hybrid use cases. SafeLogic will be demonstrating these modules in booth #6572 at the RSA Conference 2024 in San Francisco this week.
Quantum computers are promising to offer many benefits to society, but the advent of that technology also carries some risks. One major risk is the threat that quantum computers are expected to pose to the world’s public key (asymmetric) encryption. It is believed that once sufficiently powerful quantum computers are available, they will be able to break most of the widely available public key encryption in use today. Should this risk materialize, the significant negative impact on security, privacy, and trust is hard to overstate.
Correspondingly, NIST has been running a worldwide competition for over five years now to select and standardize PQC algorithms that are resistant to cryptanalytic attacks from future quantum computers. SafeLogic had been working closely with NIST and other industry collaborators on NIST’s NCCOE PQC migration project where it had been leading the PQC migration prioritization workstream.
“For over a decade, SafeLogic has been a trusted and proven cryptographic software solutions partner for companies that require strong, FIPS 140 validated cryptographic software. Our customers include top technology vendors, many of which sell to regulated industries such as the US Public Sector that already have PQC migration requirements in place via various executive orders and congressional actions,” said Evgeny Gervis, CEO of SafeLogic. “These and other customers, such as financial services and healthcare organizations, want to start preparing for PQC migration now, and SafeLogic is excited to be their partner on that journey.”
SafeLogic’s PQC solutions offer several capabilities that organizations migrating to PQC will find important.- PQC algorithms CRYSTALS-KYBER, CRYSTALS-Dilithium, FALCON, SPHINCS+, LMS, and XMSS are now available for customer testing. SafeLogic expects to incorporate these into its FIPS 140 validated CryptoComply software once NIST completes the standardization process and doing so becomes possible.
- SafeLogic takes a unique approach to cryptographic asset discovery by providing real-time operational information for when quantum-vulnerable cryptography is being used. This information can greatly help organizations with their cryptographic inventories and migration prioritization decisions.
- SafeLogic’s approach to cryptoagility builds on CryptoComply’s provider architecture to reduce the effort required for future cryptography migrations.
- SafeLogic’s approach to hybrid mode allows organizations to safely wrap classical FIPS 140-2 or FIPS 140-3 validated encryption in PQC to protect valuable data from “harvest now, decrypt later” attacks while maintaining FIPS compliance and providing defense in depth.
SafeLogic’s PQC solutions offer several distinct advantages:
- Field-Proven Validated Cryptographic Implementations: SafeLogic’s CryptoComply cryptographic software modules have been used in the field for over a decade. SafeLogic’s implementations have achieved FIPS 140 validation status following rigorous testing and review by certified laboratories and NIST. SafeLogic plans to add PQC algorithms to its FIPS 140-3 validated modules once those algorithms are fully standardized.
- Extensive Environment Coverage with Maximum Compatibility. The use of cryptography is ubiquitous across the digital ecosystem, and comprehensive cryptographic software solution providers must be able to cover the full gamut of environments in which cryptography is used. SafeLogic’s modules are available for more programming languages, operating systems, and technology stacks than any alternative. SafeLogic customers use CryptoComply software modules anywhere from mobile and embedded environments, to mainframes, and everything in between. Also, SafeLogic’s modules are designed to serve as drop-in replacements for existing (e.g., open source) cryptographic libraries.
- Commercial Grade Support: As always, SafeLogic’s cryptographic software modules come with an experienced support team ready to provide white-glove service to support its customers’ software and certification needs. SafeLogic can also consult with organizations to assist with their PQC migration planning.
- Support for CNSA 2.0: SafeLogic’s modules support the CNSA 2.0 suite of algorithms, a set of standards that commercial solutions must meet if they are to be used in classified environments.
- Memory Safety: SafeLogic is offering increasingly growing support for cryptographic algorithm implementations in memory-safe languages. It is widely known that using memory safe languages can eliminate whole categories of security issues. A recent White House memorandum has called on the industry to adopt the use of memory-safe languages to the greatest degree possible.
As organizations prepare for PQC migration, the largest migration in the history of cryptography, the dimensions above will be key to meeting their needs in a comprehensive fashion. To learn more about SafeLogic’s PQC EAP, contact sales@safelogic.com.
Evgeny Gervis
Evgeny is the CEO of SafeLogic.
Popular Posts
Search for posts
Tags
- FIPS 140 (111)
- FIPS validation (85)
- Encryption (70)
- cryptography (68)
- NIST (62)
- CryptoComply (60)
- SafeLogic (58)
- Industry News (54)
- cryptographic module (51)
- Conversations (49)
- CMVP (48)
- RapidCert (46)
- compliance (41)
- Ray Potter (33)
- SafeLogic News (33)
- Event (27)
- federal (27)
- CAVP (23)
- Cybersecurity (23)
- FIPS 140-3 (18)
- OpenSSL (16)
- government (14)
- FedRAMP (13)
- CryptoCompact (12)
- Cryptology (12)
- DoD (12)
- RSA (12)
- healthcare (12)
- partners (12)
- NSA (11)
- post-quantum cryptography (11)
- Cloud (9)
- PQC (9)
- security (9)
- CMMC (8)
- Suite B (8)
- testing (8)
- whitepaper (8)
- Approved Products List (APL) (6)
- HITECH (6)
- ICMC (6)
- lab (6)
- CEO (5)
- NIST 800-171 (5)
- NIST 800-53 (5)
- OpenSSL 3.0 (5)
- iOS (5)
- procurement (5)
- C3PAO (4)
- Common Criteria (4)
- HITECH Act (4)
- deadline (4)
- encrypt (4)
- innovation (4)
- procure (4)
- public sector (4)
- Air Force (3)
- BSAFE (3)
- DFARS (3)
- HIPAA Safe Harbor (3)
- HITECH Safe Harbor (3)
- OpenSSL 1.1.1 (3)
- OpenSSL 3.x (3)
- POA&M (3)
- TLS 1.3 (3)
- magazine (3)
- queue (3)
- transition (3)
- 3PAO (2)
- ACVP (2)
- BAA (2)
- CIO (2)
- CSP (2)
- Cyber Defense Magazine (2)
- Defense Industrial Base (2)
- HIPAA security controls (2)
- Historical Status (2)
- MFA (2)
- OpenSSL 1.0.2 (2)
- SPRS (2)
- StateRAMP (2)
- entropy (2)
- excellence (2)
- finance (2)
- founder (2)
- gold (2)
- leader (2)
- maturity (2)
- overlap (2)
- pilot (2)
- rsa conference (2)
- solution (2)
- sponsors (2)
- sunset (2)
- vendor (2)
- year (2)
- Active Status (1)
- Alliance for Digital Innovation (1)
- Android (1)
- CIO Prime Views (1)
- DHS (1)
- DIU (1)
- DIUx (1)
- DOJ (1)
- DoDIN APL (1)
- Entropy Source Validation (1)
- FCA (1)
- FIPS Compliance (1)
- FISMA (1)
- GSA (1)
- HITRUST (1)
- Matt Cornelius (1)
- Matthew Cornelius (1)
- Maturity Model (1)
- NCCoE (1)
- OMB (1)
- SLED (1)
- SP800-131A (1)
- SP800-90A (1)
- TLS 1.1 (1)
- background (1)
- best (1)
- co-founder (1)
- codies (1)
- congress (1)
- cybertech (1)
- education (1)
- elliptic curve cryptography (1)
- extended (1)
- faq (1)
- fintech (1)
- fiscal (1)
- fiscal year (1)
- fraud (1)
- globee (1)
- hill (1)
- interview (1)
- kratos (1)
- libgcrypt (1)
- national cybersecurity strategy (1)
- opportunities (1)
- parallel (1)
- profile (1)
- public (1)
- representatives (1)
- reseller (1)
- senate (1)
- senators (1)
- simplify (1)
- state (1)
- stealth mode (1)
- story (1)
- terminology (1)
- trophy (1)
- whistleblower (1)
- whistleblowing (1)