ellen_messmer
Senior Editor, Network World

Eastman Kodak embraces encryption, forgoes certificates

News
Mar 4, 20083 mins

Identity-based encryption wins out over PKI

Photographic equipment maker Eastman Kodak is focusing on protecting the confidentiality of e-mail communications among employees and business partners by using an encryption technology known as “identity-based encryption.”

Photographic equipment maker Eastman Kodak is focusing on protecting the confidentiality of e-mail communications among employees and business partners by using Voltage Security’s technology known as Identity-Based Encryption  IBE, part of Voltage’s SecureMail offering, eliminates much of the key distribution and management hassle, according to Kodak’s technology managers.

In the past, Kodak has made use of a public-key infrastructure (PKI) with digital certificates issued to individuals for encryption and decryption. But Kodak found management of X.509 certificates to be an unwieldy process because of the validation and revocation-list procedures, which are made more complex when certificate distribution must be extended outside the internal organization.

“For five years we went down the certificate path but found it difficult to manage certificates and exchange keys,” says Janel Egli, information systems and business analyst at Kodak, about how hard it was to wrestle with a traditional PKI.

But business encryption for Kodak was only growing more important, so after a review of options, the Rochester, N.Y.-based firm decided on SecureMail.

Kodak has been so pleased with it, the company is going to use it to encrypt e-mail with more than 30,000 individuals, including company employees and outside business partners.

“Encryption is some areas is a requirement for us, and with some of our suppliers, we’re going to require it,” says Bruce Jones, Kodak’s global information technology security and risk manager. “We’re implementing it because of the ease of use and integration with our mail systems, including Lotus Notes.”

Terence Spies, chief technology officer at Voltage, says IBE works by encrypting e-mail with a public key constructed from the recipient’s e-mail address and the name of the key server that can calculate the decryption key.

To decrypt the received encrypted e-mail, the recipient contacts the key server, which can be located at the sender’s enterprise or with a third-party party service.

For the e-mail to be decrypted, the policy of that key server determines how it will authenticate the recipient before giving over the key that will decrypt the e-mail.

The key server might typically contact a directory or other external authentication source to authenticate the recipient’s identity or establish any other security-policy stipulations. The authentication method required under the policy can vary, from simple passwords to SecurID tokens to certificates.

After the authentication process, the key server returns the private key that lets the recipient decrypt the message. Because the key is generated only using the recipient’s e-mail address, the recipient doesn’t have to download software in advance of receiving the IBE-encrypted message.

With IBE, users never see or deal with a certificate because each certificate is sent along transparently to them with each message, says Spies says.

IBE was first devised in the mid-1980’s by Adi Shamir, the Israeli cryptographer who’s the co-inventor of the RSA cryptographic algorithm.

“Today, Stanford University has a patent license on the technology used by Voltage,” says Spies, who has sought to champion IBE as a standard at the IEEE and IETF organizations.

However, he acknowledged patent issues could slow that down. At least one other firm has commercialized some form of IBE: Identum, which was acquired by Trend Micro last week. The Identum and Voltage technologies are similar but not exactly the same, Spies says. The advantage in having a standardized IBE would be “broad-based consensus that there is a right way to do this.”

Voltage says 450 corporate customers are making use of its IBE software.