* Shocked by the negative reaction of some to EMC's planned purchase of RSA Security
I’m not typically in the habit of dissing my fellow industry-watchers, but I have to say, I was actually shocked at the negative reaction of some to EMC’s announcement of its planned acquisition of RSA Security.
I’m amazed that so many – who should know better – don’t see the essential synergy between solutions that manage information, and those that secure it, maintain its confidentiality, and control access to it.
Have these industry watchers forgotten that for many years RSA owned a monopoly on the first true public key cryptosystem of the same name, and still maintains strong assets in this domain? If so, perhaps they don’t fully appreciate that public key cryptography (PKC) is essentially an identity technology, directly linking people with information access and security. Or perhaps they have no understanding just how critical experience in this domain is to the success of an information security strategy.
Here’s a brief, and necessarily oversimplified, digression to explain: PKC enables encryption “keys” – the factors used in equations that both encrypt and decrypt information – to be generated in pairs. The two keys in a PKC “keypair” are different but directly related to each other in such a way that one can encrypt what the other decrypts. Keeping one of the keys private enables anybody to use the other key to encrypt data that can be decrypted only by the owner of the corresponding private key, hence why the nonprivate key is known as the “public” key. Thus, the use of a specific public key limits information access to a specific private key owner. Turn this technology around, and you have digital signature – the encryption of data with the private key that anyone can decrypt with the corresponding public key, and only that key, thus identifying the source of the information. These are the characteristics that make PKC technologies such as RSA cryptography primarily identity, information access, and information authentication technologies – more so, in fact, than they are used as encryption technologies per se, since PKC is computationally expensive and usually limited to identifying parties in a data exchange.
PKC authentication operations are typically used to secure the keys that do the actual symmetric encryption/decryption itself, using DES variants or AES, for example. These are the strong identity, information authentication and information access capabilities that the company RSA Security, Inc. (referred to hereafter as “RSAS” to avoid confusion with RSA cryptography) has extended through solutions such as its highly successful SecurID multifactor authentication systems.
The ownership of breakthrough cryptographic technology alone would not explain the high value associated with RSAS, however. What EMC saw – and it is a case of uniquely well informed executive insight into the practical aspects of applied technology – is that one of the thorniest challenges in securing information is not the technology of crypto itself. It is the management of all these keys – which, again, are only factors in an equation – that can quickly scale out of control in any enterprise-scale application of cryptography to persistent data security. (Just ask anyone who has ever been tasked with such a deployment!) In this domain, success is directly related to experience. At a time when just such success is critical to any company with a stake in information management, EMC felt it had to pay the price.
These factors explain why the terms of this deal – approximately $2.1 billion, in cash – were so steep. Though its products are no longer unique (its monopoly on the RSA cryptography patent expired in 2000), the ownership of RSAS was seen as critical to those who are most concerned with information management, of which EMC is in the top tier. This suggests that the bidding for RSAS was competitive, probably highly so, and it is not hard to see players such as Symantec or the Sun-StorageTek combination having a serious interest. In particular, while Sun already has significant identity assets, many have felt that Symantec has long needed to own a leadership stake in identity, not least because of its centrality to data security and its essential value to the Symantec-Veritas combination. RSAS was consequently seen by many as a likely Symantec target.
In the end, however, while Symantec or others may have had the cash and the will to raise the stakes, only EMC was willing to pony up $2.1 billion on the barrelhead. EMC was willing to take the short-term hit (no mean feat in light of the company’s stock performance over the past year), because it appreciates just how vital strong credibility in information security means to its very existence going forward. This speaks to EMC’s ability to judge the value as well as the cost of taking the long view – and it’s a view that would have been more fitting of market-watchers who are supposed to be expert in what these technologies really mean, and why they are valued as they are.
As it was, the ill-informed reaction of the market made its shortsighted disappointment look more like we still haven’t learned anything from the day-trader mentality of the late ’90s – and even less from the information security breaches of the past several months.
* To register for Scott’s full impact brief published by EMA on this acquisition, please go to EMA’s Web site.




