jheary
Distinguished Systems Engineer

Innovative new way to do Email Encryption

Analysis
Sep 17, 20074 mins

Email encryption solutions have always been a headache for users as well as administrators. The most main stream solutions use a pull technology or use PGP. Both of these solutions have proven to have several problems, most notably is their lack of ease of use. Cisco’s IronPort PostX encryption solution breaks away from the status quo with their push technology. Here’s how it works: [img]http://www.jheary.com/encryption1.gif[/img]

  • Sender creates email message. The user can choose to encrypt this message or the IronPort policy engine can encrypt it automatically based on a match within its content security engine. This engine can extract the ascii text from over 390 different filetypes so it can match on things like key words or meta data. For example is a message contained Patient Identifiable Information then the message can be auto encrypted for HIPAA compliance before it is sent out.
  • The email message is encrypted with a unique per sender per message key
  • PostX email messages are delivered to the recipients inbox just like other messages. The full encrypted message is attached to the email as an html attachment.
  • Open the email as normal. The text of the email tells the recipient that they have received a secure email attachment and should open it.
  • The user double clicks on the attachment which opens up in any web browser. The browser displays the secure PostX envelope.
  • If this is your first time using the a PostX system then you will be directed to register to create an account and password. The process is short and self explainatory. After registration is completed the user will receive an account activation email.
  • Now that you have an account return to the PostX envelope and enter your password. The browser will then go back to the Cisco PostX key server (this is a public system hosted by Cisco that all Ironport PostX customers use) to pull down the decryption keys for the message. The message is now decrypted and displayed in the browser.
  • For message recall, expiry, or deletion the original sender can manage this. It works by deleting the message key from the key server. Each time a user tries to open the encrypted message a request for the key is made. If the key has been deleted or has expired then the recipient will no longer be able to read the message.

Besides being extremely easy to use there are other nice things about this email encryption solution:

  • Since this is a push technology, the user received the real message, you don’t have to worry about email storage and the security of those emails. These are common problems for pull technologies that send out links back to a central mail server.
  • No client software needed, unless you count a web browser . This allows it to work with all client operating systems.
  • No requirement for PKI or Certificates management.
  • The PostX encryption software can run on the same IronPort C-series platform that you may already have deployed for email spam, AV, and content scanning already.
  • PostX works with any email client, even web mail clients like yahoo mail, etc.
  • Works with all email systems like exchange, groupwise, notes, etc.
  • It is possible to securely reply and forward postX messages
  • Support for Very large attachments. This works by dynamically stripping and parking large attachments on the IronPort or other Server before they are delivered. The sender doesn’t have to do anything special the system work automatically. A URL is inserted into the original email that will lead the recipient back to the server holding their attachment. This allows the attachment to be delivered via a web browser.

So will this new push technology change the game in email encryption? I think it has some promise. What do you think? For more information visit http://www.ironport.com/ or http://www.ironport.com/resources/encryption_technology.html The opinions and information presented here are my personal views not those of my employeer.

jheary

Jamey Heary, CCIE #7680, is a Distinguished Systems Engineer at Cisco Systems. Jamey sits on the PCI Security Standards Council- Board of Advisors where he provides strategic and technical guidance for future PCI standards. Jamey has authored several security books, his latest is Cisco ISE for BYOD and Secure Unified Access. He also has a patent on a new DDoS mitigation and firewall IP reputation technique. Jamey leads numerous security advisory boards for Cisco Systems and is a founding member of the Colorado Healthcare InfoSec Users Group. He is also recognized as a Distinguished Speaker at Cisco Live. He has been working in the IT field for 19 years and in IT security for 15 years.

More from this author