500 Oracle Parkway Redwood Shores California United States North Americas 94065
Separating encryption keys from encrypted data is a best practice and the foundation of an effective security strategy. Organizations that choose Oracle TDE on Exadata can use CipherTrust Application Key Management (CAKM) with CipherTrust Manager (CM) to secure their database encryption keys to ensure that their database data cannot be accessed without proper authentication and the Master Encryption Key (MEK) to decrypt the Data Encryption Keys (DEKs).
Securing Oracle Exadata Data with CipherTrust - Solution Brief |
Oracle Advanced Security, an option to Oracle Database, helps address privacy and regulatory requirements with its data encryption functionality known as transparent data encryption (TDE) to safeguard sensitive data against unauthorized access to the network, operating system or through theft of hardware or backup media.
While TDE provides encryption, regulations and best practice security call for external encryption key storage and management that enforces appropriate separation of duties. Separating encryption keys from encrypted data is a best practice and the foundation of an effective and compliant encryption strategy.
Fortunately, Thales solves this problem for Oracle TDE customers with two solutions from its portfolio: Thales CipherTrust Manager, and Thales Luna HSM. Organizations will choose between the two options according to the specific needs of their Oracle TDE implementation.
Thales CipherTrust Manager is an encryption key management platform that centralizes Oracle TDE key administration in addition to keys from a wide ecosystem of 3rd party encryption providers. Organizations that choose Oracle TDE can secure and manage their encryption keys with CipherTrust Manager to ensure that an encrypted database cannot be accessed without CipherTrust Manager authentication. This barrier to entry both secures data and serves as a deterrent to any would-be attackers. Customers choose CipherTrust Manager when their primary concerns are externally storing their keys to enforce separation of duties and managing encryption key operations across large-scale landscapes.
Additionally, organizations can choose Thales Luna Hardware Security Modules (HSMs) to secure their Oracle TDE keys in a purpose built, dedicated appliance. With Luna HSMs master encryption keys never leave the secure confines of the physical appliance. Similarly to CipherTrust Manager, storing TDE keys externally in a Thales Luna HSM is considered a sufficient control for a wide variety of data security and privacy regulations. Customers choose Thales Luna HSMs when their primary concerns are secure storage in physical devices, and addressing FIPS 140-2 Level 3 compliance requirements.
Oracle's complete, integrated approach makes it easy for companies to get started in the cloud and even easier to expand as business grows. With Oracle Cloud Infrastructure, developers, IT professionals, and business leaders to develop, extend, connect, and secure cloud applications and share data. Oracle makes the full cloud experience available to its customers in whatever consumption models makes the most sense to them, from standard public cloud offerings to Dedicated Region Cloud@Customer and Roving Edge Devices for greater customer control. Companies use Oracle's IaaS, PaaS and SaaS offerings to run any workload in the cloud, encompassing compute, storage, network, container services, and service-based versions of the legacy Oracle applications customers on which customers have long depended. Oracle Cloud facilitates companies’ efforts to innovate faster, increase productivity, and lower costs.
Oracle encrypts all of the data in its cloud services by default. In partnership with Thales, Oracle relies on CipherTrust Manager for full, customer controlled external key management to satisfy a wide range of compliance and security requirements. In conjunction with Thales’ CipherTrust Data Security Platform, CipherTrust Manager supports Oracle customers’ hybrid and multi-cloud adoption in a secure and controlled way.
Securing Oracle Database with Transparent Data Encryption (TDE) is a security best practice and a critical step to addressing data security and privacy regulations governing sensitive data. As part of its efforts to support customers who manage TDE encryption deployments at scale, Oracle offers its Oracle Key Vault (OKV) encryption management platform to ensure high availability and maximum performance along with compliant security. OKV is available as a virtual machine. Organizations needing hardware encryption key security can connect OKV with Thales Luna HSM to store top-level encryption keys in a FIPS 140-2 Level 3 validated physical appliance. Together OKV and Thales Luna HSM offers the best of both worlds – maximum Oracle performance with the industry’s leading hardware key security.
Securing Oracle Key Vault Keys in Thales Luna Network HSMs - Solution Brief | |
Oracle Key Vault with Thales Luna HSM - Integration Guide |
Oracle WebLogic Server is an enterprise-ready Java Platform, Enterprise Edition (Java EE) application server that supports the deployment of distributed applications. WebLogic Server provides a standard set of APIs for creating distributed Java applications that can access databases, messaging services, and connections to external enterprise systems. Enterprises using WebLogic can deploy mission-critical applications in a robust, highly available, and scalable environment with extensive security features to keep data secure and prevent malicious attacks.
Thales HSMs integrate with Oracle WebLogic Server to provide significant performance improvements by off-loading cryptographic operations from the Server to the HSMs. In addition, the Thales HSMs help provide a secure server environment by protecting and managing the server’s high value SSL private key within a FIPS 140-2 certified hardware security module.
Oracle Secure Global Desktop is a secure remote access solution providing access to applications running on Microsoft Windows, Linux, Oracle Solaris and mainframe servers from a wide variety of popular client devices, including Windows PCs, Macs, Linux PCs, and tablets such as the Apple iPad and Android-based devices. Oracle Secure Global Desktop allows administrators the freedom to use a single solution to provide secure access to a variety of applications and desktop environments in the data center. SafeNet Trusted Access raises the identity assurance level of users accessing Global Desktop with multi-factor authentication solutions that protect identities and ensure that individuals are who they claim to be.
Building on Thales’s award winning authentication service, SafeNet Trusted Access combines authentication and access management in a fully integrated cloud service. Our service lets you transform your business and operate securely in the cloud by preventing data breaches, simplifying access for users, and enabling compliance.
Our customers include over 25,000 organizations and 30 million users worldwide across all industries. Partnering with Thales for the long term, they trust our innovative access management and authentication services to help them securely adopt new ways of doing business on mobile, and in the cloud.
Resources and Additional Information:
SafeNet Authentication Service (SAS) is now SafeNet Trusted Access (STA).
For STA SAML integrations, please refer to STA Application Catalog. For STA RADIUS integrations, please refer to STA RADIUS Integration guides page on Thales Customer Portal.
Oracle Solaris is a enterprise UNIX operating system that provides high performance, scalability, and reliability. Optimized to run Oracle hardware, databases, and middleware for remote access, the Pluggable Authentication Module (PAM) framework lets businesses “plug in” new authentication services without changing system entry services. SafeNet Trusted Access raises the identity assurance level of users accessing Solaris with multi-factor authentication solutions that protect identities and ensure that individuals are who they claim to be.
Building on Thales’s award winning authentication service, SafeNet Trusted Access combines authentication and access management in a fully integrated cloud service. Our service lets you transform your business and operate securely in the cloud by preventing data breaches, simplifying access for users, and enabling compliance.
Our customers include over 25,000 organizations and 30 million users worldwide across all industries. Partnering with Thales for the long term, they trust our innovative access management and authentication services to help them securely adopt new ways of doing business on mobile, and in the cloud.
SafeNet Authentication Service (SAS) is now SafeNet Trusted Access (STA).
For STA SAML integrations, please refer to STA Application Catalog. For STA RADIUS integrations, please refer to STA RADIUS Integration guides page on Thales Customer Portal.
Oracle Access Manager provides the core functionality of sign For STA SAML integrations, please refer toon, authentication, authorization, centralized policy administration, agent management, and real-time session management and auditing for remote access. Built as a 100% Java solution, Access Manager provides rich functionality, extreme scalability and high availability thereby increasing security, improving user experience and productivity, and enhancing compliance while reducing total cost of ownership. SafeNet Trusted Access raises the identity assurance level of users with multi-factor authentication solutions that protect identities and ensure that individuals are who they claim to be. SafeNet Trusted Access provides a cost-effective, innovative, unbeatable security solution that allows businesses to continue using their existing authentication systems.
Building on Thales’s award winning authentication service, SafeNet Trusted Access combines authentication and access management in a fully integrated cloud service. Our service lets you transform your business and operate securely in the cloud by preventing data breaches, simplifying access for users, and enabling compliance.
Our customers include over 25,000 organizations and 30 million users worldwide across all industries. Partnering with Thales for the long term, they trust our innovative access management and authentication services to help them securely adopt new ways of doing business on mobile, and in the cloud.
Resources & Additional Information
SafeNet Authentication Service (SAS) is now SafeNet Trusted Access (STA).
For STA SAML integrations, please refer to STA Application Catalog. For STA RADIUS integrations, please refer to STA RADIUS Integration guides page on Thales Customer Portal.
NetSuite users require security and convenience when accessing their SaaS-based web applications. Thales Authentication Manager provides authentication and identity assurance by collecting each user’s credentials, evaluating these credentials, and then accepting them and allowing access, or, if invalid, prohibiting access. Thales Authentication Manager provides this level of security for enhanced mobile access across WiFi channels, ensuring secure access to sensitive data in web applications.
Thales Authentication Manager Integration Guide Using SAM as an Identity Provider for NetSuite