Strategic cooperation creates integrated solution for network connections at public authorities and in critical infrastructures Central management of layer 2 and layer 3 encryption in an integrated solution BSI-approved for German VS-NfD and EU/NATO classification level "Restricted" Kirchheim and Berlin (Germany), March 12, 2024. The German IT security specialist genua and the German Adva Network Security have signed a long-term strategic cooperation agreement. The two companies are combining their expertise in highly secure Metro and VPN networks to create an integrated solution intended for customers with high protection requirements and ensuring maximum IT security and performance. genua will bring to the table its decades of experience in secure layer 3 networking, while Adva Network Security is contributing its proven Ethernet access technology with layer 2 encryption. This combination will deliver a unified solution tailored for large-scale EU/NATO communication infrastructures and has approval from the Federal Office for Information Security (BSI) for the transmission of data with the German VS-NfD and EU/NATO classification level "Restricted". With the BSI’s cooperation, the two companies will focus primarily on the regulated market, i.e., public authorities , critical infrastructure companies and the healthcare sector. Seamless integration of layer 2 and layer 3 Within the framework of the cooperation, genua will first add Adva Network Security’s FSP 150-XG118Pro network access device to its product range – a device that enables up to 40 Gbit/s encrypted data throughput in real time. With its Metro Ethernet functions and the BSI-approved L2 encryption, this system complements genua's proven layer 3 solution genuscreen for secure communication via VPN. Beyond the current reseller agreement, genua and Adva Network Security intend to work jointly on further developing their combined solution. Initially, this collaboration will focus on an integrated configuration and management of the combined layer 2/layer 3 encryption using the management system genucenter, set to be implemented in 2024. For the end customer, the integration of the two technologies into a single management system will simplify site networking, particularly in critical environments, and therefore make it much more cost-effective. "The partnership with Adva Network Security enables us to expand our sales and technological capabilities by offering approved layer 2 encryption components. This will allow us to address the high IT security requirements of our customers in an even more needs-oriented manner," explains Marc Tesch, Managing Director of genua GmbH, with regard to the strategic cooperation with Adva Network Security. "Together, we can offer our customers an integrated, flexible solution that is easy to operate and also fulfils very high security requirements with BSI approval. Our collaboration will make an important contribution to strengthening Germany as a cyber nation," comments Josef Sißmeir, Managing Director of Adva Network Security GmbH, on the significance of the partnership. Technical Background Typically, site networking uses various VPN technologies. With a Layer 2 VPN, for example, data can be transmitted securely between two data centres via encrypted Ethernet connections, ensuring complete transparency for higher network layers. Layer 3 VPN enables the secure transmission of individual data streams between two end devices on an IP basis, regardless of the transmission technology (e.g., DSL, mobile radio, WLAN). Central sites are usually connected by means of layer 2 encryption, like that from Adva Network Security, whereas smaller sites, home offices or mobile users can be securely connected using genua's layer 3 technology. Gradual integration Technical integration of Adva Network Security’s secure access technology into the central management solution genucenter will take place in several steps. The Network Configuration Protocol (NETCONF) is used as the interface. In addition to dashboards for displaying the status, genucenter also provides object-oriented templates for the configuration. This genucenter add-on allows scalable and flexible configuration of protected Ethernet connections in a proven management system. Further information More about genucenter More about genuscreen More about FSP 150-XG118Pro Image captions: Marc Tesch, Managing Director of genua GmbH Josef Sißmeir, Managing Director of Adva Network Security GmbH The FSP 150-XG118Pro network access device from Adva Network Security enables up to 40 Gbit/s encrypted data throughput in real time genucenter enables the central management of Layer 2 and Layer 3 encryption in one integrated solution ( RGB CMYK ) © genua GmbH, Adva Network Security Press Contact Adva Network Security Adva Network Security GmbH Ulrich Kohn Marketing T +49 171 73 92 378 E ulrich.kohn@advasecurity.com About Adva Network Security Adva Network Security has built a fierce reputation for protecting packet optical networks. We pioneered low-latency, multi-layer encryption solutions that are right now safeguarding data in motion for many mission-critical applications. Our ConnectGuardTM security technology is even combating tomorrow’s quantum security threats. Built by the industry’s leading security experts, our German-based organization helps organizations and government agencies security-harden their networks to ensure critical infrastructure is protected against cyber threats. Our development and manufacturing processes, as well as our security solutions, have been approved and certified by leading governmental security agencies. For more information on how we can help you, please visit www.advasecurity.com .
genuconnect Enterprise provides your organization with a security level comparable to approved solutions. The VPN software client connects remote employees easily and reliably to company networks. The solution is characterized by low complexity, high scalability, and convincing usability. And if your security needs increase: simply switch to the approved genuconnect version. Learn more: Visit product page Contact and service: + 49 89 991950-902
Remote access is an important tool for gaining quick and cost-effective access to automation technology in the process industry. For example, it enables the maintenance of production systems and thus ensure trouble-free operational processes. However, remote access also poses a significant risk: through inadequately secured access to the target system, unauthorized persons or malware can get into the network and cause serious damage. The “NAMUR Recommendation: Remote Access” offers a recognized expert guidance in eight chapters developed by process industry experts. Secure Remote Access to Plants in the Process Industry As a manufacturer of a highly secure remote maintenance solution, genua covers all solution-specific requirements for a secure architecture for process industry remote access, which result from chapters 5 to 7 of the NAMUR Recommendation. For implementing the processes recommended in chapter 7, you can receive consulting and support from genua or from specialized partners in your area upon request. Learn more: Solution overview (PDF) genubox product information Contact and service: + 49 89 991950-902
Rendezvous-based solution enables secure, browser-based remote maintenance, even on security-critical systems Machine and plant manufacturers receive even more flexibility for secure remote service Nuremberg, Germany, October 12, 2023, it-sa – In addition to its proven native Microsoft Windows app for its remote maintenance solution genubox, the German IT security specialist genua now also supports remote access via a web interface. This makes remote maintenance even more independent of time and location and of the operating system of the remote maintenance client. Even mobile remote maintenance sessions on security-critical machines and plants while underway, e.g., via the browser of a tablet PC, can be performed with genubox with reliable protection. Secure Access from Every Device The new web interface for genubox enables the https-based establishment of a remote desktop connection to a rendezvous server to initiate a pre-configured remote maintenance session. The identity verification of the user is performed via identity providers such as OKTA, Microsoft Entra ID or Keycloak using the OpenID Connect identity protocol. The genubox rendezvous server can thereby be located in the demilitarized zone (DMZ) of the LAN operator, of the remote maintenance provider or in the cloud. Following successful login and if the remote maintenance session was approved by the plant operator, remote maintenance providers then see by means of RDP (Remote Desktop Protocol), VNC or SSH (Secure Socket Shell) all connected target systems for which they have been authorized. The genubox solution offers very granular control that can be used to specify which remote maintenance provider can access which target system and with which application. It thereby supports modern zero trust concepts. Rendezvous Architecture is State of the Art As a rendezvous-based solution, the genubox remote maintenance corresponds to the gold standard for secure remote maintenance architectures recommended by the German Mechanical Engineering Industry Association (VDMA). It also satisfies all BSI recommendations for secure remote maintenance in industrial environments. Depending on customer requirements, hardware-based, visualized or hybrid setups are possible. Further information • Product page for remote maintenance with genubox Image Caption The new web interface for genubox remote maintenance from genua enables the highly secure, https-based establishment of a remote desktop connection to a rendezvous server. Image: Laptop web interface for genubox remote maintenance DOWNLOAD Image: Tablet web interface for genubox remote maintenance DOWNLOAD © genua GmbH Press ContaCt Kafka Kommunikation Kafka Kommunikation GmbH & Co. KG Mona Bastian Dr. Torben Gülstorff E genua@kafka-kommunikation.de T +49 89 74747058-0
Rendezvous-based solution enables secure, browser-based remote maintenance, even on security-critical systems Machine and plant manufacturers receive even more flexibility for secure remote service Nuremberg, Germany, October 12, 2023, it-sa – In addition to its proven native Microsoft Windows app for its remote maintenance solution genubox, the German IT security specialist genua now also supports remote access via a web interface. This makes remote maintenance even more independent of time and location and of the operating system of the remote maintenance client. Even mobile remote maintenance sessions on security-critical machines and plants while underway, e.g., via the browser of a tablet PC, can be performed with genubox with reliable protection. Secure Access from Every Device The new web interface for genubox enables the https-based establishment of a remote desktop connection to a rendezvous server to initiate a pre-configured remote maintenance session. The identity verification of the user is performed via identity providers such as OKTA, Microsoft Entra ID or Keycloak using the OpenID Connect identity protocol. The genubox rendezvous server can thereby be located in the demilitarized zone (DMZ) of the LAN operator, of the remote maintenance provider or in the cloud. Following successful login and if the remote maintenance session was approved by the plant operator, remote maintenance providers then see by means of RDP (Remote Desktop Protocol), VNC or SSH (Secure Socket Shell) all connected target systems for which they have been authorized. The genubox solution offers very granular control that can be used to specify which remote maintenance provider can access which target system and with which application. It thereby supports modern zero trust concepts. Rendezvous Architecture is State of the Art As a rendezvous-based solution, the genubox remote maintenance corresponds to the gold standard for secure remote maintenance architectures recommended by the German Mechanical Engineering Industry Association (VDMA). It also satisfies all BSI recommendations for secure remote maintenance in industrial environments. Depending on customer requirements, hardware-based, visualized or hybrid setups are possible. Further information • Product page for remote maintenance with genubox Image Caption The new web interface for genubox remote maintenance from genua enables the highly secure, https-based establishment of a remote desktop connection to a rendezvous server. Image: Laptop web interface for genubox remote maintenance DOWNLOAD Image: Tablet web interface for genubox remote maintenance DOWNLOAD © genua GmbH Press CONTACT Kafka Kommunikation Kafka Kommunikation GmbH & Co. KG Mona Bastian Dr. Torben Gülstorff E genua@kafka-kommunikation.de T +49 89 74747058-0
IT security provider genua meets high industry demand for OPC-UA-native encryption with cyber-diode 2.5 Additional optimizations reduce the data load and, thus, the total-cost of ownership Nuremberg, Germany, October 12, 2023, it-sa – In cases where information from sensitive production networks or critical infrastructures is needed for further processing, data diodes like cyber-diode from IT security company genua GmbH are, for security aspects, the first choice. This enables a non-reactive extraction of machine and plant data in non-secure networks, such as in the cloud for data analysis. In the most recent version, 2.5, cyber-diode now also supports the encryption and authentication in accordance with the OPC UA interoperability standard. genua thereby satisfies the high demand in industry for OPC UA-native encryption. Highly Secure Vertical and Horizontal Data Extraction OPC UA enables the platform-independent communication and standardized exchange of machine data, both horizontally (i.e., networking of control systems, individual machines, plants or production units) as well as vertically (from the machine sensor to the cloud). Through the use of cyber-diode, for example, between OPC UA servers of machines and targets such as databases, visualization clients or cloud services, data can be encrypted for further processing and extracted in a highly secure manner – e.g., for condition monitoring. The data diode thereby permits only one-way data transfer. It completely blocks the flow of information in the opposite direction. The transport of malicious code or other cyber risks are thereby rendered impossible. Reading Out Partial Quantities Reduces TCO Moreover, the new version of cyber-diode allows information to be extracted from a sub-quantity of UPC UA nodes. For example, in cases where machinery transmits comprehensive data, the data load is reduced and the transmission speed of the remaining data is increased, since the diode only allows data that is relevant to the target system to pass through. Depending on the license model for plant components and source server, this can also reduce the total cost of ownership (TCO). For some source servers available on the market, the license costs depend on the quantity of extracted data. Secure by Design cyber-diode is the only industrial software data diode that can serve as the basis for a product approved for the protection of classified data. Its unique hardware separation on a microkernel level guarantees the integrity protection of highly secure industrial networks. A low level of complexity of the operating system (Security by Design) ensures the functionality, protects against tampering and lowers the risk of machine failure. Further information • Product page for the Data Diode cyber-diode Image Caption cyber-diode example application: The image shows cyber-diode (left) from the security specialist genua, which securely transmits the data from a security control system (HIMatrix) to a cloud application by way of OPC UA for the purpose of calculating test cycles for devices and control systems. DOWNLOAD Image: genua GmbH Press ContaCt Kafka Kommunikation Kafka Kommunikation GmbH & Co. KG Mona Bastian Dr. Torben Gülstorff E genua@kafka-kommunikation.de T +49 89 74747058-0
Company of The Bundesdruckerei Group supplies secure remote maintenance solution for Magenta Remote Access Service MSIRAS With Open Telecom Cloud, genubox and IT security solutions, industrial customers receive a comprehensive range of solutions “Made in Germany” from a single source Nuremberg, Germany, October 12, 2023, it-sa – With the Magenta Secure Industrial Remote Access Service – abbreviated MSIRAS – Deutsche Telekom Security GmbH offers a new managed service package for secure remote maintenance in industry (Industrial RAS). For remote access in sensitive industrial networks, the IT security provider makes use here of a highly secure technology from the IT security specialist genua GmbH, a company of the Bundesdruckerei Group. genubox was developed in Germany specifically for industrial environments and satisfies all recommendations of the German Federal Office for Information Security (BSI) for secure remote maintenance. Unsecure Remote Maintenance Among the Top Ten Cyber Threats In systems for production and process automation (industrial control systems, ICS), e.g., in energy supply, factory automation or traffic control technology, external access points are very common for maintenance purposes. These are necessary as the respective manufacturers and external service providers must often be called upon for maintenance and programming of components. According to the BSI , among the most critical and commonly occurring threats to industrial control system security is the use of such remote maintenance points by cyber criminals to break in – and the trend is rising. Secure Remote Maintenance with MSIRAS As a result, the demand for secure remote maintenance solutions and accompanying managed services is high. MSIRAS addresses this demand as a trustworthy complete solution “Made in Germany” that combines the expertise of Deutsche Telekom Security GmbH and genua GmbH. It is characterized, in particular, by the high-security remote maintenance solution genubox with the central management solution genucenter , a trustworthy, virtual private cloud (VPC) hosted in Germany as well as extensive managed security services For the secure remote maintenance access point, the MSIRAS architecture hosts a genubox rendezvous server from genua with the corresponding central management system genucenter in a virtual private cloud (VPC) within the Open Telekom Cloud (OTC). Within the cloud, the VPC is fully separated from the instances of other clients. The rendezvous architecture of genubox ensures that only authorized external users obtain access to previously specified services and target systems and then only at an agreed-upon time and for the specified period. For this purpose, genubox features a fine-grained, sophisticated rights and role system and is suitable for a very targeted access control, including the implementation of zero-trust concepts. Moreover, the system enables an SIEM connection and offers logging functions as well as a video recording function for revision-optimized documentation of all maintenance work. MSIRAS, on the basis of genubox, thereby enables the central management of remote maintenance access points with complete control over maintenance action, access time, target and accessing instance. Depending on customer requirements, the configuration of the remote maintenance solution can be completely outsourced to Deutsche Telekom Security or performed by the customer within the framework of shared management via a separate management tunnel. Comprehensive Engineering Services and Managed Services With their more than 1,600 security experts, Deutsche Telekom Security supports MSIRAS customers according to their needs during the realization of the remote access, from the rough planning of the architecture and testing of the location requirements to the integration planning and migration to the operation, including CERT management and monitoring. “The combination of the strengths of Deutsche Telekom Security in the cloud and network sector with our remote maintenance solution offers customers a managed service from a single source and OT security “Made in Germany,” explains Markus Maier, Product Owner for Industrial Products at genua GmbH. “Customers can thereby quickly establish remote maintenance that is compliant with a basic level of protection whose infrastructure – all the way to the interface at the customer location – is completely operated by Telekom.” Further information to the genubox product page more about Deutsche Telekom Security (German only) Image Caption Conceptional representation of the MSIRAS architecture DOWNLOAD Image: © Deutsche Telekom Security GmbH / genua GmbH Press ContaCt Kafka Kommunikation Kafka Kommunikation GmbH & Co. KG Mona Bastian Dr. Torben Gülstorff E genua@kafka-kommunikation.de T +49 89 74747058-0
Company of The Bundesdruckerei Group Achieves an Increase in Sales Again in 2022 Government Requirements Create a Favorable Market Environment for High-Quality IT Security Continuously Growing Demand for Secure Solutions for Mobile Work and Critical Infrastructure Kirchheim near Munich, July 20, 2023. In fiscal year 2022, genua GmbH was once again able to increases its turnover – this time to 75.3 million euros (2021: 66.8 million euros). This means that over the last five years the German IT security specialist has recorded an average annual increase in growth of 22.5 percent (CAGR). In 2022, a significant proportion of this growth was due to genua's solution portfolios and infrastructure components for secure remote access. genua GmbH is part of the Bundesdruckerei Group and specializes in IT security for authorities, critical infrastructure, and other organizations that require a high level of protection against cyber attacks. Although the coronavirus crisis ended some time ago, this has had little impact on the growing interest in setting up and expanding remote and home office workplaces. Last year, this trend reflected positively in the business performance of genua GmbH. Other growth drivers were the ongoing digitization in the process industry as well as the German IT Security Act 2.0 that came into force in 2021. Both significantly increased the demand for secure solutions among operators of industrial and critical infrastructure systems. Growth Drivers and Potential in the IT Security Segment For this reason, 2022 also proved to be a good year for the German IT security specialist. Marc Tesch, Managing Director of genua, is more than happy with the result: "In 2022, the turnover in the German IT sector increased by 6.6 percent. With an increase in sales of 12.7 percent – or 8.5 million euros – our business performance speaks for itself. In the more stringently regulated IT markets in particular, we were able to make huge gains." Tesch has this to say about the growth drivers in the German market: "The legal minimum requirements on cybersecurity are constantly increasing. National obligations within the framework of the German IT Security Act as well as European legislative initiatives such as NIS 2.0 and the Cyber Resilience Act create a growing demand for our portfolio, which is designed to meet high security requirements. Further growth drivers are the continuing digitization of authorities as well as the need for greater digital sovereignty in Germany and Europe." With regard to the industrial sector, Tesch adds: "With its 2030 Vision for Industry 4.0, the German Federal Ministry of Economics and Climate Protection is promoting digitization in industry. Such strong ambitions provide genua with a further, innovative and attractive market environment because more and more machines and components used in companies are connected to the Internet and must be reliably protected." Product Development and Research In 2022, genua placed emphasis on the improvement and expansion of its existing range of products. Development focused on virtualized solutions, the approval and certification of the products for use in infrastructures with particularly high protection requirements, as well as research into network security and quantum resistance. Zero Trust Remote Maintenance Due to the increasing digitization of sensitive processes in IT and OT environments, zero trust concepts are becoming more and more important – also and especially in the context of secure remote accessibility. For this reason, since November of last year the virtualized remote maintenance solution genubox has also supported cloud-based identity systems from providers such as OKTA, Azure Active Directory or open source providers. Approved Firewalls In March of last year, the High Resistance Firewall genugate was again approved by the German Federal Office for Information Security (BSI) for use in environments involving data with the classification levels German VS-NfD, RESTREINT UE/EU RESTRICTED and NATO RESTRICTED. Furthermore, the current version also supports new automation features that reliably handle complex administration tasks over a large number of appliances. Government institutions and businesses with very high protection requirements can use genugate to securely consolidate and efficiently manage their IT infrastructures. Network Security and Post-Quantum Cryptography In 2022, genua was able to successfully continue its research activities for greater network security with projects such as WINTERMUTE , AI-NET-PROTECT , and VerSeCloud . The development of quantum-secure solutions also remains a key focus of research. In this context, the QuaSiModO project was successfully concluded in February 2023. The follow-up project AMiQuaSy (Agile Migration to Quantum-resistant Systems)) investigates how currently available means can be used to protect complex IT networks with high heterogeneity against quantum computers. Photos and Image Caption Marc Tesch and Matthias Ochs are the managing directors of genua GmbH DOWNLOAD DOWNLOAD 2 photos: genua GmbH Press ContaCt Kafka Kommunikation Kafka Kommunikation GmbH & Co. KG Mona Bastian Dr. Torben Gülstorff E genua@kafka-kommunikation.de T +49 89 74747058-0
genuscreen 40G VPN approved for classification level “German VS-NfD” and the classification levels "Nato Restricted" and "Restreint UE/EU Restricted" FPGA-accelerated network packet processing provides guaranteed 2x 40 Gbit/s IPsec and <20 μs latency Highly secure transfer through encryption using AES-256-GCM with 16-byte integrity check Kirchheim near Munich (Germany), July 11, 2023. The German Federal Office for Information Security (BSI) has recertified the Firewall & VPN Appliance genuscreen (version 8.0p11) from German IT security specialist genua in accordance with the demanding EAL4+ trustworthiness level of the Common Criteria (CC). This means that all of the security functions for this level are proven to have been implemented correctly, thus confirming the high level of trustworthiness of the solution. Proven, Highly Secure Update Mechanism For the first time, the current recertification of genuscreen incorporates the ALC_PAM.1 security component for patch management. This proven, highly secure update mechanism can even protect against attacks from quantum computers. Since it has been tested for vulnerabilities, this patch management solution allows trusted software and hardware updates to be provided – even for the highest security levels. Already in June 2021, the High Resistance Firewall genugate – also available from genua – became the first CC-EAL4+ system worldwide to have patch management jointly certified. Goetz Salzmann, Product Owner VPN Solutions at genua GmbH: "Software updates are a basic foundation of IT security because they serve to correct errors. This is the reason why the German Federal Office for Information Security (BSI) has long been recommending that patches should be installed regularly and promptly. Users obligated to operate a certified IT security product due to high security requirements are, however, faced with a dilemma. They are not able to make use of software updates to rectify errors as the certification of the product would thereby be lost. This is because the certification applies to a specific software version. With a certified patching process, we provide these users with a tool that allows them to more effectively combine both formal and practical requirements." Level 4 Significantly Exceeds The Required Vulnerability Analysis Alongside the ALC_PAM.1 patch component, the Evaluation Assurance Level EAL4 has been supplemented with the ALC_FLR.2 component on flaw remediation documentation, the ASE_TSS.2 component (TOE summary specification with architectural design summary) and the AVA_VAN.4 component (methodical vulnerability analysis), thus achieving level EAL4+. Level 4 of the AVA_VAN component is significantly higher than the vulnerability analysis required for EAL4. Highly Secure Connection of up to Ten Thousand Participants Via VPN The Firewall & VPN Appliance genuscreen allows data to be securely exchanged between different company locations via the Internet. "The required level of data protection necessary for doing this is achieved using backdoor-free VPN technology. We ensure that the technology is secure with regular approval and certification processes through the BSI," explains Mr. Salzmann. Thanks to a Stateful Packet Filter, this is also achieved for IPv4 and IPv6. With this technology, the firewall assesses the overall context before allowing a connection. The certification number at the time of the patch release was BSI-DSZ-CC-1194-2023. This covers stand-alone operation and operation in combination with Version 8.0p5 of the Central Management Station genucenter. With the approval for the classification levels German VS-NfD and EU/NATO RESTRICTED, users can implement the scalable genuscreen solution both nationally and internationally for high-security applications, either as a site-to-site VPN with over one thousand participants or as a remote-access-service VPN (RAS) with up to ten thousand participants. Further Information https://www.genua.eu/it-security-solutions/firewall-vpn-appliance-genuscreen https://www.genua.eu/news-article/firewall-with-bsi-certified-patch-management-cc-eal4 https://www.genua.eu/it-security-solutions/central-management Image captions Photo (preview): genuscreen is a highly secure Firewall and VPN Appliance certified and approved by the German Federal Office for Information Security (BSI) "Made in Germany" for companies with high protection requirements, government organizations and industries with an obligation to maintain secrecy. © genua GmbH Press ContaCt Kafka Kommunikation Kafka Kommunikation GmbH & Co. KG Mona Bastian Dr. Torben Gülstorff E genua@kafka-kommunikation.de T +49 89 74747058-0
The Remote Maintenance Solution from genua Now Supports Authentication via Cloud Identity Providers Okta and Azure Active Directory Kirchheim near Munich, February, 28 2023. After three years, the BMBF-funded research project "Quantum-Safe VPN Modules and Operation Modes" (QuaSiModO) has been successfully completed. The researchers' goal was to investigate and test novel quantum-resistant - that is, not vulnerable to attack by a quantum computer - cryptographic algorithms and prepare them for use in VPN standards and VPN implementations. The results and their practical significance for IT security will be presented this week at an event on post-quantum cryptography hosted by Fraunhofer AISEC. IT security specialist genua GmbH is already working on initial implementations of the project results and is aiming for a post-quantum migration of its network security solutions as soon as possible. Quantum Computers Challenge Cryptography Cryptography is a prerequisite for ensuring the confidentiality and authenticity of communications and data. In virtual private networks (VPNs), it is used, among other things, for exchanging cryptographic keys as well as for encryption itself to communicate securely with a remote device over an insecure network such as the Internet. However, established encryption algorithms are at risk: Quantum computers could become powerful enough to crack them within a few decades. This threat also affects sensitive data already stored today, as it could be decrypted retrospectively. In addition, post-quantum cryptography poses new challenges to the design of network protocols, as PQK algorithms are often slower or have larger key sizes than classic methods. Practical Cryptoalgorithms For The Quantum Age To meet these challenges, researchers around the world are working on new cryptographic methods. In the QuaSiModO research project, the aim was to identify practical trustworthy and secure algorithms that can be used to operate quantum-secure VPNs in the near future. The common IPsec and MACsec key exchange and key agreement protocols, Internet Key Exchange Version 2 (IKEv2) and MKA/PACE, should be made quantum secure for this purpose, including by using hybrid, crypto-agile, and multilayer encryption techniques. According to Stefan-Lukas Gazdag, crypto researcher for the genua GmbH project coordinator, all project goals were achieved: • the quantum-resistant key exchange for IPsec and MACsec, • the implementation of quantum-resistant solutions on Layer 2 and Layer 3 of the TCP/IP reference model • as well as the development and testing of VPN-suitable hybrid and cryptoagile mechanisms - in coordination with the relevant standardization committees. In addition, the first attempts at post-quantum authentication have been undertaken. genua's main research had been on IPsec protocols. Gazdag is more than satisfied with the results: “We found several mechanisms to successfully quantum-proof the classic Internet Key Exchange IKEv2 as well as IPsec.” The Next Step - Fully Quantum-Resistant Networks genua GmbH has been active in research for quantum-resistant IT for a long time. As early as 2014, the company was involved in QuaSiModO's predecessor “Quantum Computer-Resistant Signature Methods For Practice" ( squareUP ). And a follow-up project for QuaSiModO is already being planned – with an expanded focus on complete quantum-resistant networks. "In the not too distant future, quantum-secure encryption techniques will be a must for IT solutions made in Europe", Gazdag continues. "Thanks to the results of QuaSiModO, we are at the forefront and will implement suitable procedures at an early stage that will keep our customers secure in the future.” Joint Research For Quantum-Resistant Algorithms The QuaSiModO project partners, in addition to genua as project coordinator, are ADVA Optical Networking SE, the Fraunhofer Institute for Applied and Integrated Security (AISEC) and the Ludwig Maximilian University of Munich (LMU). The German Federal Office for Information Security (BSI) and the Hessen CyberCompetenceCenter (Hessen3C) were also associated partners. Image caption Demonstrator of quantum-secure communication through IPsec and MACsec. Two sites are connected via layer 2 (VLAN) and layer 3 (IP tunnel). The VLAN is secured by SecTAG. The IP tunnel, on the other hand, is secured by IPsec / ESP and additionally encapsulated in SecTag. The connection is established with IKEv2 for ESP and MKA / PACE for SecTAG. © genua GmbH Further information • QuaSiModO project website https://pq-vpn.de/index.html Press ContaCt Kafka Kommunikation Kafka Kommunikation GmbH & Co. KG Mona Bastian Dr. Torben Gülstorff E genua@kafka-kommunikation.de T +49 89 74747058-0
We are an «Attractive Employer». Our employees confirmed this again in 2022 in an anonymous survey as part of the "Great Place to Work® Certified" program. The award by the award committee of the international research and consulting institute is a confirmation of the genua corporate culture. It underscores what we focus on: the employees should simply feel good – even beyond the purely professional level. It is important to us that our employees have the freedom to develop new ideas in an inspiring work environment – unhindered by hierarchies and in an open work culture. That is what we are committed to. The head of customer service at Great Place to Work, Sebastian Diefenbach, said when making the decision: "Good employers have one thing in common: They are committed to credible, fair management and the active promotion of employees. Respect, trust and team spirit are to a large extent part of the corporate culture.” We see it the same way and feel that the certification confirms our efforts. The award is given a place of honor alongside the kununu "Top Company" seal and the award as one of the most family-friendly companies in Bavaria (awarded by the Bavarian State Ministry for Economic Affairs, Regional Development and Energy together with the Bavarian State Ministry for Family, Labor and Social Affairs). More information: Career with genua
The Remote Maintenance Solution from genua Now Supports Authentication via Cloud Identity Providers Okta and Azure Active Directory Kirchheim, March 16, 2022. The German Federal Office for Information Security (BSI) has approved the High Resistance Firewall genugate 10.0 Z for classification level German VS-NfD, as well as classification levels RESTREINT UE/EU RESTRICTED, and NATO RESTRICTED 1 . Effective immediately, this current version of the IT security solution supports a REST-API as well as central log evaluation via Elastic Stack. Government institutions as well as businesses with very high protection requirements can thereby extensively automate administration tasks, further consolidate IT infrastructures and, at the same time, reliably secure sensitive infrastructures against cyber risks. Kirchheim near Munich, Germany, November 9, 2022. The remote maintenance solution genubox from the Munich-based IT security specialists genua GmbH now supports the use of cloud-based identity systems. Connecting to a cloud identity provider such as Okta or Azure Active Directory enables the full integration of genua remote maintenance into a central user management system with commonly used multi-factor authentication. Companies benefit from scalable client, role, and rights concepts and users can authenticate themselves via their usual method. Safeguarding Individual Services According to Zero Trust Due to the increasing digitization of processes in sensitive IT and OT environments such as industrial production and critical infrastructures, zero trust concepts are also becoming more important in the context of secure remote access. In zero trust environments, identity and access management plays a fundamental role because it enables external users to have authenticated access to individual, defined services, without affecting the overall security of the network. The remote maintenance solution from genua is based on a highly secure rendezvous architecture and uses a software defined perimeter to support the safeguarding of individual services according to the zero trust paradigm. The newly created interface to cloud-based identity and access management systems such as Okta, Azure Active Directory and other open-source providers now enables customers to easily integrate the remote maintenance solution into existing identity and access management systems. As a result, access for employees, service providers and partners can be efficiently regulated from the cloud. This reduces the configuration effort required on the part of the organization and facilitates migration to cloud applications and platforms in a constantly growing IT ecosystem. In addition, it simplifies the process for users, who can perform identification via their usual method. Highly Scalable User and Role Management Cloud identity providers enable graduated access management for remote maintenance providers according to the "least privilege access" principle, with sophisticated client, role and rights concepts. Multi-factor authentication and methods such as 2FA authenticator applications are used to ensure that only authorized people can access the respective resources and services. In addition, other criteria defined within the scope of governance can be integrated into the rights concept as parameters, for example the location (region) or the time of access. With security "made in Germany", the solution from genua meets all recommendations from the German Federal Office for Information Security (BSI) regarding secure remote maintenance. When used in conjunction with secure VPN solutions from genua, it is also suitable for use in environments with classification level German VS-Nfd.
Strong Demand for Highly Secure Communication Results in a 25 Percent Increase in Turnover for the IT Security Specialist Kirchheim near Munich, October 25, 2022. With a turnover of 66.8 million euros, genua GmbH recorded significant growth for the third time in a row in fiscal year 2021. The 24.9 percent increase in turnover of the German provider of highly secure IT security solutions was primarily attributable to its range of solutions for firewalls, virtual private networks (VPN), and mobile work. A principal driver of growth was the public sector, in particular for the safeguarding of communication categorized as classification level German VS-NfD. In particular, the purely software-based VPN software client genuconnect, which was newly introduced in summer 2021, was received extremely positively by the market. Growth in Macroeconomically Challenging Environment The past year was characterized by a challenging overall macroeconomic situation. Marc Tesch, Managing Director of genua GmbH, says: “At genua, we have been intensively researching and working on the subject of cybersecurity for 30 years in order to sustainably protect the state, companies and society from harm. We see the quantity and quality of cyber threats continuing to grow rapidly. Furthermore, the current, unprecedented combination of multiple global crises exacerbates the conditions under which organizations have to protect their digital, sometimes critical infrastructures.” With regard to the business result, Tesch adds: “Our consistently positive business performance is an impressive indication of the growing willingness to invest in highly secure IT solutions and confirms the high level of trust that the market has in us.” Highlights of 2021: Product Innovations and Research Topics With new developments for highly secure communication as well as approvals and certifications, in the past year genua GmbH once again underlined its special role as IT security company for the German federal government in ensuring information security in Germany. Software Client for Secure Workplaces Authorized for Use with Restricted Data With genuconnect, introduced in April last year, the German IT security specialist offers a purely software-based remote security solution for laptops or tablets with Microsoft Windows 10. The VPN software client rigorously shields the communication connection between sensitive intra-corporate or authority-internal IT networks and mobile devices and in doing so supports highly secure remote work – on the road, working from home or at external locations. High-Speed VPN Gateway Supports Georedundancy of Datacenters In summer 2021, genua launched genuscreen 40G VPN – a high-speed VPN gateway “made in Germany” for interconnecting datacenters. The VPN appliance is designed for the high-performance, encrypted transfer of large quantities of data. With it, datacenter operators can meet the georedundancy requirements stipulated by the German Federal Office for Information Security (BSI) and at the same time protect their digital sovereignty. Research into Quantum Cryptography and Network Security At its dedicated department for research and innovation, genua GmbH together with partners from science, research and industry is continuously working on urgent future issues concerning cybersecurity. In 2021, genua focused its research on four projects funded by the German Federal Ministry of Education and Research (BMBF). Key research activities were the “QuaSiModO” project which concerns the analysis and implementation of quantum-resistant algorithms, the “Wintermute” initiative deals with the artificial-intelligence-assisted protection of especially complex networks, and the European “AI-NET-PROTECT” project that focuses on automated resilient networks for the economy and society. In VerSeCloud, the research partners are working on secure hypervisors in the cloud, based on L4 microkernel technology. BSI Certifies Patch Management for First Time In March 2021, the BSI for the first time accepted patch management in the certification in accordance with Common Criteria EAL4+ (CC EAL4+). The security component ALC_PAM newly developed by genua protects software updates extremely effectively against infiltration attempts, e.g., by malicious software. Further Approvals and Certifications by the BSI In the past year, the vs-diode used for protecting highly confidential communication received approval for the SECRET, NATO SECRET and SECRET UE / EU classification levels. In addition, the VPN software client genuconnect and the high-resistance firewall genugate received approval for the following classification levels: German VS-NfD, RESTREINT UE/EU RESTRICTED and NATO RESTRICTED. The firewall and VPN appliance genuscreen as well as the personal security device genucard received approval from the Council of the European Union.
genugate 10.0 supports a REST-API as well as central log evaluation via Elastic Stack Kirchheim, March 16, 2022. The German Federal Office for Information Security (BSI) has approved the High Resistance Firewall genugate 10.0 Z for classification level German VS-NfD, as well as classification levels RESTREINT UE/EU RESTRICTED, and NATO RESTRICTED 1 . Effective immediately, this current version of the IT security solution supports a REST-API as well as central log evaluation via Elastic Stack. Government institutions as well as businesses with very high protection requirements can thereby extensively automate administration tasks, further consolidate IT infrastructures and, at the same time, reliably secure sensitive infrastructures against cyber risks. Automated Management of Complex Firewall Systems Technology trends such as cloud services, remote connections or IT consolidation increase the complexity of IT system landscapes in the public sector as well. This makes it increasingly difficult for IT administrators to efficiently manage and monitor firewalls. The risk of configuration errors and security vulnerabilities thereby increases as well. To reliably handle complex administration tasks over a large number of appliances, the new version 10.0 Z of genugate supports a REST-API, which offers a machine-readable definition based on the OpenAPI standard. Public authorities and companies can thereby use the firewall on a large scale and easily and transparently automate processes. This includes the creation of host entries, the alignment of policies across multiple installations, the creation of rules for integration in a cloud infrastructure or policy documentation for audit purposes. Improved Evaluation and Analysis of Log Messages genugate 10.0 Z also supports central logging via Elastic Stack. Integration with the open-source solution, also known as the ELK Stack, enables convenient evaluation, analysis, and handling of log messages across multiple firewalls via a single user interface (GUI) as well as the real-time monitoring of security-critical functions. Even with highly complex systems with many devices, warning messages can thereby quickly be localized and evaluated and appropriate measures taken. Web Application Security and Secure Software Updates Moreover, genugate 10.0 Z is the world's only Web Application Firewall (WAF) to have received certification according to the Common Criteria (CC) EAL4+ with AVA_VAN.5 (Advanced Methodical Vulnerability Analysis) by the BSI. Designation AVA_VAN.5 stands for a high level of self-protection which has been proven to protect the firewall even against attackers with high attack potential. Especially endangered organizations such as security authorities, the military or operators of critical infrastructures can thereby reliably protect their servers against attacks. Furthermore, genugate 10.0 Z is the only firewall on the market equipped with a patch management solution certified in accordance with CC EAL4+. This provides an especially effective protection of software maintenance processes such as updates and patches against infiltration attempts. 1 IT security products that perform security functions within classified IT applications in the public sector are to be certified by the BSI prior to use. The current BSI approval for genugate 10.0Z is valid until February 2, 2024. Photo captions genugate is a high resistance firewall that combines an application level gateway and a packet filter, each on separate hardware, to form a compact solution. With its two-tier design and a high level of self-protection, the appliance offers an especially high level of security. Download RGB Download CMYK © genua GmbH
Maximum Security for Highly Confidential Communication Kirchheim near Munich, December 16, 2021. The new 2.0 version of vs-diode from genua was again approved by the German Federal Office for Information Security (BSI) for the classification level SECRET. In addition, the data diode received BSI approval for the classification levels NATO SECRET and SECRET UE/EU SECRET. The current version also supports the FTPS protocol and offers a higher performance level of up to three Gbit/s. BSI Seal for Protected Data Transfers to Red-Black Gateways Whether with simple phishing mails to members of the Bundestag or sophisticated infiltrations over longer periods of time: cyber-espionage attacks against critical IT infrastructures of government institutions will continue to be part of everyday life in the future. The critical interface that the attackers set their sights on is the data transfer from networks with a low security classification, so-called "black" networks into "red" networks with classification level SECRET – such as when receiving e-mail, when transferring video and radar data or when uploading the latest patterns for anti-virus systems. For comprehensively secured data transfers to these red-black gateways, genua developed the Data Diode vs-diode. The current version 2.0 again received BSI approval for the processing and transfer of information up to and including the classification level SECRET. In addition, vs-diode 2.0 is approved for the protection of EU information up to classification level SECRET UE/EU SECRET for national use and up to classification level NATO SECRET for the protection of NATO information. The classification level designates the level of protection required for classified information, i.e., facts, topics or findings which, in the public interest, must remain confidential. "We are pleased with the recertification and with the accompanying confirmation from the BSI that the data diode possesses outstanding security features," says Matthias Ochs, Managing Director of genua GmbH. In addition to the approval, the new version of vs-diode is characterized by the fact its performance has increased from two to up to three Gbit/s. Security Architecture with One-Way Principle and Strict Segmentation vs-diode consists of two application level gateways (ALG) – one for the black network and one for the red network – as well as a one-way middle section located in-between. This only copies data from black to red. In the other direction, indication is only provided as to whether the data correctly arrived at the opposite site. This transfer notification enables fast data transfer without a redundant and slow transmission. Communication between the red and the black ALG is by means of TCP or UDP. The middle part of vs-diode consists of two para-virtualized genuscreen firewalls and a one-way task located in-between. It uses a separation kernel of the L4 family, which divides the hardware into three compartments that are strictly separated from one another. Each of these compartments has its own CPU kernel. The working memory is also strictly separated from the other compartments by the microkernel. Located between the two firewalls is the one-way task that represents the only interface between the two firewall compartments. vs-diode 2.0 supports the new FTPS protocol (FTP with TLS encryption) and provides continued support for FTP, SMTP, SNMP Traps, TCP, Lumberjack (Elastic Stack), Syslog and UDP. Image caption: Data transfers from the black network to the red network with vs-diode 2.0 from genua © genua GmbH
genubox Now Available for All Virtualization Platforms Kirchheim, November 23, 2021. With the introduction of genubox 8.0, the latest version of the highly secure remote maintenance solution from the German IT security manufacturer genua now supports virtualization with Microsoft Hyper-V. Used in combination with the existing genubox for Linux KVM, VMWare ESXi and VMWare vSphere, this provides purely software-based remote maintenance solutions for all key virtualizations available on the market. This provides the customer with a freely scalable remote access and remote maintenance solution for operation on the customer's own on‑premise systems or in public clouds. In industry, the trend is toward virtualized solutions. This purely software-based approach enables remote maintenance solutions to be deployed extremely quickly and flexibly without the need for complex hardware integration. Cross-platform mixed operation in particular illustrates the strength of the overall solution from genua – the proven, specially hardened genubox appliance solutions can continue to be used. These solutions are also available as variants suitable for conditions that exist in industrial environments. This means that the maintenance solutions from genua can be scaled freely without insecure network connection and adapted at low cost to the respective situation on site. The remote maintenance solution is operated and managed via the easy-to-use central management station genucenter. Maintenance sessions can be released and monitored individually via a rendezvous server and also documented as a video in a tamper-proof manner using genuview. genubox Supports Implementation in Accordance with Zero Trust Networking Access genubox is particularly well suited to the implementation of zero trust concepts. Finely grained access for the remote maintenance provider (least privilege access) with sophisticated client, role and privilege concepts only permits access to the functions required for the respective task and only at the required point in time. All external communication with the outside world is encrypted and monitored beforehand within the network. As an option, users can be authenticated using the two-factor authentication method and interfaces to identity providers such as Microsoft Active Directory. The software-defined perimeter with rendezvous architecture in combination with an integrated firewall ensures service coupling instead of a more insecure, complete network coupling. Moreover, multiple genubox instances enable the implementation of microsegmentation up to the target system and therefore access to existing legacy systems ("Brownfield"). This makes it possible to realize retrofit projects, for example. With security "Made in Germany", the genubox solution also meets all recommendations from the German Federal Office for Information Security (BSI) regarding secure remote maintenance and can be used for the highest requirements up to German classification level "Restricted". Photo captions Product photo: genubox appliance. Version 8.0 of the highly secure remote maintenance solution is also available as purely software-based virtualization for Microsoft Hyper-V. Download RGB Download CMYK Illustration: genubox is used as a rendezvous server and as a service box. This minimizes risks during remote access and boosts the maturity level of security and safety. Download RGB Download CMYK © genua GmbH