RSS
Логотип
Баннер в шапке 1
Баннер в шапке 2

ViPNet TLS Gateway

Product
Developers: Infotecs
Last Release Date: 2016
Technology: Information Security - Authentication,  Information Security - Firewalls,  Information Security - Encryption Tools

Content

2024: Rosa Virtualization Compatibility

The companies ROSA InfoTeCS conducted testing and confirmed the correct operation of the ViPNet TLS Gateway VA high-performance TLS crypto gateway on the platform. virtualizations ROSA Virtualization InfoTeCS announced this on February 13, 2024.

Established interoperability is of strategic importance to enterprises that seek not only to improve their security, but also to make optimal use of virtual environment resources, especially when dealing with security-sensitive data. The solution ensures that today's business meets the requirements for security, flexibility, and performance.

ROSA Virtualization is an enterprise server and desktop virtualization platform. With ROSA Virtualization, you can optimize your IT infrastructure while delivering high performance, reliability, and scale for mission-critical applications. The platform is certified by the FSTEC of Russia No. 4610 according to the 4th level of trust in information protection tools and information technology security tools.

ViPNet TLS Gateway VA is a virtualized security gateway designed to organize secure protocol connections TLS the Russian using foreign crypto. algorithms TLS enables authentication users and secure connections to work with portal solutions. ViPNet TLS Gateway VA is certified FSB of Russia and meets cryptographic information KS1 class security requirements.

2017

Completed ViPNet TLS Gateway testing with Sailfish Mobile OS RUS

On June 27, 2017, InfoTeCS announced the results of testing ViPNet TLS Gateway secure remote access technology for corporate web resources for mobile devices with Sailfish Mobile OS RUS. Partner in the Open Mobile Platform project.

As part of the system testing, a TLS connection was established between a mobile device running Sailfish Mobile OS RUS and the ViPNet TLS Gateway cryptosync using a one-way authentication scheme. The Sailfish Mobile OS RUS operating system includes the Pathfinder crypto provider. This made it possible to provide a secure connection to the ViPNet TLS Gateway, which uses domestic cryptography algorithms that comply with GOST.

File:Aquote1.png
The compatibility of the ViPNet TLS Gateway product with the Sailfish Mobile OS RUS operating system provides mobile device owners with the ability to access portal web resources via secure channels. At the same time, the confidentiality of the transmitted information is ensured by reliable, modern and fully compliant with the regulator's requirements by means of cryptographic information protection of InfoTeCS and Open Mobile Platform.

Dmitry Gusev, Deputy General Director of InfoTeCS
File:Aquote2.png

File:Aquote1.png
Working on the development of Sailfish Mobile OS RUS, we pay attention not only to the development of the operating system itself, but also to the creation of an ecosystem of applications and services for building an enterprise infrastructure based on it. One of the key features of such solutions is to provide secure communication channels between mobile devices and the company's web resources. ViPNet TLS Gateway, together with the Pathfinder crypto provider, conveniently allows you to implement a secure connection that meets the requirements of our customers.

Pavel Eiges, General Director of Open Mobile Platform LLC
File:Aquote2.png

ViPNet TLS Gateway

As of June 29, 2017, ViPNet TLS Gateway is a security gateway based on Russian cryptographic algorithms for authentications users and organizing secure connections using the TLS v.1.2 protocol when working with portal technologies.

ViPNet TLS Gateway Hardware Implementation, (2017)

The technology can be used in the form of a PAC and a virtual device. Included in the register of Russian software.

Network architecture using ViPNet TLS Gateway, (2017)


Functionality

  • Reverse proxy server that provides secure remote HTTPS access to resources.
  • Authentication schemes for establishing a secure TLS connection:
    • one-way: server authentication;
    • two-sided: mutual authentication of the server and the user;

  • Users and the server are authenticated by certificates of electronic signature verification keys;
  • ViPNet TLS Gateway controls the list of resources available to users: depending on the specified settings and rules for processing incoming requests, the server decides whether to provide information to the end user or not;
  • Automatic maintenance of revoked certificate lists (CRLs) for verification of certificates used by users;
  • Work of users using certificates issued in different certification centers;
  • The ability to remotely administer via the ViPNet TLS Gateway web interface;
  • Supports a load-balanced cluster through an external balancer.

Support for cryptographic standards and recommendations

  • Electronic signature: GOST R 34.10-2001, 34.10-2012;
  • Hashing: GOST 34.11-2012, 34.11-94;
  • Imitation protection: GOST 28147-89;
  • Encryption: GOST 28147-89, recommendations of the Technical Committee 026 "Cryptographic Information Protection."


Use Cases

  • Employee remote access to corporate resources.
  • Provision of electronic services through a secure channel:

As of June 29, 2017, the FSB completed ViPNet TLS Gateway certification tests for compliance with security classes:

  • KS1 for execution of TLS VA;
  • KC3 for TLS variants 500/TLS 1000/TLS 5000.

The term for obtaining the conclusion is the 3rd quarter of 2017.