Simplifies Replacement of OpenSSL with Mocana’s FIPS 140-2 Validated Cryptographic Engine
Sunnyvale, CA – January 15, 2019 – Mocana, the leading provider of device security solutions for IoT and industrial control systems, today announced the integration of Mocana TrustPoint™, the company’s award-winning, embedded cybersecurity software, with Unified Automation’s High Performance OPC Unified Architecture (UA) Software Development Kit (SDK). This integration enables industrial manufacturers and operators to easily replace OpenSSL, an open source crypto library, with Mocana’s proven cybersecurity software solution that is FIPS 140-2 validated and compliant with leading industrial cybersecurity standards.
“Mocana’s embedded cybersecurity solutions are used by the largest industrial companies for mission critical systems,” said Uwe Steinkrauss, Executive Director at Unified Automation. “We’re committed to partnering with Mocana to provide the OPC UA community with solutions that are secure and compliant with industry standards.”
OPC UA is an open machine-to-machine communication platform for industrial automation developed by the OPC Foundation. The OPC UA standard enables industrial control system (ICS) devices across multiple platforms to communicate using a services-oriented architecture (SOA) including enhanced publish/subscribe capabilities. The standard is broadly used across many industries, including pharmaceutical, oil and gas, building automation, industrial robotics, security, manufacturing, process control, and transportation.
Unified Automation develops several OPC UA software development kits for C++, .NET, and ANSI C. Unified Automation’s High Performance (HP) OPC UA Server SDK was designed to support OPC UA in the smallest, most resource-constrained devices, such as IoT devices. The HP SDK improves the performance, scalability, and security of OPC UA and enables servers to handle thousands of connections in parallel.
By default, most OPC UA SDKs have been designed to use OpenSSL, open source security software, to handle security functions such as authentication and encryption. Besides the large footprint hindering implementation on the smallest embedded devices, OpenSSL has been shown to have thousands of vulnerabilities, a hard to maintain complex code base, and slow vulnerability remediation times. Additionally, the latest NIST 140-2 standards cannot be met by the current version of OpenSSL. As a result, industrial companies are migrating away from OpenSSL to meet cybersecurity compliance standards.
Mocana’s integration with Unified Automation’s OPC UA SDKs makes it easy to replace OpenSSL with Mocana’s FIPS 140-2 validated cryptographic engine and comprehensive device security lifecycle management platform. Mocana provides an OpenSSL Connector, a shim that transparently intercepts the device application’s OpenSSL API calls, changes the arguments, and passes them onto Mocana’s cryptographic engine without requiring any application code changes.
“Unified Automation has deep expertise with OPC UA and was instrumental in developing the OPC UA stacks, in particular the ANSI C stack,” said Srinivas Kumar, Vice President of Engineering at Mocana. “We are committed to making it easy to enable the highest level of security and device integrity for OPC UA-enabled industrial devices.”
Mocana’s proven device security solution facilitates compliance with cybersecurity standards, such as the NIST FIPS 140-2, IEC 62443, NIST 800-63, and CIP-007. Mocana and Unified Automation are members of the OPC Foundation.
About Mocana Corporation
Founded in 2002, Mocana provides mission-critical IoT security solutions for embedded systems, industrial controls and the Internet of Things (IoT). Our proven cybersecurity software goes beyond traditional security approaches by making IoT and ICS devices trustworthy and enabling secure device-to-cloud communications. Mocana’s full-stack platform operates across complex, multi-vendor environments where performance and security are critical to ensuring safety and reliability. Hundreds of industrial and IoT companies depend on Mocana’s military-grade technology to protect millions of IoT devices, controllers and embedded systems. www.mocana.com.
About Unified Automation
As a leading supplier of OPC UA software Unified Automation provides UA-enabled products, cross-platform toolkits and development frameworks in different programming languages (ANSI C, C++, JAVA and C# .NET) and for different platforms (Windows, Linux, VxWorks, QNX, RTOS, and many embedded operating systems). The target market of OPC UA products ranges from manufacturers of embedded devices to developers of enterprise applications. Unified Automation sees itself as technology and software provider in the field of OPC based communication. The software development kits (SDKs) form the base of OPC UA products of nearly all large and small automation vendors worldwide.
Merritt Group on behalf of Mocana