All articles

iStorage CloudAshur secures the use of cloud-based data

Looks simple, works simply, but is a technological achievement

In these unusual times, nothing is as it was. Working outside the familiar office environment has become almost “the new normal” for everyone, but we may be less aware that critical business information travels everywhere with us. Unfortunately, cybercriminals are exploiting this situation in both creative and increasingly malicious ways to gain access to our valuable data and systems. Now that we all work everywhere, everyone is making video calls and business information moves from place to place and system to system across a wide selection of conferencing tools, the question is how we can keep it secure and under control.

As the COVID-19 virus spread, so did the use of cloud-based applications and platforms such as MS Teams, Zoom and Webex. Cloud storage and data exchange through the cloud also took off. Cloud apps such as WeTransfer promise secure exchange, Zoom proved to leak, and we know access to familiar drives and boxes can easily be obtained through the endpoint or weak passwords without 2FA/MFA. Endpoint security, such as a good EDR solution, is missing in almost every case… In short, this is every information security specialist's worst nightmare.

The solution: hardware encryption and multi-multi-factor

Criminals also know they are most successful when targeting users directly, which is why phishing, smishing, spam and other methods of accessing user details remain so popular. Once a user opens a door and a hacker gains a foothold, attention turns to data on the connected VPN network, and ransomware quickly becomes an attractive extortion tool. The endpoint, the computer, laptop or home workstation, is therefore where the first gains can be made by protecting the user and their use of data.

iStorage's CloudAshur focuses on securing data through encryption and protecting access at several levels. The CloudAshur solution consists of various components that fit together seamlessly, the most visible being a USB module. Strangely for a data storage company such as iStorage, no data is stored on that module: it provides hardware encryption instead. This slightly larger-than-average “USB stick” features iStorage's characteristic numeric keypad. Its high-quality, very robust housing also stands out: dustproof and IP68 waterproof, important for a security solution.

The CloudAshur USB module incorporates advanced security technology, including a crypto chip meeting the highest military specifications for 100% real-time hardware encryption at AEX-XTS or 256-bit AES-ECB level, with a FIPS-PUB197-certified USB 3.0 controller. The crypto chip is also Common Criteria EAL4+ certified, providing a further assurance of security and safety. Hardware encryption is widely accepted as the most secure and fastest way to make data inaccessible to unauthorised users. The module is fully protected against opening the housing, protects against various external attacks and provides self-destruct functions.

What is multi-multi-factor?

Strictly speaking, it does not exist, but generic multifactor authentication (MFA) solutions usually rely on three factors: 1) something you are, often your application username; 2) something you know, your password; and 3) something you have, often a USB module or smartphone app with a code.

For iStorage CloudAshur, this works the same way, with several additions: 1) something you are, your application username; 2) something you know, your password; and 3) something you have, the CloudAshur USB module. Then come the 7-to-15-digit access code entered on the module, 4) your username in the CloudAshur application and 5) your password. Extra security providing additional assurance for access to business-critical data.

How does this work in practice?

Alongside the USB module, iStorage CloudAshur includes a Windows or macOS user application. This gives the user access to the module's encryption capabilities and determines which cloud-based folders and data are linked to the local CloudAshur folder. All data stored in this folder, which automatically synchronises in the background, is immediately encrypted in hardware by the USB module. Data in the relevant cloud folders is therefore always fully encrypted and accessible only to the correct user with the correct CloudAshur and credentials.

A Windows-based remote management application gives IT administrators a complete view of where the various CloudAshur USB modules are located and lets them configure access and use based on location and/or time. In the event of theft or loss, modules can be made unusable remotely, temporarily or permanently, and administrators can determine which types of data may or may not be encrypted.

To share encrypted data between users inside or outside the organisation, the critical encryption information can be copied between CloudAshur USB modules. IT administrators can use CloudAshur Keywriter to copy this highly sensitive information between modules in a fully secure way. Data encrypted with CloudAshur cannot be accessed in any way other than through a CloudAshur USB module, by anyone: not an IT administrator, a hacker or even iStorage experts.

If a user forgets their access code, an administrator code is available as a backup to activate a new user code. If a USB module falls into the wrong hands and someone repeatedly tries to discover the code, the user code can be completely deleted after, for example, 10 incorrect attempts. If the hacker also fails to enter the correct administrator code within a set number of attempts, the entire USB module is rendered unusable.

Now to work

First, the CloudAshur environment must be registered and activated. You can then choose Personal or Enterprise use, with the latter managed through Remote Management software. This is the option for businesses with multiple users and keys. It requires a licence, a unique PIN and downloadable software.

The user then activates the USB module by entering the 7 to 15 digits chosen when replacing the factory settings on its numeric keypad. When the module gives the green light, literally, it can be inserted into the PC and the CloudAshur application's login screen appears. After logging in with a username and password, the user gains access to the local CloudAshur user folder. All data placed there is automatically encrypted by the USB module. All folders at the various cloud providers linked to this folder are also immediately and automatically encrypted.

As long as the USB module remains in the PC, the encrypted data in the local CloudAshur folder and connected cloud folders is accessible as though nothing were different from usual. Opening, editing, saving and copying files all work as normal. As soon as the module is disconnected, however, the data is fully encrypted and can no longer be used in any way. If someone tries to open an encrypted file, the CloudAshur application opens for login, which is possible only when the activated USB module is present.

The same applies when an encrypted file is sent to another user or location through, for example, WeTransfer or Tresorit. Unless the CloudAshur application can be used there with an authorised CloudAshur USB module, the file is completely unusable and inaccessible.

If a hacker somehow gains access to an encrypted file or cloud environment such as Dropbox, Google Drive or OneDrive, the information it contains is unusable without CloudAshur. Encryption by ransomware is impossible, as are data breaches.

Sharing is good, as long as it is secure

Encrypting your own valuable data this way may be useful and sensible, but CloudAshur really comes into its own in business environments where protecting shared data is crucial and data breaches are unacceptable. Sharing encrypted information through the cloud, email or data transfer automatically means having multiple authorised CloudAshur USB modules. CloudAshur KeyWriter makes sharing data between authorised users straightforward, with maximum security and peace of mind, allowing users to share data securely regardless of their location.

Using KeyWriter software, IT administrators can clone all critical security parameters, including the randomly generated encryption key, all PINs and administrator-defined configurations, between the Master cloudAshur USB module and as many secondary modules as needed. In principle, this can be done with a standard USB hub; we recommend a 10-port hub. Because the different cloudAshur USB modules then contain the necessary authentication and decryption information, encrypted data can be used and shared by different users in different locations. Sharing information in such a securely protected way has never been so well thought out or easy to use.

Everything under control, centrally and securely

The cloudAshur Remote Management Console gives IT administrators full control over all cloudAshur USB modules in the organisation, including management of their authorised users. This Windows application shows exactly where the modules are on a map and what users are doing at that moment: uploading, downloading or editing files, all without being able to view the data itself.

Access to cloudAshur can be restricted by geographical location and time of day, and specific IP addresses can be blocklisted. These seemingly simple measures immediately create an initial security layer for data access. The Remote Console can also render USB modules unusable temporarily or permanently, for example after theft. Access to the cloudAshur application is naturally also protected through a cloudAshur USM module.

Conclusion: nothing left to wish for

Data is sacred. Sharing data is necessary. Data breaches are forbidden.

The only solution is therefore to store, send and share data solely in a form unusable by others. Encryption is the key word, and hardware encryption is necessary for security and strength. Access to data decryption can be obtained only through multiple layers and forms of authentication.

iStorage cloudAshur uniquely offers these different layers of protection for business-critical information: from high-quality hardware encryption to multiple authentication layers, including a mandatory USB module with its own activation credentials and additional remote management functions. iStorage CloudAshur is currently the only solution offering such a high level of cloud-based data security combined with optimal ease of use and complete management.


Back to all articles