AllSafeguard Business and IoT Integrity with Secure App Service: Unrivaled code signing service and security for IoT
Safeguard Business and IoT Integrity with Secure App Service: Unrivaled code signing service and security for IoT
DATASHEET
Instead of trying to manage your own IoT code signing efforts, Secure App Service simplifies and secures
your IoT code signing by making the process easy.
•
Upload your software or file hash to our secure cloud service and we sign it for you.
•
Use our management dashboard or tie the service into your custom build processes with our APIs.
•
Trust us to securely store your certificates and keys in the cloud in our highly secure data center.
• No
longer worry about the security risks, management complexity, and hardware security investments
associated with storing keys locally.
SELF-MANAGED
CODE SIGNING
VS
Signing keys vulnerable to theft due to complexity and
difficulty in implementing adequate security measures
SECURE APP
SERVICE MANAGED
CODE SIGNING
Signing keys stored in robust PKI infrastructure in
military-grade data centers
Insufficient controls over access tokeys and who can
sign code
Role-based code signing access and process controls
with approval queues
Inability to keep track of all keys and no visibility into
who signed what code, when and how many
Detailed tracking, reporting, and auditing of all code
signing keys and activity for complete visibility
Streamlined code signing with flexibility to manage process
with web portal or automate into existing workflows
Inefficient and cumbersome code signing processes
Cost-effective and flexible fixed-pricing of cloud-based
subscription service
High capital investment in specialized security hardware
Effortless, worry-free best-practice and leading-edge
service that keeps code signing efforts compliant
Constant struggle to keep up with the latest code signing
techniques, mandates, and best practices
3
DATASHEET
Secure IoT software with flexible code signing options
The highly innovative, expansive, and constantly changing nature of IoT can lead to very diverse
development environments that need to support a wide variety of software file types. To support the diverse
nature of IoT software, we offer code signing flexibility with support for OpenSSL, GPG, and RPM. Each of
these signing types include the ability to sign IoT firmware and OS images, as well as small to large file sizes
and different flavorsof software.
IoT code signing options with Secure App Service
Key models
File types
Full file upload only versus
hash-based signing
Digest algorithms
Signing options
Open SSL
GPG
RPM
Fixed cert pool (On-demand)
Unique key model
New key
Fixed cert pool
New key
Fixed cert pool
All
All
.rpm
Hash-based and
full file upload
Full file
upload only
Full file
upload only
SHA1
SHA256
SHA1
SHA256
SHA1
SHA256
RSAUT
DGST
sign (binary) clearsign
detach-sign
addsign resign
Gain complete control over and insight into all IoT code signing activity to protect your business and IoT
integrity. Backed by one of the global cyber security leaders, our Secure App Service solution helps protect
your business against major financial losses and brand damage with simplified, no-worry IoT code signing
visibility, agility,and security.
4
Please complete the form to gain access to this content