Share this
A Master List of Trenton Systems' Cybersecurity Advantages & Solutions
by Brett Daniel on Feb 23, 2021 4:48:44 PM
Graphic: Trenton Systems cares about the security of your computing solution. It's why we place great emphasis on internal cybersecurity practices and investing in cybersecurity solutions that protect each layer of your server or workstation, in an all-hands-on-deck effort to fortify your system against both hardware-based and software-based cyberattacks.
Trenton Systems is dedicated to cybersecurity. We have and are continuing to put in place hardware and software processes, practices, and procedures that help verify the security of your system during every step of its build.
Examples of these processes, practices, and procedures include supply chain security measures, which help us validate the security protections and quality management systems of our suppliers, as well as help prevent supply chain attacks; a Counterfeit Protection Program (CPP), which detects, identifies, and removes potentially security-compromised and counterfeit electronic parts; partnerships with Intel that allow us to incorporate the company's security technologies for hardware, firmware, and software; and the fact that we're made in the USA in one secure facility and compliant with the TAA.
Our computing solutions can be configured with a slew of hardware-based and software-based cybersecurity protections, many of which our competitors can't match.
We've listed these advantages and solutions in this blog post and will update the list as we continue to incorporate additional protections that safeguard your sensitive information.
1. Made in the USA
Given recent revelations regarding hardware hacks perpetrated by foreign adversarial governments, we truly can't stress this advantage enough.
We've pasted the following statement into our promotional materials hundreds of times and for good reason. We believe that acquiring a made-in-USA high-performance computer from a trusted manufacturer housed in a vetted and secure facility is vital to the good cybersecurity hygiene of your mission-critical infrastructure.
Trenton Systems designs, manufactures, assembles, integrates, tests, and supports its cybersecure, high-performance computing solutions in Lawrenceville, Georgia, United States of America.
Having authority over each of these processes diminishes outside access to your system and the number of different - potentially compromised - facilities to which it must travel.
In just one facility, you've got a trusted set of eyeballs and ESD-protected hands on your computer.
By purchasing made-in-USA, you significantly reduce the likelihood that your HPC becomes compromised by nation-state forces seeking to steal your data and weaponize it against you and your business, organization, or agency.
2. Revision Control
Trenton Systems has control of its hardware down to the minutiae, and that includes hardware revision control.
We have a living, breathing Approved Vendor List (AVL), comprised of thousands of engineer-vetted parts, that we use to manage your computer's life cycle and facilitate the secure integration of any alternate parts.
This list tracks two things primarily:
- The primary part - the part that we've approved for use in your system
- The alternate part - the part that we've already researched, vetted, and confirmed would be compatible with your system should the primary part become obsolete
Maintaining and constantly monitoring this list secures our supply chain proactively by allowing us to vet and purchase replacement parts ahead of time, usually when we're first made aware that a component may be reaching end-of-life.
If we didn't meticulously monitor and add to this list, we'd have to scramble to find replacement parts for your system, which may ultimately jeopardize its security.
3. BIOS Control & Customization
Trenton Systems employs in-house software engineers who work directly with BIOS source code to create firmware security tweaks and enhancements, such as USB port and optical drive disablement during boot time.
Being able to customize the BIOS also allows us to make all sorts of security fixes, tweaks, and updates related to the Intel Management Engine (ME), Intel Active Management Technology (AMT), and Unified Extensible Firmware Interface (UEFI) specification.
In addition, our longtime partnerships with Intel and AMI allow us to implement updates from these companies quickly and efficiently, ensuring that you have the latest security patches for your system.
The key takeaway here is that we have significant control over the BIOS, which gives us the authority to not only suggest firmware security enhancements for our security-conscious customers but also provide our customers with the choice of tweaking the BIOS based on their own security-related requirements.
4. Intel Platform Firmware Resilience (PFR)
Intel Platform Firmware Resilience (PFR), a firmware security solution that uses an Intel Field-Programmable Gate Array (FPGA) to protect your system's firmware from malware, zero-day exploits, and unauthorized tampering, will be offered in the security packages of some of Trenton Systems' forthcoming computing solutions.
The FPGA helps protect the firmware by attesting that it is safe prior to executing the code.
- Intel, Third Generation Intel Xeon Processor Scalable Family Technical Overview
With PFR, suspicious activity is detected and blocked, and the system is able to default the system back to a known good condition.
In addition, PFR helps customers achieve compliance with NIST SP 800-193, which defines strict requirements for protecting system-level firmware.
5. Intel Software Guard Extensions (SGX)
Intel Software Guard Extensions (SGX) is a CPU-based security instruction set found in many of Intel's Core and Xeon processors. It works by creating secure enclaves within memory into which users' sensitive information is placed.
SGX protects against common cyberattacks by reducing the attack surface of servers and workstations through its use of encrypted portions of memory, which protect sensitive information from processes running at higher privilege levels.
Protected sensitive information could include:
- Financial records
- Medical records
- Classified information
- Controlled unclassified information (CUI)
- Passwords
- Encryption keys
- Any sensitive information that needs to be secured
In the case of other system layers, such as the BIOS, becoming compromised, SGX still protects sensitive information, as the data stored within the enclave is inaccessible to unauthorized users and safe from alteration or theft.
6. FIPS 140-2 Self-Encrypting Drives (SEDs)
FIPS 140-2 self-encrypting drives (SEDs) help Trenton Systems' customers achieve data-at-rest protection by encrypting and decrypting sensitive data automatically on hard disk drives (HDDs) and solid-state drives (SSDs).
The SED's hardware-based encryption mechanism protects against common software-level attacks by encrypting your data and storing encryption keys within the drive itself, rather than in memory, where it could be hijacked by a hacker employing a software-level attack.
Another essential part of using an SED properly is setting a drive password and storing it in a secure place; otherwise, you're just leaving your information vulnerable to a physical-access attack. Thankfully, Trenton's support team can help you with properly authenticating your SED.
Trenton Systems takes SEDs a step further for its military and government customers by helping ensure that their drives are compliant with FIPS 140-2, a government computer security standard for securing and validating cryptographic modules.
We even partner with FUTURA Cyber for encryption key management solutions to further ensure the security of your drive's data.
7. Counterfeit Protection Program (CPP)
Trenton Systems has a thorough Counterfeit Protection Program (CPP) in place. The CPP is aimed at detecting, identifying, documenting, and removing counterfeit electronic parts that could compromise the security of your computing solution.
We've observed high-profile hardware-based infiltrations over the past few years, and it's clear that hackers are focusing more and more on supply chain attacks and physically modifying hardware to surreptitiously access to governments' and corporations' sensitive information.
The CPP allows Trenton to identify, report, and remove potentially counterfeit electronic parts before they ever make their way to into your system, or our facility, for that matter, where they can wreak havoc on your infrastructure and steal or expose information that must be kept private at all costs.
Trenton also adheres to AS5553 and ARP6328, which focus on avoidance, detection, mitigation, and disposition of counterfeit electronic parts.
8. Supplier Quality Surveys
Trenton Systems has a thorough vetting process for its suppliers, which helps protect your system from potentially compromised software applications and electronic parts. This process involves validating our suppliers' quality control systems and certifications and other vetting practices.
Our supplier quality surveys include a five-page questionnaire and evidence-based documentation process for determining whether a supplier meets certain quality standards, capabilities, and ultimately, whether they're a trusted source with whom to do business.
By meticulously vetting each supplier, we ensure that your system has even further protection against hardware and software that could undermine your cybersecurity protections, access your sensitive data, and cause widespread harm to your agency, department, business, or organization.
9. CMMC Compliance
Trenton Systems is in the process of obtaining its Cybersecurity Maturity Model Certification (CMMC).
CMMC Level 3 requires that an organization establish, maintain, and resource a plan demonstrating the management of activities for practice implementation. The plan may include information on missions, goals, project plans, resourcing, required training, and involvement of relevant stakeholders.
CMMC Level 3 also includes satisfying practices under Level 1 and Level 2 as well and specifically addresses the protection of controlled unclassified information (CUI), which the National Archives and Record Administration (NARA) defines as "information that requires safeguarding and dissemination controls pursuant to and consistent with laws, regulations, and government-wide policies."
By obtaining our CMMC, Trenton Systems will be able to offer its customers even more assurance of its internal cybersecurity practices.
10. TAA Compliance
Trenton Systems is TAA-compliant, meaning that its computing solutions are manufactured or substantially transformed in the USA or manufactured in a TAA-designated country.
The Trade Agreements Act (TAA) of 1979 lets program management offices limit their procurement of goods and services to products that are manufactured or wholly transformed in the USA or a TAA-designated country. TAA compliance is a requirement for many of our government customers.
Although there is no official TAA certification, internal verification is a must, as the responsibility of verifying TAA compliance rests with the contractor or supplier that must comply with the TAA.
As such, Trenton is happy to provide evidence that its computing solutions are manufactured or substantially transformed in the USA or manufactured in a TAA-compliant country.
You can also view our TAA Compliance Statement here.
11. Titanium Security Suite
Trenton Systems partners with Star Lab, a Wind River company, to offers its customers their multi-layer Titanium Security Suite.
The Titanium Security Suite, comprised of Titanium Linux, Titanium Secure Hypervisor, and Titanium Secure Boot, is the most robust system-hardening and security capability available on the market for operationally-deployed systems.
It ensures that your computing solution is:
- Secure at rest
- Protected during boot
- Hardened at runtime
The TSS also adheres to common cybersecurity standards and requirements, including DoD anti-tamper requirements, STIG, DODI 8510.01, NIST SP 800-53, and FIPS 140-2.
12. Computational Storage Drives (CSDs)
Trenton Systems partners with NGD Systems, which allows the company to incorporate ruggedized computational storage drives (CSDs) into its computing solutions.
With NGD's CSDs, data is processed directly on the storage drive, which reduces the amount of data transmitted to the host system, reduces latency, but most importantly, increases security.
Processors located within the CSD's drive controller carry out the processing of the data within the drive, ensuring that much of the data never even leaves the CSD for processing by the host system. Less data is being transmitted to the host system, which means less of it is up for grabs by hackers.
13. CSfC, ITAR, & ISO9001 Adherence
Trenton Systems adheres to the National Security Agency's (NSA's) Commercial Solutions for Classified (CSfC) Program, International Traffic in Arms Regulations (ITAR), and complies with international standards for an ISO9001 quality management system.
Adherence to and compliance with these programs, regulations, and standards allows us to consistently provide high-quality computing solutions that satisfy common security and regulatory requirements.
For more information on CSfc, ITAR, and ISO9001 visit our Legal Information webpage or the links below:
Share this
- High-performance computers (42)
- Military computers (38)
- Rugged computers (32)
- Cybersecurity (25)
- Industrial computers (25)
- Military servers (24)
- MIL-SPEC (20)
- Rugged servers (19)
- Press Release (17)
- Industrial servers (16)
- MIL-STD-810 (16)
- 5G Technology (14)
- Intel (13)
- Rack mount servers (12)
- processing (12)
- Computer hardware (11)
- Edge computing (11)
- Rugged workstations (11)
- Made in USA (10)
- Partnerships (9)
- Rugged computing (9)
- Sales, Marketing, and Business Development (9)
- Trenton Systems (9)
- networking (9)
- Peripheral Component Interconnect Express (PCIe) (7)
- Encryption (6)
- Federal Information Processing Standards (FIPS) (6)
- GPUs (6)
- IPU (6)
- Joint All-Domain Command and Control (JADC2) (6)
- Server motherboards (6)
- artificial intelligence (6)
- Computer stress tests (5)
- Cross domain solutions (5)
- Mission-critical servers (5)
- Rugged mini PCs (5)
- AI (4)
- BIOS (4)
- CPU (4)
- Defense (4)
- Military primes (4)
- Mission-critical systems (4)
- Platform Firmware Resilience (PFR) (4)
- Rugged blade servers (4)
- containerization (4)
- data protection (4)
- virtualization (4)
- Counterfeit electronic parts (3)
- DO-160 (3)
- Edge servers (3)
- Firmware (3)
- HPC (3)
- Just a Bunch of Disks (JBOD) (3)
- Leadership (3)
- Navy (3)
- O-RAN (3)
- RAID (3)
- RAM (3)
- Revision control (3)
- Ruggedization (3)
- SATCOM (3)
- Storage servers (3)
- Supply chain (3)
- Tactical Advanced Computer (TAC) (3)
- Wide-temp computers (3)
- computers made in the USA (3)
- data transfer (3)
- deep learning (3)
- embedded computers (3)
- embedded systems (3)
- firmware security (3)
- machine learning (3)
- Automatic test equipment (ATE) (2)
- C6ISR (2)
- COTS (2)
- COVID-19 (2)
- Compliance (2)
- Compute Express Link (CXL) (2)
- Computer networking (2)
- Controlled Unclassified Information (CUI) (2)
- DDR (2)
- DDR4 (2)
- DPU (2)
- Dual CPU motherboards (2)
- EW (2)
- I/O (2)
- Military standards (2)
- NVIDIA (2)
- NVMe SSDs (2)
- PCIe (2)
- PCIe 4.0 (2)
- PCIe 5.0 (2)
- RAN (2)
- SIGINT (2)
- SWaP-C (2)
- Software Guard Extensions (SGX) (2)
- Submarines (2)
- Supply chain security (2)
- TAA compliance (2)
- airborne (2)
- as9100d (2)
- chassis (2)
- data diode (2)
- end-to-end solution (2)
- hardware security (2)
- hardware virtualization (2)
- integrated combat system (2)
- manufacturing reps (2)
- memory (2)
- mission computers (2)
- private 5G (2)
- protection (2)
- secure by design (2)
- small form factor (2)
- software security (2)
- vRAN (2)
- zero trust (2)
- zero trust architecture (2)
- 3U BAM Server (1)
- 4G (1)
- 4U (1)
- 5G Frequencies (1)
- 5G Frequency Bands (1)
- AI/ML/DL (1)
- Access CDS (1)
- Aegis Combat System (1)
- Armed Forces (1)
- Asymmetric encryption (1)
- C-RAN (1)
- COMINT (1)
- CPUs (1)
- Cloud-based CDS (1)
- Coast Guard (1)
- Compliance testing (1)
- Computer life cycle (1)
- Containers (1)
- D-RAN (1)
- DART (1)
- DDR5 (1)
- DMEA (1)
- Data Center Modular Hardware System (DC-MHS) (1)
- Data Plane Development Kit (DPDK) (1)
- Defense Advanced Research Projects (DARP) (1)
- ELINT (1)
- EMI (1)
- EO/IR (1)
- Electromagnetic Interference (1)
- Electronic Warfare (EW) (1)
- FIPS 140-2 (1)
- FIPS 140-3 (1)
- Field Programmable Gate Array (FPGA) (1)
- Ground Control Stations (GCS) (1)
- Hardware-based CDS (1)
- Hybrid CDS (1)
- IES.5G (1)
- ION Mini PC (1)
- IP Ratings (1)
- IPMI (1)
- Industrial Internet of Things (IIoT) (1)
- Industry news (1)
- Integrated Base Defense (IBD) (1)
- LAN ports (1)
- LTE (1)
- Life cycle management (1)
- Lockheed Martin (1)
- MIL-S-901 (1)
- MIL-STD-167-1 (1)
- MIL-STD-461 (1)
- MIL-STD-464 (1)
- MOSA (1)
- Multi-Access Edge Computing (1)
- NASA (1)
- NIC (1)
- NIC Card (1)
- NVMe (1)
- O-RAN compliant (1)
- Oil and Gas (1)
- Open Compute Project (OCP) (1)
- OpenRAN (1)
- P4 (1)
- PCIe card (1)
- PCIe lane (1)
- PCIe slot (1)
- Precision timestamping (1)
- Product life cycle (1)
- ROM (1)
- Raytheon (1)
- Remotely piloted aircraft (RPA) (1)
- Rugged computing glossary (1)
- SEDs (1)
- SIM Card (1)
- Secure boot (1)
- Sensor Open Systems Architecture (SOSA) (1)
- Small form-factor pluggable (SFP) (1)
- Smart Edge (1)
- Smart NIC (1)
- SmartNIC (1)
- Software-based CDS (1)
- Symmetric encryption (1)
- System hardening (1)
- System hardening best practices (1)
- TME (1)
- Tech Partners (1)
- Total Memory Encryption (TME) (1)
- Transfer CDS (1)
- USB ports (1)
- VMEbus International Trade Association (VITA) (1)
- Vertical Lift Consortium (VLC) (1)
- Virtual machines (1)
- What are embedded systems? (1)
- Wired access backhaul (1)
- Wireless access backhaul (1)
- accredidation (1)
- aerospace (1)
- air gaps (1)
- airborne computers (1)
- asteroid (1)
- authentication (1)
- autonomous (1)
- certification (1)
- cognitive software-defined radios (CDRS) (1)
- command and control (C2) (1)
- communications (1)
- cores (1)
- custom (1)
- customer service (1)
- customer support (1)
- data linking (1)
- data recording (1)
- ethernet (1)
- full disk encryption (1)
- hardware monitoring (1)
- heat sink (1)
- hypervisor (1)
- in-house technical support (1)
- input (1)
- integrated edge solution (1)
- international business (1)
- licensed spectrum (1)
- liquid cooling (1)
- mCOTS (1)
- microelectronics (1)
- missile defense (1)
- mixed criticality (1)
- moving (1)
- multi-factor authentication (1)
- network slicing (1)
- neural networks (1)
- new headquarters (1)
- next generation interceptor (1)
- non-volatile memory (1)
- operating system (1)
- output (1)
- outsourced technical support (1)
- post-boot (1)
- pre-boot (1)
- private networks (1)
- public networks (1)
- radio access network (RAN) (1)
- reconnaissance (1)
- secure flash (1)
- security (1)
- self-encrypting drives (SEDs) (1)
- sff (1)
- software (1)
- software-defined radios (SDRs) (1)
- speeds and feeds (1)
- standalone (1)
- storage (1)
- systems (1)
- tactical wide area networks (1)
- technical support (1)
- technology (1)
- third-party motherboards (1)
- troposcatter communication (1)
- unlicensed spectrum (1)
- volatile memory (1)
- vpx (1)
- zero trust network (1)
- November 2024 (1)
- October 2024 (1)
- August 2024 (1)
- July 2024 (1)
- May 2024 (1)
- April 2024 (3)
- February 2024 (1)
- November 2023 (1)
- October 2023 (1)
- July 2023 (1)
- June 2023 (3)
- May 2023 (7)
- April 2023 (5)
- March 2023 (7)
- December 2022 (2)
- November 2022 (6)
- October 2022 (7)
- September 2022 (8)
- August 2022 (3)
- July 2022 (4)
- June 2022 (13)
- May 2022 (10)
- April 2022 (4)
- March 2022 (11)
- February 2022 (4)
- January 2022 (4)
- December 2021 (1)
- November 2021 (4)
- September 2021 (2)
- August 2021 (1)
- July 2021 (2)
- June 2021 (3)
- May 2021 (4)
- April 2021 (3)
- March 2021 (3)
- February 2021 (8)
- January 2021 (4)
- December 2020 (5)
- November 2020 (5)
- October 2020 (4)
- September 2020 (4)
- August 2020 (6)
- July 2020 (9)
- June 2020 (11)
- May 2020 (13)
- April 2020 (8)
- February 2020 (1)
- January 2020 (1)
- October 2019 (1)
- August 2019 (2)
- July 2019 (2)
- March 2019 (1)
- January 2019 (2)
- December 2018 (1)
- November 2018 (2)
- October 2018 (5)
- September 2018 (3)
- July 2018 (1)
- April 2018 (2)
- March 2018 (1)
- February 2018 (9)
- January 2018 (27)
- December 2017 (1)
- November 2017 (2)
- October 2017 (3)
Comments (1)