Enterprise Applications Security, Embedded SSH, Embedded SSL, Embedded SSH, Embedded IPSEC and OpenSSH/OpenSSL Alternatives, FIPS certified, FIPS certification, FIPS 140-2 - Device Security Framework
Mocana Corporation - Securing Devices, Applications & the Enterprise.
NEWSLETTER   
Newsletter Sign Up contactus
  • About


Mocana delivers and open standards based, full featured, RFC compliant embedded Extensible Authentication Protocol (EAP) solution. The Mocana NanoEAP solution offers a complete peer (supplicant) as well as an authenticator that can support pass-through mode and stand-alone mode. Both the supplicant and the authenticator(s) are available individually or as a bundle. The Mocana NanoEAP solution can prevent unauthorized access to your network devices, easily update your security handling, and independently manage multiple users who require unique security configurations. Separate VLANs can be served by separate EAP instances. Upper-layer APIs enable session creation, initialization, statistics collection and provides several callback functions and APIs to configure and monitor a particular EAP session. Lower-layer APIs enable EAP communication over Ethernet, PPP, UDP, or any other protocol.

The NanoEAP model contains the following elements:


EAP Authentication


Extensible Authentication Protocol Framework

EAP Architecture

Currently, there are approximately 40 different EAP methods. Methods defined in IETF RFCs include:

LEAP:The Lightweight Extensible Authentication Protocol (LEAP) is a proprietary EAP method developed by Cisco Systems prior to the IEEE ratification of the 802.11i security standard.

EAP-TLS:
EAP-Transport Layer Security or EAP-TLS, defined in RFC 5216, is an IETF open standard, and is well-supported among wireless vendors.

EAP-MD5: defined in RFC 3748, is the only IETF Standards Track based EAP method.

EAP-PSK: defined in RFC 4764, is an EAP method for mutual authentication and session key derivation using a Pre-Shared Key (PSK).

EAP-TTLS: EAP-Tunneled Transport Layer Security, or EAP-TTLS is an EAP protocol that extends TLS. It was co-developed by Funk Software and Certicom. It is widely supported across platforms.

EAP-IKEv2: is an EAP method based on the Internet Key Exchange Protocol version 2 (IKEv2). It provides mutual authentication and session key establishment between an EAP peer and an EAP server.

PEAP: is a joint proposal by Cisco Systems, Microsoft and RSA Security as an open standard. It is already widely available in products, and provides very good security. It is similar in design to EAP-TTLS, requiring only a server-side PKI certificate to create a secure TLS tunnel to protect user authentication.

EAP-FAST: (Flexible Authentication via Secure Tunneling) is a protocol proposal by Cisco Systems as a replacement for LEAP.[7] The protocol was designed to address the weaknesses of LEAP while preserving the "lightweight" implementation.

EAP for GSM: Subscriber Identity is used for authentication and session key distribution using the Global System for Mobile Communications (GSM) Subscriber Identity Module (SIM). EAP-SIM is defined in RFC 4186.

EAP for UMTS: Authentication and Key Agreement is used for authentication and session key distribution using the Universal Mobile Telecommunications System (UMTS) Universal Subscriber Identity Module (USIM). EAP AKA is defined in RFC 4187
.

Untitled Document
 
Supported processor platforms:
Processor Platforms

Awards and Certifications
Awards and Certifications
Nominations
2010 Spiffy Awards Nominee

Sales | Support | Contact | Privacy Policy | FAQs | Site Map | Referral Program

Copyright © 2010 Mocana Corporation
  • Benefits


NanoEAP™ Features


Ease of Control

Mocana NanoEAP provides system administrators complete control of authentication configuration — deciding when supplicants should be authenticated, how to handle connectivity loss, adding new authentication methods, and more. This flexibility is easily achieved using common configuration templates as models for customization.

Platform Independent
NanoEAP, like all of Mocana’s device security toolkits, is CPU-architecture and platform independent, working with any TCP/IP stack. It works seamlessly out of the box. Platforms supported out-of-the-box include Linux, Monta Vista Linux, VxWorks, OSE, Nucleus, Solaris, ThreadX, Windows, MacOS X, (ARC) MQX, pSOS, and Cygwin. NanoEAP is endian-neutral, and can be used without an RTOS if required.

IETF Compliant Implementations
Authentication Support
EAP-TLS and EAP-TTLS Cipher Support
Additional Cryptography Support
NanoEAP Features

Untitled Document
 
Supported processor platforms:
Processor Platforms

Awards and Certifications
Awards and Certifications
Nominations
2010 Spiffy Awards Nominee

Sales | Support | Contact | Privacy Policy | FAQs | Site Map | Referral Program

Copyright © 2010 Mocana Corporation
  • Benefits


NanoEAP™ Benefits

Speed
NanoEAP consistently outperforms. NanoEAP’s assembly language optimization and support for hardware acceleration make it the fastest embedded EAP implementation on the market. Benchmark testing on a 700 MHz Pentium III CPU with Embedded EAP-SIM, Embedded EAP peer running on Linux, and Mocana NanoEAP authenticator in RADIUS pass-through mode with 100 sessions/sec yielded only a two percent CPU utilization rate. It includes strong code reuse for a smaller memory footprint.

Flexibility
Mocana NanoEAP delivers incredible flexibility, as it is able to support multiple authentication schemes, including generic token cards, one-time passwords, AKA, TLS, RADIUS, LEAP and many others. You get to determine where supplicants should be authenticated as well as easily add new authentication methods. It’s a snap to independently manage multiple users who require unique security configurations.

Dramatically Speeds Your Development Cycle NanoEAP is a ready-made, pre-optimized and exhaustively tested EAP solution that frees your in-house development resources to focus on what’s really important: the functionality of your project. As well, NanoEap is cleared for export. As always, Mocana’s developer support team is available 24/7/365 to help you anytime. Untitled Document
 
Supported processor platforms:
Processor Platforms

Awards and Certifications
Awards and Certifications
Nominations
2010 Spiffy Awards Nominee

Sales | Support | Contact | Privacy Policy | FAQs | Site Map | Referral Program

Copyright © 2010 Mocana Corporation
  • Architecture


NanoEAP™ Architecture

Mocana’s products, together, make up what we call the Device Security FrameworkTM.
The DSF is designed to secure all aspects of any connected device. All components of the Device Security Framework are built on a common architecture and share a common API and cryptographic code base. As a device designer, you can choose only the components you need for your particular project... or standardize company-wide on the DSF’s common code base, future-proofing your investment with this broad, flexible and extensible security architecture.
NanoBoot Architecture
[enlarge]
Untitled Document
 
Supported processor platforms:
Processor Platforms

Awards and Certifications
Awards and Certifications
Nominations
2010 Spiffy Awards Nominee

Sales | Support | Contact | Privacy Policy | FAQs | Site Map | Referral Program

Copyright © 2010 Mocana Corporation
Mocana products are built for developers, OEMs and ISVs. DSF for Android, NanoSSH and other products are not finished security applications usable by IT personnel or end users.
Please fill out the form below. All fields are required.
First Name
Last Name
Company
Job Title
Phone
State
Email

Your Privacy

Country
Embedded security code packages can only be delivered to valid business email addresses.
When is your project starting?


What is your target OS/CPU?



I'd like to receive email updates and news from Mocana*

I have read the Mocana Terms and Conditions
Malware Free!
COST COMPARISON:
Mocana vs Open Source
Cost Comparision: Build vs Buy Button
Features & Benefits

Greatly speeds development cycle

Open-standards, RFC compliant, full featured

Easy to install and use

Source Code

Code reuse for smaller memory footprint

Advanced well documented APIs

Advanced cryptography support

RTOS neutral and transport agnostic

High performance zero-threaded, asynchronous architecture