Artec EMA Features
Authentication
A modern, organization-wide archive has to allow users quick access to archived data. At the same time, however, quick access
must not result in compromise security and privacy. EMA® seamlessly integrates with all common authentication solutions and
protocols; it works with the technology in use in your IT infrastructure, not against it.
Among others, the appliance supports protocols such as LDAP (Lightweight Directory Access Protocol), OpenLDAP, Active
Directory, and RADIUS Servers. EMA® also offers a variety of settings that allow you to fine-tune user authentication to
suit your individual requirements. Live authentication data queries, which are performed against existing systems, ensure
maximum security when accessing the archive.
Single Sign-On
EMA® supports user authentication using single-sign on (SSO) to allow secure access to the archive while remaining
comfortable to use for users.
Using this authentication method, users can access the archive directly from their E-Mail client after successfully
logging on to their workstation.
Additional means identification, such as a separate username and password prompt, are no longer necessary and will
not be shown if authentication succeeds. This makes working with the archive extremely convenient for users while not
at all compromising the system's security.
Four-Eye-Principle
EMA®'s innovative Four-Eye-Principle authentication provides maximum protection for your organization's information.
Many core archive features can be configured that they generally cannot be performed by a single person alone. This
ensures that administrators or other users with a high level of privileges cannot purposely or accidentally perform
security-critical tasks on the archive without the consent of a second person. Specialized privacy and compliance
regulations, such as viewing or restoring E-Mail messages, can also be set up to suit your organization's needs using
Four-Eye-Principle authentication.
Users can be placed into two groups and given individual permissions by using EMA®'s sophisticated role-based
permission management. Once set up and enabled, access to security-critical features will only be possible representatives
from each group (e.g. a department manager and an employee representative) log in.
Four-Eye-Principle authentication is ideal for implementing organizational policies in order to ensure that archived
information is protected from unauthorized access.
Encryption
The Professional Way to Protect Sensitive Information
Your organization's information requires special security in order to prevent its abuse.
This is why EMA® uses a military-grade encryption concept that guarantees your data is protected. The appliance
protects archived information, such as E-Mail messages and documents, using powerful, state-of-the-art AES (Advanced
Encryption Standard) protection.
Access to archived information is only possible by using EMA®'s special appliance hardware. Furthermore, only the
appliance that encrypted the information is able to decrypt it Our security concept effectively prevents abuse through
malicious parties, even if they have administrator permissions to storage locations.
Web-based access to the archive itself is also secure because SSL, encryption technology known from the online banking
sector, is used to ensure eavesdropping on the connection does not reveal sensitive information.
User Access
Ease of access to archived information is what makes or breaks an archiving solution. If the steps necessary to access
an archive are long-winded and complicated, it loses its practical use and your users will most likely develop ways to
work around having to use it.
EMA® provides several ways to access archived information. With seamless mail client integration, users can access the
archive without having to leave Outlook or Notes. Since the installation of special client-side software is not required,
users do not have to launch an additional application to work with the archive. Instead, they can access it from within
an environment they are already familiar with.
Single sign-on ensures that users are automatically identified, and a cumbersome additional login to access the archive
is avoided.
Users can search for, view, and if necessary restore E-Mail messages, attachments, and other documents as required.
Permissions and access rules control which actions users can perform. EMA®'s ease of use allows users to get productive
without first having to sit through lengthy training sessions.
When we designed EMA®, we consciously designed against using all forms of stubbing, because these technologies are
anything but easy and uncomplicated. EMA®'s innovative full-text search is particularly fast at finding and restoring
E-Mail messages or documents while at the same time lowering resource usage for maximum performance.
Full Text Search
A Powerful Tool to Retain Control over Information
EMA® contains powerful full text search functionality that gives you easy access to the contents of your archive. The
full text search does not only archive E-Mail messages, but also attachments, documents, and files. The search interface
allows you to comfortably search through the entire archive using a single search mask. EMA® automatically indexes all
E-Mail messages and documents, and makes them show up in full text searches shortly after they enter the archive.
An immediate benefit when compared with conventional, locally created folder structures is that users throughout your
organization can find and restore information required to get work done a lot faster. They do not first need to look for
or remember specific locations that contain the required files. Because EMA®'s full text search was heavily optimized for
high performance, even the largest archives remain searchable and all required E-Mail messages or documents can quickly be
found when it is required.
The attribute editor (tagging) makes it even simpler to keep an overview over the contents of your archive. Depending
on the document content and assignment, you can use attributes to add additional information to archived items. You could,
for example, use attributes to create project-based department archives. Attributes also allow you to "freeze" items in your
archive that may not be removed from under any circumstances. This might be beneficial in situations that require a legal
hold of documents.
Permissions can additionally be adjusted for specific user groups in order to limit access to attribute data to selected
users.
Backup and Recovery
Many IT departments suffer from storage-intensive backups. These often contain redundant data, put a strong burden on
existing network resources, and can turn out to be difficult to handle when required data has to be restored. Using an EMA®
appliance opens up a completely new backup scenario. Depending on their permissions, users can search for and restore previously
archived E-Mail messages or documents without first having to consult an IT administrator.
The uniform archive structure provided by EMA® lowers the load on the file system and local mail folders. It also avoids the
common practice of creating local PST files, which waste space and create an additional burden on administrators. EMA® ensures
that backup environments remain maintainable, while catering the needs of users, IT professionals, and network administrators
alike.
ANA Automated Network Administrator®
A Smart Solution for IT Administration
ARTEC's ANA Server offers the latest technology for automated remote administration. ANA Server is an online server management
service that automates and facilitates complex administrative tasks.
ANA Server automatically downloads the latest software updates, creates digital signatures and monitors security-relevant
authentication and remote connections. ANA Automated Network Administrator® - the clever solution for modern IT administration.
Features:
- Automated download and installation of latest software updates
- Issuing of digital signatures
- Monitoring of security-relevant authentication and remote connections
Trusted EMA®
Advanced security features, such as the automatic encryption of all information and the closed-down architecture with a proprietary
operating system have always made EMA® one of the most secure solutions for digital archiving available on the market. Our latest
innovation, called Trusted EMA®, takes the advanced security measures one step further. EMA® is now the world's first archiving
appliance that is built according to the Trusted Computing standard (TC).
Almost all conventional systems and security mechanisms reveal a decisive weakness when examined closer: they are potentially
open to attacks when third parties can gain direct access to the hardware. Trusted EMA® prevents such attacks by creaking links to
hardware characteristics that are unique to each appliance. This protects the appliance from unauthorized manipulation and constructs
an unbreakable "safe" for your organization's archived data.
Trusted EMA® is based around a TPM chip (Trusted Platform Module), firmly anchored inside all EMA® appliances, which provides a
smart extension to our existing security concept. Using the TPM chip and the groundbreaking Trusted EMA® feature, the appliance-specific
data decryption key now receives even better protection against malicious hardware attacks. EMA® hardware and appliance software now
truly combine and form an inseparable unit.
Trusted EMA® can monitor individual access regulations and permissions that have been defined for users in your organization. This
ensures that the contents of the archive receive maximum protection, because Four-Eye-Principle authentication cannot be circumvented
in any way.
Adherence to any implemented organization-internal guidelines and compliance regulations can be monitored and guaranteed. In short,
we managed to make one of the most secure archiving solutions even more secure.
Main advantages:
- Maximum security for your data is provided by an integrated TPM chip
- Self-defense mechanism protects against manipulation and unauthorized access
- Adherence to individual user permissions and roles is enforced
- Guaranteed protection of the appliance-specific decryption key
- Provides enhanced security in local and cloud infrastructures