SFTP has proven to be a reliable and secure method for transferring data, especially when used as part of automated workflows between applications and organisations. By overlaying ssh protocols on top of ftp, sftp helps ensure compliance within regulated industries such as Healthcare, Finance, Education and Defence.
Despite this, one of its biggest drawbacks lies in the fact that ssh implementation is not standardised. Unlike the IETF’s ratified ftp (File Transfer Protocol) specifications, sftp can be implemented in a variety of ways using ssh. In short, different sftp servers and clients can have different features, commands and options. Once set within a workflow process it is difficult to change, which is especially problematic when connecting new and legacy servers or when embedded within back-office applications.
Take the example of the NHS Supply Chain, which has been in operation for years, and connects with a wide range of organisations both in and outside of the NHS:
NHS Supply Chain teams send out orders to suppliers using their ordering system which ultimately transfers orders to suppliers via sftp.
The inventory system is heavily integrated into the ordering system which utilises obsolete sftp software from a vendor which closed shop 5 years ago.
As a technical offering the old sftp system now fails on two critical issues:
SSH key support is limited to older key types. ED25519 key exchange is not and will never be supported. This means the supply chain system will be unable to communicate with the modern up-to-date sftp services most organisations should be running.
Directory Traversal is not supported. Even if a connection could be made, the sender can only place orders in the root directory, which in most implementations is not permitted.
Practically this means that supply chain partners have been finding it increasingly difficult to support the legacy configuration required. There have been many cases recently where supply chain partners are suddenly finding they can’t negotiate or establish a secure connection and even if they were to accept older key types, no orders could be uploaded.
Amending the NHS Supply Chain order management system to use a replacement sftp server is hugely problematic and would be time consuming, disruptive and undoubtedly very expensive. Undoubtedly the motivation falls upon the supply chain vendors to resolve the problems which ultimately lands their infrastructure team with pressure to quickly find a solution.
So, what can be done to make ensure interoperability between SFTP systems?
If two people who spoke different languages needed to communicate you’d use a translator; to establish sftp interoperability you can make use of a broker service or gateway between the two organisations.
DOQEX has been built to do exactly this. With DOQEX as the intermediate secure data exchange there is no need to change existing systems, simply configure the exchange and continue working.
Going back to the NHS Supply Chain example, these were the actions taken:
The NHS Supply Chain ordering system connects directly to the customer’s secure DOQEX service, which is configured to negotiate using the precise protocols and ciphers the sender supports.
DOQEX also configured and implemented a Virtual File Store which maps the customer’s own in-house sftp service to their DOQEX service; again the precise protocols and key exchange at the receiving end are configured.
Now, files and data can be exchanged without the need to change either party’s processes or software.
File Forwarding is configured for each specific NHS Supply Chain user and a secure workspace, every file which is delivered to the DOQEX Service via sftp by the NHS is automatically securely sent to the customer’s own sftp server for processing.
DOQEX created a new capability within the sftp service to work around the lack of directory traversal. An option was added to restrict and force files to be delivered to the secure workspace without the need for the sftp sending client to be able to navigate a directory structure.
With DOQEX configured, the NHS Supply Chain can now securely send data and files to its suppliers regardless of its existing processes and software. Likewise, the supplier securely receives files and data from their DOQEX service.
The DOQEX architecture also means clients are less susceptible to a wide array of common security compromises. Every customer service we provision is a discrete instance, a private cloud service with unique keys and configuration for each.
But isn’t this a long-winded and expensive way of solving the problem?
Not at all. All the work, configuration and extension capability were performed in less than a fortnight.
In the instant above, as an existing DOQEX customer, no additional costs or licences are necessary, as it’s all part of our managed service.
Time, Money, Risk reduction – we helped our customer, and the NHS save not just time and money, but also replaced an unsupportable process with one which is automated, flexible and highly secure.
For a technical view of the differences between ssh key types, see https://security.stackexchange.com/questions/90077/ssh-key-ed25519-vs-rsa
SFTP workflow automation
Getting Old & New SFTP Servers to Talk.
SFTP has proven to be a reliable and secure method for transferring data, especially when used as part of automated workflows between applications and organisations. By overlaying ssh protocols on top of ftp, sftp helps ensure compliance within regulated industries such as Healthcare, Finance, Education and Defence.
Despite this, one of its biggest drawbacks lies in the fact that ssh implementation is not standardised. Unlike the IETF’s ratified ftp (File Transfer Protocol) specifications, sftp can be implemented in a variety of ways using ssh. In short, different sftp servers and clients can have different features, commands and options. Once set within a workflow process it is difficult to change, which is especially problematic when connecting new and legacy servers or when embedded within back-office applications.
Take the example of the NHS Supply Chain, which has been in operation for years, and connects with a wide range of organisations both in and outside of the NHS:
NHS Supply Chain teams send out orders to suppliers using their ordering system which ultimately transfers orders to suppliers via sftp.
The inventory system is heavily integrated into the ordering system which utilises obsolete sftp software from a vendor which closed shop 5 years ago.
As a technical offering the old sftp system now fails on two critical issues:
SSH key support is limited to older key types. ED25519 key exchange is not and will never be supported. This means the supply chain system will be unable to communicate with the modern up-to-date sftp services most organisations should be running.
Directory Traversal is not supported. Even if a connection could be made, the sender can only place orders in the root directory, which in most implementations is not permitted.
Practically this means that supply chain partners have been finding it increasingly difficult to support the legacy configuration required. There have been many cases recently where supply chain partners are suddenly finding they can’t negotiate or establish a secure connection and even if they were to accept older key types, no orders could be uploaded.
Amending the NHS Supply Chain order management system to use a replacement sftp server is hugely problematic and would be time consuming, disruptive and undoubtedly very expensive. Undoubtedly the motivation falls upon the supply chain vendors to resolve the problems which ultimately lands their infrastructure team with pressure to quickly find a solution.
So, what can be done to make ensure interoperability between SFTP systems?
If two people who spoke different languages needed to communicate you’d use a translator; to establish sftp interoperability you can make use of a broker service or gateway between the two organisations.
DOQEX has been built to do exactly this. With DOQEX as the intermediate secure data exchange there is no need to change existing systems, simply configure the exchange and continue working.
With DOQEX configured, the NHS Supply Chain can now securely send data and files to its suppliers regardless of its existing processes and software. Likewise, the supplier securely receives files and data from their DOQEX service.
The DOQEX architecture also means clients are less susceptible to a wide array of common security compromises. Every customer service we provision is a discrete instance, a private cloud service with unique keys and configuration for each.
But isn’t this a long-winded and expensive way of solving the problem?
Not at all. All the work, configuration and extension capability were performed in less than a fortnight.
In the instant above, as an existing DOQEX customer, no additional costs or licences are necessary, as it’s all part of our managed service.
Time, Money, Risk reduction – we helped our customer, and the NHS save not just time and money, but also replaced an unsupportable process with one which is automated, flexible and highly secure.
For a technical view of the differences between ssh key types, see https://security.stackexchange.com/questions/90077/ssh-key-ed25519-vs-rsa
< Back to news & blogs
Want to know more?
Call Us
01904 500255
Message Us