The technology, known as the “secure transaction management system” (STMS), was developed by Roberto Tamassia, director of Brown University’s Center for Geometric Computing, and his research team, building on years of basic research supported by the Defense Advanced Research Projects Agency (DARPA) and the National Science Foundation.
In 2004, Tamassia and a group of veteran Internet entrepreneurs launched IAM Technology Inc. to commercialize STMS in a variety of applications, licensing the technology from Brown and committing to sponsor more research there for three years. It’s all paying off, with new applications for STMS being tested in multiple settings – including, this summer, a project with Amazon.com that applied the security system to remote-storage applications.
Providence Business News spoke with David Croston, president of the Lexington, Mass.-based company.
PBN: IAM Technology was created specifically to commercialize STMS?
CROSTON: Yes, but not just to commercialize the original technology, which was actually developed for the Department of Defense, but also to fill the void of the lack of federal funding into universities and make a commitment to actual intellectual property growth and derivative technology as we developed it. So IAM Technology is the largest [provider of funds for] basic research in the computer science department at Brown. And we are a very small group – I have eight employees.
PBN: The research you’re sponsoring is in the area of trust and authentication?
CROSTON: Yes. The principal focus is the validation of a data object. That goes really across the spectrum from security, to authenticating messaging, to authenticating domains, and in the case [of the Amazon project], the authentication of third-party storage.
Beyond Cash Donations: How New Forms of Giving Are Transforming Not-for-Profit Accounting
Evolving Funding Landscape for Not-for-Profits Not-for-profit organizations are being asked to do more with less,…
Learn More
PBN: Is the need for that type of authentication driven by post-911 concerns?
CROSTON: I would say it’s more the SEC has changed many of the guidelines that a public company must meet. Sarbanes-Oxley requires that a CEO and a CFO sign off on the integrity of their data. It’s basically given license to technology companies to go scream from the rooftops: You’ve got to buy all this gear so it’s actually secure data. And while we’re not complaining about it, there are reactive ways of doing it, and there are proactive ways. [STMS] is unique, it’s patented, it was developed for the Department of Defense, but we felt it had commercial applications …We have filed six patents in two years based on the investment we have made in Ph.D. students at the Center for Geometric Computing.
PBN: What are the main uses of this technology?
CROSTON: The principal use today and the appliance we have created validates the integrity of what are messages – text-readable messages that are being sent between servers that you would never see. This messaging is not e-mail; it’s called Web services messaging … going between servers. The problem is, how do you trust those messages? Each is digitally signed by the server that sent it. And what our technology does, we tell the server that’s receiving it that this can be trusted.
PBN: One unique aspect of your technology is that it’s decentralized – you don’t have to go to a central source for verification.
CROSTON: Yes, usually you’re either dealing with a [central source] or at least accessing a database housed [there]. And traditional technology takes literally one or two seconds, while we bring it down to less than a millisecond.
PBN: Why is that important?
CROSTON: Because everything has a cost. When you think of these major financial institutions and their trading platforms, or the mortgage company and their desire to give customers instant decisions … in most markets, that means significant amounts of money. We’re talking hundreds of millions of dollars.
PBN: With Amazon, you looked at third-party storage.
CROSTON: Our goal was to give undergrads, graduate students and post-docs … IAM Technology is able to provide these students not just a vehicle for their intellectual prowess, but a vehicle for practical skills in the industry. We’ve developed something that could sit on a desktop that you could drag and drop files into and absolutely validate the integrity of the third-party storage without knowing where that storage was, or needing to have any cumbersome process associated with it.
PBN: Will this be the first commercial use of STMS?
CROSTON: Amazon may not be the ideal user of that … while the prototype and the opportunity for the students … was with Amazon, the business opportunity actually, there are multiple possible avenues for this technology.
PBN: How big is the potential?
CROSTON: What is unique about the technology is that it is highly scalable and it does not take any significant storage space on the server. And it’s the fastest validation technology on the market. Its applications actually change the paradigm of validation in a number of core markets, among them telecommunications, financial services, the integrity of a domain itself.
PBN: Is this already being used in the marketplace?
CROSTON: Yes. One of our biggest customers is British Telecom, which is still in research capacity. But they’re testing it on their 21st-century backbone and have been doing so for over a year. We have one of the largest commercial certificate authorities, QuoVadis, in Bermuda. … They actually manage the electronic signing of documents in Bermuda. We have a group in Rome that is using it for validation of stock quotes. •












