|
VeriSign, Inc. -
Network Security - Category
Directory
(650)
961-7500
487
E. Middlefield Road
Mountain View, California 94043
www.verisign.com
Sales
$1.1
billion
Business Description (source: SEC filings)
VeriSign, Inc. is a leading provider of critical infrastructure services
that enable Web site owners, enterprises, communications service providers,
electronic commerce, or e-commerce, service providers and individuals to
engage in secure digital commerce and communications. Our services include
the following core offerings: security services, naming and directory
services, and telecommunications services. We market our products and
services through our direct sales force, telesales operations, member
organizations in our global affiliate network, value-added resellers,
service providers, and our Web sites.
We are currently organized into two service-based lines of business: the
Internet Services Group and the Communications Services Group. The Internet
Services Group consists of the Security Services business and the Naming and
Directory Services business. The Security Services business provides
products and services that enable enterprises and organizations to establish
and deliver secure Internet-based services to customers and business
partners, and the Naming and Directory Services business acts as the
exclusive registry of domain names in the .com and .net generic top-level
domains, or gTLDs, and certain country code top-level domains, or ccTLDs.
The Communications Services Group provides Signaling System 7, or SS7,
network services, intelligent data base and directory services, application
services, and billing and payment services to wireline and wireless
telecommunications carriers. During 2003, we operated our business in three
reportable segments including the two described above, and the Network
Solutions business segment which was sold effective November 25, 2003.
Internet Services Group
The Internet Services Group consists of the Security Services business and
Naming and Directory Services business. The Security Services business
provides products and services to enterprises and organizations that want to
establish and deliver secure Internet-based services for their customers and
business partners. The following types of services are included in the
Security Services business: enterprise security services, including our
managed security and authentication services, and e-commerce services,
including our Web trust and payment services. The Naming and Directory
Services business provides registry services as the exclusive registry of
domain names in the .com and .net gTLDs and certain ccTLDs, as well as
providing other value added services and digital brand management services.
Security Services
Enterprise Security Services
Our enterprise security services include managed security services and
authentication services including public key infrastructure (“PKI”) services
for enterprises.
Managed Security Services (“MSS”). VeriSign’s MSS services enable
enterprises to effectively monitor and manage their network security
infrastructure on a 24x7 basis while reducing the associated time, expense,
and personnel commitments by relying on VeriSign’s security platform and
experienced security staff. Our MSS services include:
• Managed Firewall Service. The Managed Firewall Service provides
enterprises with management and monitoring of firewalls. VeriSign security
engineers and program managers stage the firewall devices and test them
prior to deployment; once deployed, devices are monitored 24x7. Ongoing
device management services include refinement of security policies, software
patches and upgrades, and quarterly security consultations.
• Managed Intrusion Detection Service. The Managed Intrusion Detection
Service provides management and monitoring of intrusion detection sensors,
designed to identify and counter malicious security events or potential
attacks against an organization’s network.
• Managed Virtual Private Network (“VPN”) Service. The Managed VPN Service
delivers encrypted site-to-site and remote access IPsec-compliant tunnel
solutions for Internet-based network computing environments.
We also provide network security consulting services to help enterprises
assess, design, and deploy cost-effective and scalable network security
solutions. Our consulting services are also available to help enterprises
integrate our PKI services with existing applications and databases and
advise on policies and procedures related to the management and deployment
of digital certificates. Our management services also include, among others,
managed DNS and DNS hosting, which are delivered through our registry
operations infrastructure.
VeriSign PKI Services. VeriSign offers Managed PKI Services and VeriSign Go
Secure! Services that can be tailored to meet the specific needs of
enterprises that wish to issue digital certificates to employees, customers
or trading partners.
• Managed PKI Services. The Managed PKI Service is a managed service that
allows an organization to use our trusted data processing infrastructure to
develop and deploy customized digital certificate services for its user
communities. The Managed PKI Service can be used by our customers to provide
digital certificates for a variety of applications, such as: controlling
access to sensitive data and account information, enabling digitally-signed
e-mail, encryption of e-mail, or Secure Socket Layer (“SSL”) sessions. The
Managed PKI Service can help customers create an online electronic trading
community, manage supply chain interaction, facilitate and protect online
credit card transactions or enable access to virtual private networks.
• Go Secure! Services. Go Secure! is a set of software modules that enable
enterprises to quickly build digital certificate-based security into their
off-the-shelf transaction and communication applications. Go Secure!
Services complement our Managed PKI Service and are designed to incorporate
digital certificates into existing applications such as e-mail, browser,
directory and virtual private network devices as well as other devices.
• VeriSign Affiliate PKI Software and Services. VeriSign Affiliate PKI
Software and Services are sold to a wide variety of entities that provide
electronic commerce and communications services over wired and wireless
Internet Protocol, or IP, networks. We designate these types of
organizations as “VeriSign Affiliates” and provide them with a combination
of technology, support and marketing services to facilitate their initial
deployment and ongoing delivery of digital certificate services. In some
instances, we have invested in VeriSign Affiliates and hold a minority
interest of less than 20%.
VeriSign Affiliates can license either our Service Center or Processing
Center offerings. The Service Center and Processing Center offerings are
based on our software platform and enable a VeriSign Affiliate to offer one
or more types of digital certificate services.
• The Service Center offerings provide VeriSign Affiliates with all of the
capabilities needed to perform subscriber enrollment and authentication,
digital certificate application approval, directory hosting, customer
support, billing integration and report generation from within their
facilities or act as an outsource provider of the Managed PKI Service, while
utilizing our secure data centers for back-end processing.
• The Processing Center provides a VeriSign Affiliate with all of the
capabilities of the Service Center as well as the software modules required
to perform all certificate life cycle services of issuance, management,
revocation and renewal from within its own secure data center.
VeriSign Affiliates typically enter into a multi-year technology licensing
and revenue sharing agreement with us whereby we receive up-front licensing
fees for the Service Center or Processing Center technology, as well as
ongoing royalties from each digital certificate or the Managed PKI Service
sold by the VeriSign Affiliate.
e-Commerce Services
Our e-commerce services include our Web trust services and payment services.
Web Trust Services. Web trust services include our server digital
certificate services and content signing digital certificate services.
Server certificate services enable Internet merchants to implement and
operate secure Web sites that utilize SSL. These services provide Internet
merchants with the means to identify themselves to consumers and to encrypt
communications between consumers and their Web site. Our content signing
digital certificate services provide software developers the means to
identify themselves and the validity of their software to the consumers and
relying software applications.
We currently offer the following Web server digital certificate services and
content signing digital certificate services: Each is differentiated by the
target application of the server that hosts the digital certificate.
• Secure Site and Secure Site Pro. Secure Site is our standard service
offering that enables 40-bit SSL when communicating with export-version
Netscape® and Microsoft® Internet Explorer browsers and 128-bit SSL
encryption when communicating with domestic-version Microsoft and Netscape
browsers. We also offer an upgraded version of this service, called Secure
Site Pro, which enables 128-bit SSL encryption with both domestic and export
versions of Microsoft and Netscape browsers. Secure Site Pro also includes a
third party site availability monitoring evaluation, a network security
monitoring trial, a site performance monitoring evaluation, and additional
warranty protection.
• Commerce Site and Commerce Site Pro. Our Commerce Site and Commerce Site
Pro offerings combine the features and functionality of our Secure Site
offerings with our payment services offerings, providing existing sites that
want to offer e-commerce solutions with a comprehensive suite of services to
secure and process online payments.
• Content Signing Certificates. We offer several code signing certificates
based on the platform for which customers wish to sign the code. Platforms
include Microsoft Authenticode, Microsoft Office and VBA, Symbian, Sun Java,
Netscape, Microsoft Smartphone, Macromedia Shockwave and Marimba Castanet.
Microsoft Authenticode certificates are also used to authenticate developers
for various Microsoft logo programs.
• Thawte Branded Digital Certificates. We offer SSL and Code Signing
security services under the Thawte brand. These services use the same
underlying infrastructure, and are targeted at small business and
independent software developers.
Payment Services. Using our payment gateway, Internet merchants are able to
securely authorize and settle a variety of payment types, including credit,
debit and purchase cards, electronic checks, and automated clearing house
transactions over the Internet.
Naming and Directory Services
VeriSign’s Naming and Directory Services include our domain name registry
services and digital brand management services.
Domain Name Registry Services. We are the exclusive registry of domain names
within the .com and .net gTLDs under agreements with the Internet
Corporation for Assigned Names and Numbers, or ICANN, and the Department of
Commerce, or DOC. As a registry, we maintain the master directory of all
second-level domain names in these top-level domains. We own and maintain
the shared registration system that allows all registrars to enter new
second-level domain names into the master directory and to submit
modifications, transfers, re-registrations and deletions for existing
second-level domain names.
We are also the exclusive registry for domain names within the .tv and .cc
ccTLDs. These top-level domains are supported by our global name server
constellation and shared registration system. In addition, we have made .bz
domain name registration services available through our outsourced hosting
environment, which enables domain name registrars and resellers to
simultaneously access .bz registries. We also provide internationalized
domain name, or IDN, services that enable Internet users to access Web sites
in their local language characters. Currently, IDNs are available in more
than 350 languages such as Chinese, Greek, Korean and Russian.
Digital Brand Management Services. We offer a range of services that we
refer to as Digital Brand Management Services to help legal professionals,
information technology professionals and brand marketers monitor, protect
and build digital brand equity. These services include our domain name
registration services for both gTLDs, such as .com, and ccTLDs, such as .de,
and our brand monitoring services.
Communications Services Group
The Communications Services Group provides managed communications services
to wireline and wireless telecommunications carriers, cable companies and
enterprise customers. Our managed communication service offerings include
network services, intelligent database and directory services, application
services, and billing and payment services.
Network Services
Through our network services, we provide connections and services that
signal and route information within and between telecommunication carrier
networks.
SS7 Connectivity and Signaling. Our Signaling System 7, or SS7, network, is
an industry-standard system of protocols and procedures that is used to
control telephone communications and provide routing information in
association with vertical calling features, such as calling card validation,
local number portability, toll-free number database access and caller
identification. Our SS7 trunk signaling service reduces post-dial delay,
allowing call connection almost as soon as dialing is completed which
enables telecommunications carriers to deploy a full range of intelligent
database services more quickly and cost effectively. By using our
trunk-signaling service, carriers simplify SS7 link provisioning, and reach
local exchange carriers and wireless carriers’ networks through our direct
access to hundreds of carriers.
Seamless Roaming for Wireless. We offer wireless carriers seamless roaming
services using the ANSI-41 and GSM signaling protocol that allow carriers to
provide support for roamers visiting their service area, and for their
customers when they roam outside their service area. This service also
allows number validation inside and outside carriers’ service areas by
accessing our SS7 network.
Communications Assistance for Law Enforcement Act (CALEA). Our NetDiscovery
services enable telecommunications carriers to meet the requirements of
CALEA through provisioning, access and delivery of call information from
carriers to law enforcement agencies.
Intelligent Database and Directory Services
We enable carriers to find and interact with network databases and conduct
database queries that are essential for many advanced services, including
the following:
• Number Portability. Local Number Portability (“LNP”) and Wireless Number
Portability (“WNP”) allow telephone subscribers to switch local service
providers while keeping the same telephone number.
• Calling Name (“CNAM”) Delivery. Our CNAM Delivery service enables carriers
to query regional Bell operating companies and major independent carriers
and provide customers with caller identification services.
• Line Information Database (“LIDB”). LIDB provides subscriber information
(such as the subscriber’s service profile and billing specifications) to
other carriers enabling them to respond to calls (e.g. whether to block
certain calls, allow collect calls, etc.).
• Toll-free Database Services. Leveraging VeriSign’s SS7 network, our
toll-free services allow customers to complete 8xx calls throughout the U.S.
and Canada.
• TeleBlock Do Not Call (“DNC”). TeleBlock DNC provides telemarketers with a
DNC management tool that automatically screens and blocks outgoing calls to
national, state, third-party and in-house DNC lists.
Application Services
Through our MetcalfTM Global Messaging (“GM”) services, we enable wireless
carriers to offer messaging services between carrier systems and devices,
and across disparate networks and technologies so that customers can
exchange messages outside the carrier’s network.
Billing and Payment Services
The Communications Services Group also offers advanced billing and customer
care services to wireline and wireless carriers. Our advanced billing and
customer care services include:
Wireline Clearinghouse Services. Through our clearinghouse services, we
serve as a distribution and collection point for billing information and
payment collection for services provided by one carrier to customers billed
by another.
Wireless Clearinghouse Services. Our settlement and exchange services enable
wireless carriers to settle telephone traffic charges with their roaming
partners in North America and portions of Latin and South America. We also
provide wireless carriers with fraud management, SS7 monitoring, and other
services.
Billing Services. Through our speedSUITETM and SmartPay services, we provide
wireless carriers with an end-to-end customer relationship management system
that supports prepaid and post-paid wireless services. Carriers have access
to a real-time account management platform, administered via a Web
interface, designed to make prepaid wireless plans flexible and convenient.
Operations Infrastructure
Our operations infrastructure consists of secure data centers in Mountain
View, California; Dulles, Virginia; Lacey, Washington; Providence, Rhode
Island; Overland Park, Kansas; Melbourne, Australia; and Kawasaki, Japan.
Many of our VeriSign Affiliates also operate secure data centers in their
geographic areas. Most of these secure data centers operate on a 24-hour a
day, 7 days per week basis, supporting our business units and services. Key
features of our operations infrastructure include:
• Distributed Servers. We deploy a large number of high-speed servers to
support capacity and availability demands that in conjunction with our
proprietary software offers automatic failover, global and local load
balancing and threshold monitoring on critical servers.
• Advanced Telecommunications. We deploy and maintain redundant
telecommunications and routing hardware and maintain high-speed connections
to multiple Internet service providers (“ISPs”) to ensure that our mission
critical services are readily accessible to customers at all times.
• Network Security. We incorporate architectural concepts such as protected
domains, restricted nodes and distributed access control in our system
architecture. We have also developed proprietary communications protocols
within and between software modules that are designed to prevent most known
forms of electronic attacks. In addition, we employ firewalls and intrusion
detection software, and contract with security consultants who perform
periodic attacks and security risk assessments.
As part of our operations infrastructure for our domain name registry
services, we operate all thirteen domain name servers that answer domain
name lookups for the .com and .net zones. We also operate two of the
thirteen root zone servers, including the “A” root, which is the
authoritative root zone server of the Internet’s domain name system (“DNS”).
The domain name servers provide the associated name server and IP address
for every .com and .net domain name on the Internet and a large number of
other top-level domain queries, resulting in an average of over 9 billion
responses per day during 2003. These name servers are located around the
world, providing local domain name service throughout North America, in
Europe, and in Asia. Each server facility is a controlled and monitored
environment, incorporating security and system maintenance features. This
network of name servers is one of the cornerstones of the Internet’s DNS
infrastructure.
To provide our communications services, we operate a SS7 network composed of
specialized switches, computers and databases strategically located across
the United States. These elements interconnect our customers and U.S.
telecommunications carriers through leased lines. Our network currently
consists of 15 mated pairs of SS7 signal transfer points that are
specialized switches that manage SS7 signaling, and into which our customers
connect. We own ten pairs and lease capacity on six pairs of SS7 signal
transfer points from regional providers. Our SS7 network control, located in
Overland Park, Kansas, is staffed 24 hours a day, 7 days per week. As part
of our operations infrastructure for network services, we also have several
SS7 network signal transfer point sites. These sites are maintained at 14
locations throughout the United States.
Call Center and Help Desk. We provide customer support services through our
phone-based call centers, e-mail help desks and Web-based self-help systems.
Our California call center is staffed from 5 a.m. to 6 p.m. Pacific Time and
employs an automated call directory system to support our Security Services
business. Our Virginia call center is staffed 24 hours a day, 7 days per
week to support our Naming and Directory Services. All call centers also
have Web-based support services which are available on a 24-hour a day, 7
days per week basis, utilizing customized automatic response systems to
provide self-help recommendations and a staff of trained customer support
agents.
Operations Support and Monitoring. We have an extensive monitoring
capability that enables us to track the status and performance of our
critical database systems at sixty-second intervals, and our global
resolution systems at four-second intervals. Our distributed Network
Operations Centers are staffed 24 hours a day, 7 days per week.
Disaster Recovery Plans. We have disaster recovery and business continuity
capabilities that are designed to deal with the loss of entire data centers
and other facilities. Our Naming and Directory Services business maintains
dual mirrored data centers that allow rapid failover with no data loss and
no loss of function or capacity. Our PKI and payment services businesses are
similarly protected by having service capabilities that exist in both of our
East and West Coast data center facilities. Our critical data services
(including digital certificates, domain name registration,
telecommunications services and global resolution) use advanced storage
systems that provide data protection through techniques such as mirroring
and replication.
|
|