Company Profile
- Company
- Crédit Agricole
- Size
- Large Enterprise
- Industry
- Financial Services
- Location
- France
Crédit Agricole used PKZIP for two decades to compress files moving between mainframe platforms, exchanged across a private encrypted network. When those files had to reach subsidiaries outside that network, and platforms that were not IBM, the network could no longer supply the protection. PK Encrypt added encryption and PGP compatibility to a workflow the bank already ran, which is why the change was an upgrade rather than a migration.
Background
French international banking group Crédit Agricole is not only the world’s largest cooperative financial institution, but the second largest bank in France. Its rich history as the bank of farmers has given Credit Agricole a very local approach, with 100 subsidiaries in every part of France. But as Credit Agricole has developed into a modern bank, methods of data exchange needed to be modernized as well.
The federated structure is the detail that matters. A group of one hundred subsidiaries exchanges far more data internally than a centralized bank does, and each exchange crosses an organizational boundary even while it stays inside the group. Modernizing data exchange therefore meant changing a pattern repeated across every one of those sites.
Challenges
In the early 2000s, Crédit Agricole partnered with PKWARE using PKZIP, a flagship file compression solution that was stable and easy to use. PKZIP became the standard for file transfer between platforms. Data was compressed then exchanged through a private encrypted network. Even when the bank’s IT group was merged into a centralized group, Crédit Agricole chose PKZIP as the standard compression solution for all of their mainframe platforms. However, data exchange needs soon changed, and Credit Agricole had to be able to securely send files to subsidiaries around the world not only outside of the private encrypted network, but also to locations using different platforms.
The private encrypted network was doing the security work, not the file format. That distinction is what changed the requirement. Once files travelled outside the network, and to platforms running a different stack, protection had to belong to the file itself rather than to the channel carrying it.
Our Approach
Crédit Agricole’s familiarity with PKWARE solutions created a seamless and easy upgrade from compression to encryption.
Use Cases
Already deeply familiar with PKZIP and the quality of its compression, Crédit Agricole began comparing PKWARE’s compression and encryption solution for IBM, PK Encrypt. They needed a solution that included PGP compatibility, since many subsidiaries were running Linux platforms. PK Encrypt works seamlessly to compress and encrypt information from IBM mainframes while also including compatibility with PGP so information can be sent securely to Linux platforms.
Not only were the quality and pricing of PK Encrypt compelling for Crédit Agricole, the familiarity with PKWARE solutions created a seamless and easy upgrade from compression to encryption. After 20 years with PKZIP, a progression to PK Encrypt was a natural fit.
PGP compatibility is the specific reason the choice held. Encryption that only IBM systems can read solves nothing when the recipient is a Linux subsidiary, so interoperability mattered as much as strength. PK Encrypt compresses and encrypts on the mainframe and produces output those platforms can open, which keeps one process in place across an estate running more than one operating system.
Results
With more than one hundred thousand MIPS in play, Crédit Agricole is one of the largest users of PK Encrypt. The organization is contracted for unlimited platform connections, including Linux, and PK Encrypt has already been adopted on multiple platforms.
One hundred thousand MIPS measures processing workload rather than data volume, which indicates encryption running inside routine mainframe work rather than as a separate stage. The contract covers unlimited platform connections, so extending it to a further platform is a deployment decision rather than a commercial one.
