
By Gilad Parann-Nissany | Article Rating: |
|
June 19, 2012 02:00 PM EDT | Reads: |
793 |

Cloud encryption keeps coming up as one of the hottest topics for enterprises migrating to the cloud. IT departments are constantly pushed to cut costs and utilize compute resources more efficiently, hence cloud computing is the natural evolution, yet at the same enterprises cannot compromise on cloud security, and cloud encryption should be considered high on the list as it segregates and “hides” your data from other virtual entities hosted on the same physical cloud infrastructure.
What’s my cloud provider’s encryption approach?
Cloud data security and cloud encryption comes in many forms and shapes. While some cloud providers will provide the encryption service, some will provide a “shopping list” of cloud encryption companies, and others will provide both. But which one is best for your needs?
A good place to start would be to define what your needs are J. Many enterprises tend to assume that data encryption automatically guarantees data confidentiality but that’s not the case. Data confidentiality is achieved only if you, the enterprise, maintain control over both the encryption process as well as the encryption keys.
If anyone else but your authorized team controls the encryption process, or manages the encryption keys for you – data confidentiality is not achieved. If cloud security is a regulatory requirement, or if intellectual property should be protected, enterprises should consider deploying and managing encryption by themselves.
Unfortunately this not an easy task to accomplish. While there are many cloud encryption technologies out there, most will answer only some of the requirements by working only with specific database kinds, or supporting a limited range of your operating systems. The ideal cloud encryption solution is the one supporting all your operating systems and databases types.
What about the encryption keys?
Now that you’ve figured out your encryption strategy and narrowed down your search to a limited number of encryption solutions who can address your cloud security requirements, there’s still the critical question of who’s responsible for my encryption keys management?
As mentioned above, if your enterprise requires data confidentiality, it is up to you to manage the encryption keys. Until recently, there were two available options; Consume key management as a service (which is equivalent in essence to trusting another entity with your encryption keys); or deploying a key management server back in your data center and integrate it with your cloud encryption software of choice, a fact which frustrates many IT managers since it eliminates many of the cloud benefits such as scalability and flexibility and burdens them with another on premise server to manage while all they wanted to do to begin with is to migrate to the cloud.
Fortunately, new and emerging technologies have been recently announced to resolve the cloud key management pain. One example is the split-key encryption technology (read more about it here or download the whitepaper) which for the first time enables enterprises migrating to the cloud to use a key management as a service without scarifying trust, by splitting an encryption key into two parts. The first part – the master key – is common to all data objects in the application. It remains the sole possession of the application owner and is unknown to the cloud provider or the encryption vendor; while the second part is different for each data object and is stored by the Key Management Service.
Ariel Dan is co-founder of Porticor Cloud Security
Read the original blog entry...
Published June 19, 2012 Reads 793
Copyright © 2012 SYS-CON Media, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
More Stories By Gilad Parann-Nissany
Gilad Parann-Nissany, Founder and CEO at Porticor is a pioneer of Cloud Computing. He has built SaaS Clouds for medium and small enterprises at SAP (CTO Small Business); contributing to several SAP products including BusinessByDesign and reaching more than 8 million users. Recently he has created a consumer Cloud at G.ho.st - a cloud operating system that delighted hundreds of thousands of users while providing browser-based and mobile access to data, people and a variety of cloud-based applications. He is now CEO of Porticor, a leader in Virtual Privacy and Cloud Security.
![]() Jun. 20, 2012 04:07 PM EDT Reads: 258 |
By Liz McMillan Jun. 20, 2012 04:00 PM EDT Reads: 329 |
By Elizabeth White ![]() Jun. 20, 2012 01:54 PM EDT Reads: 385 |
By Jeremy Geelan Jun. 20, 2012 12:00 PM EDT Reads: 374 |
By Liz McMillan ![]() Jun. 20, 2012 11:00 AM EDT Reads: 910 |
By Liz McMillan ![]() Jun. 20, 2012 06:00 AM EDT Reads: 2,377 |
By Elizabeth White ![]() Jun. 20, 2012 05:45 AM EDT Reads: 3,679 |
By Liz McMillan ![]() Jun. 19, 2012 08:30 AM EDT Reads: 3,436 |
By Pat Romanski ![]() Jun. 19, 2012 06:00 AM EDT Reads: 1,941 |
By Elizabeth White ![]() Jun. 18, 2012 09:30 AM EDT Reads: 1,521 |
- Cloud Expo New York: Why PostgreSQL is the Database for the Cloud
- Cloud Expo New York Speaker Profile: Dave Asprey – Trend Micro
- Cloud Expo New York Speaker Profile: Jill T. Singer – NRO
- Cloud Expo New York Speaker Profile: Greg O'Connor – AppZero
- Cloud Expo New York Speaker Profile: Dave Linthicum – Blue Mountain Labs
- iPad3 vs Windows 8 - and the Winner Is...Cloud
- Cloud Expo New York Speaker Profile: Mårten Mickos – Eucalyptus Systems
- Cloud Expo New York Speaker Profile: George Gerchow – VMware
- Cloud Expo New York Speaker Profile: James Weir – UShareSoft
- Cloud Expo New York Speaker Profile: Bernard Golden – HyperStratus
- Gartner Hype Cycle 2011 - Emerging Technologies
- Cloud Expo New York: The Java EE 7 Platform - Developing for the Cloud
- Cloud Expo New York: Why PostgreSQL is the Database for the Cloud
- Cloud Expo New York Speaker Profile: Dave Asprey – Trend Micro
- Cloud Expo New York Speaker Profile: Jill T. Singer – NRO
- Cisco Unveils Visual Collaboration Solutions in the Post-PC Era, Extending the Reach of TelePresence With New Mobile-to-Immersive Offerings
- The Business Value of Cloud Computing
- Cloud Expo New York Speaker Profile: Greg O'Connor – AppZero
- Cloud Expo New York Speaker Profile: Dave Linthicum – Blue Mountain Labs
- iPad3 vs Windows 8 - and the Winner Is...Cloud
- Cloud Expo New York Speaker Profile: Mårten Mickos – Eucalyptus Systems
- Box Brings New Mobile and Social Capabilities to the Post-PC Era Enterprise
- Cloud Expo New York Speaker Profile: George Gerchow – VMware
- Cloud Expo New York Speaker Profile: James Weir – UShareSoft
- What is Cloud Computing?
- The Top 150 Players in Cloud Computing
- Six Benefits of Cloud Computing
- Virtualization Conference Keynote Webcast Live on SYS-CON.TV
- What's the Difference Between Cloud Computing and SaaS?
- Twenty-One Experts Define Cloud Computing
- GDS International: Global Warming Scam?
- The Top 250 Players in the Cloud Computing Ecosystem
- The Future of Cloud Computing
- A Brief History of Cloud Computing: Is the Cloud There Yet?
- Cloud Expo Europe 2009 in Prague: Themes & Topics
- SOA 2 Point Oh No!