The Wayback Machine - https://web.archive.org/web/20120623025351/http://cloudcomputing.sys-con.com:80/node/2298507

Welcome!

Cloud Expo Authors: David Smith, Srinivasan Sundara Rajan, App Man, Maureen O'Gara, Elizabeth White

Related Topics: Cloud Expo, Virtualization, Security

Cloud Expo: Blog Feed Post

Cloud Encryption Best Practices

Cloud security questions to ask your cloud provider

Cloud encryption keeps coming up as one of the hottest topics for enterprises migrating to the cloud. IT departments are constantly pushed to cut costs and utilize compute resources more efficiently, hence cloud computing is the natural evolution, yet at the same enterprises cannot compromise on cloud security, and cloud encryption should be considered high on the list as it segregates and “hides” your data from other virtual entities hosted on the same physical cloud infrastructure.

What’s my cloud provider’s encryption approach?
Cloud data security and cloud encryption comes in many forms and shapes. While some cloud providers will provide the encryption service, some will provide a “shopping list” of cloud encryption companies, and others will provide both. But which one is best for your needs?

A good place to start would be to define what your needs are J. Many enterprises tend to assume that data encryption automatically guarantees data confidentiality but that’s not the case.  Data confidentiality is achieved only if you, the enterprise, maintain control over both the encryption process as well as the encryption keys.

If anyone else but your authorized team controls the encryption process, or manages the encryption keys for you – data confidentiality is not achieved. If cloud security is a regulatory requirement, or if intellectual property should be protected, enterprises should consider deploying and managing encryption by themselves.

Unfortunately this not an easy task to accomplish. While there are many cloud encryption technologies out there, most will answer only some of the requirements by working only with specific database kinds, or supporting a limited range of your operating systems.  The ideal cloud encryption solution is the one supporting all your operating systems and databases types.

What about the encryption keys?
Now that you’ve figured out your encryption strategy and narrowed down your search to a limited number of encryption solutions who can address your cloud security requirements, there’s still the critical question of who’s responsible for my encryption keys management?

As mentioned above, if your enterprise requires data confidentiality, it is up to you to manage the encryption keys. Until recently, there were two available options; Consume key management as a service (which is equivalent in essence to trusting another entity with your encryption keys); or deploying a key management server back in your data center and integrate it with your cloud encryption software of choice,  a fact which frustrates many IT managers since it eliminates many of the cloud benefits such as scalability and flexibility and burdens them with another on premise server to manage while all they wanted to do to begin with is to migrate to the cloud.

Fortunately, new and emerging technologies have been recently announced to resolve the cloud key management pain. One example is the split-key encryption technology (read more about it here or download the whitepaper) which for the first time enables enterprises migrating to the cloud to use a key management as a service without scarifying trust, by splitting an encryption key into two parts. The first part – the master key – is common to all data objects in the application. It remains the sole possession of the application owner and is unknown to the cloud provider or the encryption vendor; while the second part is different for each data object and is stored by the Key Management Service.

Ariel Dan is co-founder of Porticor Cloud Security

Read the original blog entry...

More Stories By Gilad Parann-Nissany

Gilad Parann-Nissany, Founder and CEO at Porticor is a pioneer of Cloud Computing. He has built SaaS Clouds for medium and small enterprises at SAP (CTO Small Business); contributing to several SAP products including BusinessByDesign and reaching more than 8 million users. Recently he has created a consumer Cloud at G.ho.st - a cloud operating system that delighted hundreds of thousands of users while providing browser-based and mobile access to data, people and a variety of cloud-based applications. He is now CEO of Porticor, a leader in Virtual Privacy and Cloud Security.

Cloud Expo Breaking News
SYS-CON Events announced today that ServerCentral, Chicago’s leading provider of colocation, cloud, network connectivity, and managed services, will exhibit at SYS-CON's 11th International Cloud Expo, which will take place on November 5–8, 2012, at the Santa Clara Convention Center in Santa Clara, CA. ServerCentral provides highly reliable IT infrastructure in secure facilities across North America, Europe, and Asia. Delivering industry leading service levels on colocation, cloud, IP connectivi...
SYS-CON Events announced today that Net Optics, Inc., the industry’s leading provider of intelligent access and monitoring architecture, will exhibit at SYS-CON's 11th International Cloud Expo, which will take place on November 5–8, 2012, at the Santa Clara Convention Center in Santa Clara, CA. Net Optics is the leading provider of Intelligent Access and Monitoring Architecture solutions that deliver real-time IT visibility, monitoring and control. As a result, businesses achieve peak performan...
SYS-CON Events announced today that 1010data, Inc., a market leader in enabling the analysis, sharing and monetizing of Big Data, has been named “Silver Sponsor” of SYS-CON's 11th International Cloud Expo, which will take place on November 5–8, 2012, at the Santa Clara Convention Center in Santa Clara, CA. 1010data provides a unique, cloud-based platform that unifies Big Data and analytics. It is used by hundreds of the world’s largest retail, manufacturing, telecom, and financial services ente...
10th International Cloud Expo, held on June 11–14, 2012 at the Javits Center in New York City, featured four content-packed days with a rich array of sessions about the business and technical value of cloud computing led by exceptional speakers from every sector of the cloud computing ecosystem. The Cloud Expo series is the fastest-growing Enterprise IT event in the past 10 years, devoted to every aspect of delivering massively scalable enterprise IT as a service. We invite you to enjoy our ph...
“Big Data is not simply code for lots of information,” observed Victoria Kouyoumjian, Sr. Business and Technologies Strategist at Esri, in this exclusive Q&A; with Cloud Expo Conference Chair Jeremy Geelan. “Instead,” Kouyoumjian noted, “Big Data refers to information in myriad different formats from varying sources – and many of these digital formats and streams haven’t existed until recently.” Cloud Computing Journal: Agree or disagree? – "While the IT savings aspect is compelling, the stronge...
“The definition of cloud and cloud services continues to evolve,” observed Robert Crespi, VP, CIO at Cervalis, in this exclusive Q&A; with Cloud Expo Conference Chair Jeremy Geelan. “As such it is difficult to predict the growth,” Crespi continued, “we see more and more customers migrating to a cloud model with virtualization as it core.” Cloud Computing Journal: Agree or disagree? – "While the IT savings aspect is compelling, the strongest benefit of cloud computing is how it enhances business ...
“Cloud computing represents a paradigm shift for IT, transforming computing power into a utility,” observed James Weir, CTO and Co-Founder of UShareSoft, in this exclusive Q&A; with Cloud Expo Conference Chair Jeremy Geelan. “While cloud adoption remains in the early stages,” Weir continued, “this shift means that the overall market will grow massively in the coming years.” Cloud Computing Journal: Agree or disagree? – "While the IT savings aspect is compelling, the strongest benefit of cloud co...
This year's Cloud Expo New York appeared to be double the size of last year. Not only were there more solution providers on the expo floor, there appeared to me quite a few additional sessions to attend. I felt even the session quality was better than last year, with more knowledge spread across various tracks, and it was obvious the expertise was well, more expert than before. There also appeared to be more attendees, and in greater diversity than the previous year. Of course, all of this impro...
“The productization of Big Data will be an interesting trend to track, and I think we'll start to see some significant investment in this area over the coming months,” noted Scott Sneddon, Vyatta’s Director of Cloud Solutions, in this exclusive Q&A; with Cloud Expo Conference Chair Jeremy Geelan. “We at Vyatta think this trend is exciting,” Sneddon continued, “because these kinds of new ventures will always need powerful and creative networking and security solutions.” Cloud Computing Journal: A...
SYS-CON Events announced today that Fortress ITX, a leading provider of network infrastructure services, has been named “Bronze Sponsor” of SYS-CON's 11th International Cloud Expo, which will take place on November 5–8, 2012, at the Santa Clara Convention Center in Santa Clara, CA. FortressITX is a Cloud Integrator serving the NY Metro area providing complete IT integration and unparalleled Hosted Exchange, Hosted PBX, Connectivity and Virtual Desktop Integration (VDI) services. FortressITX als...