By Gilad Parann-Nissany | Article Rating: |
|
November 1, 2012 01:31 PM EDT | Reads: |
509 |

(Originally posted by Lori Macvittie on rishidot.com)
Porticor, which earlier this year unveiled its split-key encryption technology for securing cloud data has taken the next step in its quest to assure users of the security of data in the cloud. In addition to adding VMware private cloud to its portfolio of supported environments (previously it supported only Amazon environments) it announced that it has introduced homomorphic encryption into the equation, which further secures one of the least often (and yet most important) aspects of cryptography – the security of cryptographic keys.
Where split-key technology assured the security of data by only allowing the full (and secret) key to be derived algorithmically from the two halves of the keys, homomorphic encryption ensures that the actual keys are no longer stored anywhere. Joining the keys is accomplished algorithmically and produces an encrypted symmetric key that is specific to a single resource, such as a disk volume or S3 object.
Porticor can secure a fairly impressive list of data objects, including:
- EBS
- VMDK
- MySQL
- Oracle
- SQL Server
- MongoDB
- Cassandra
- Linux, Unix (NFS)
- Windows (CIFS)
- AWS S3
The split-key technology is used when data is stored, and homomorphic techniques are used when data is accessed. Keys are always encrypted in the cloud, and control is maintained by the customer – not the key management or cloud service provider.
The addition of partially homomorphic encryption techniques allows for two very important security features to its portfolio of cloud encryption services:
1. The master key is never exposed, making it nigh unto impossible to steal
2. A compromise involving one object does not afford attackers access to other objects as each is secured using its own unique encrypted symmetric key
This second benefit is important, particularly as access to systems is often accomplished via a breach onto a single, internal system. Gaining access to or control over one system in a larger network has been a primary means of gaining a foothold “inside” as a means to further access the intended target, often data stores. The 2012 DATA BREACH INVESTIGATIONS REPORT noted that “94% of all data compromised involved servers.” The 18% increase in this statistic over the previous years’ findings make the security of individual systems – not just from outsider agents but inside agents as well – a significant contributor to data breaches and one in need of serious attention.
While new to the security scene and relatively untested as to its ability to withstand the rigorous attention and zealous attempts to crack as other cryptographic algorithms and techniques, Porticor offers the analysis and proof of its homomorphic techniques via Dr. Alon Rosen, a cryptography expert from the School of Computer Science at the Herzliya Interdisciplnary Center.
Regardless, the problems Porticor is attempting to address are real. Key management in the cloud is too often overlooked and storing full keys anywhere – even on-premise in the data center – can be a breach waiting to happen. By splitting key management responsibility but assigning control to the customer, Porticor provides a higher level of trust over traditional techniques in the overarching cryptographic framework required to securely store and manage data stored in public cloud computing environments.
The post HOMOMORPHIC ENCRYPTION FINDS A HOME IN THE CLOUD appeared first on Porticor Cloud Security.
Read the original blog entry...
Published November 1, 2012 Reads 509
Copyright © 2012 SYS-CON Media, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
More Stories By Gilad Parann-Nissany
Gilad Parann-Nissany, Founder and CEO at Porticor is a pioneer of Cloud Computing. He has built SaaS Clouds for medium and small enterprises at SAP (CTO Small Business); contributing to several SAP products and reaching more than 8 million users. Recently he has created a consumer Cloud at G.ho.st - a cloud operating system that delighted hundreds of thousands of users while providing browser-based and mobile access to data, people and a variety of cloud-based applications. He is now CEO of Porticor, a leader in Virtual Privacy and Cloud Security.
- Cloud People: A Who's Who of Cloud Computing
- Examining the True Cost of Big Data
- Here Comes Rackspace & Amazon’s Latest Rival
- Is Hondo AMD’s John Wayne?
- The Disruptor Framework: A Concurrency Framework for Java
- 11th Cloud Expo: A–Z of Big Data & Cloud Computing Topics
- Big Data Analytics: Thinking Outside of Hadoop
- Cloud Expo Silicon Valley: Big Data Is at the Heart of Cloud Computing
- Research and Markets: Hadoop & Big Data Market [Hardware, Software, Services, Hadoop-as-a-Service] - Trends, Geographical Analysis & Worldwide Market Forecasts (2012 - 2017)
- Configuring JMX in WebSphere 8.5
- A Big Data Infographic
- Oracle Revenues Light on Dim Sun; Firm Going IaaS
- Cloud People: A Who's Who of Cloud Computing
- Big Data: The ‘Perfect Storm’ Syndrome
- Examining the True Cost of Big Data
- Rapid7 Nexpose Introduces IPv6 Discovery and Scanning Capabilities, and Reduces Signal-to-Noise Ratio for Vulnerability Management, Enabling Security Professionals to Focus on Highest Priority Issues
- Here Comes Rackspace & Amazon’s Latest Rival
- Is Hondo AMD’s John Wayne?
- The Disruptor Framework: A Concurrency Framework for Java
- Java Architect Certification Preparation Training Lab Review
- The Rebirth of SOA on the Wings of SaaS and Cloud Computing
- EMC Reportedly Looking for Security (Acquisitions)
- Cloud Computing Strategies to Fast Track Revenue Generation
- The Age of Big Data: How to Gain Competitive Advantage
- The Top 250 Players in the Cloud Computing Ecosystem
- Web Services Using ColdFusion and Apache CXF
- Cloud People: A Who's Who of Cloud Computing
- Red Hat Named "Platinum Sponsor" of Virtualization Conference & Expo
- Eclipse "Pollinate" Project to Integrate with Apache Beehive
- Cloud Expo New York Call for Papers Now Open
- An Introduction to Ant
- Apache's Tomcat 5.5 is First Release Ever to Use Eclipse JDT Java Compiler
- Beehive Code Now Available in Apache
- Cloud Expo 2011 East To Attract 10,000 Delegates and 200 Exhibitors
- 4th International Cloud Computing Conference & Expo Starts Today
- "Beehive" Now Officially an Open Source Project: Apache Beehive