| By Gilad Parann-Nissany | Article Rating: |
|
| November 1, 2012 01:31 PM EDT | Reads: |
1,976 |
(Originally posted by Lori Macvittie on rishidot.com)
Porticor, which earlier this year unveiled its split-key encryption technology for securing cloud data has taken the next step in its quest to assure users of the security of data in the cloud. In addition to adding VMware private cloud to its portfolio of supported environments (previously it supported only Amazon environments) it announced that it has introduced homomorphic encryption into the equation, which further secures one of the least often (and yet most important) aspects of cryptography – the security of cryptographic keys.
Where split-key technology assured the security of data by only allowing the full (and secret) key to be derived algorithmically from the two halves of the keys, homomorphic encryption ensures that the actual keys are no longer stored anywhere. Joining the keys is accomplished algorithmically and produces an encrypted symmetric key that is specific to a single resource, such as a disk volume or S3 object.
Porticor can secure a fairly impressive list of data objects, including:
- EBS
- VMDK
- MySQL
- Oracle
- SQL Server
- MongoDB
- Cassandra
- Linux, Unix (NFS)
- Windows (CIFS)
- AWS S3
The split-key technology is used when data is stored, and homomorphic techniques are used when data is accessed. Keys are always encrypted in the cloud, and control is maintained by the customer – not the key management or cloud service provider.
The addition of partially homomorphic encryption techniques allows for two very important security features to its portfolio of cloud encryption services:
1. The master key is never exposed, making it nigh unto impossible to steal
2. A compromise involving one object does not afford attackers access to other objects as each is secured using its own unique encrypted symmetric key
This second benefit is important, particularly as access to systems is often accomplished via a breach onto a single, internal system. Gaining access to or control over one system in a larger network has been a primary means of gaining a foothold “inside” as a means to further access the intended target, often data stores. The 2012 DATA BREACH INVESTIGATIONS REPORT noted that “94% of all data compromised involved servers.” The 18% increase in this statistic over the previous years’ findings make the security of individual systems – not just from outsider agents but inside agents as well – a significant contributor to data breaches and one in need of serious attention.
While new to the security scene and relatively untested as to its ability to withstand the rigorous attention and zealous attempts to crack as other cryptographic algorithms and techniques, Porticor offers the analysis and proof of its homomorphic techniques via Dr. Alon Rosen, a cryptography expert from the School of Computer Science at the Herzliya Interdisciplnary Center.
Regardless, the problems Porticor is attempting to address are real. Key management in the cloud is too often overlooked and storing full keys anywhere – even on-premise in the data center – can be a breach waiting to happen. By splitting key management responsibility but assigning control to the customer, Porticor provides a higher level of trust over traditional techniques in the overarching cryptographic framework required to securely store and manage data stored in public cloud computing environments.
The post HOMOMORPHIC ENCRYPTION FINDS A HOME IN THE CLOUD appeared first on Porticor Cloud Security.
Read the original blog entry...
Published November 1, 2012 Reads 1,976
Copyright © 2012 SYS-CON Media, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
More Stories By Gilad Parann-Nissany
Gilad Parann-Nissany, Founder and CEO at Porticor is a pioneer of Cloud Computing. He has built SaaS Clouds for medium and small enterprises at SAP (CTO Small Business); contributing to several SAP products and reaching more than 8 million users. Recently he has created a consumer Cloud at G.ho.st - a cloud operating system that delighted hundreds of thousands of users while providing browser-based and mobile access to data, people and a variety of cloud-based applications. He is now CEO of Porticor, a leader in Virtual Privacy and Cloud Security.
- Cloud People: A Who's Who of Cloud Computing
- How to Move Your Oracle Databases to Amazon EC2 Cloud
- Cloud Expo NY: Best Practices for Delivering Oracle Database as a Service
- Session Topics: 12th Cloud Expo / Cloud Expo New York
- Cloud Expo New York: Build Modern Business Applications
- Velocity Technology Solutions Introduces IBM Power Systems Universal Cloud Services at COMMON 2013
- Here Comes Oracle’s New Sparc Servers
- Cloud Expo NY: Fast-Track Your Transformation to Enterprise Private Cloud
- Cloud Business Solutions, Social Media, and Platform Systems of Engagement Market Shares, Strategies, and Forecasts, Worldwide, 2013 to 2019
- Oracle Buys Tekelec
- Cloud Expo New York: Ten Myths of Cloud Computing
- Research and Markets: Global Platform-As-A-Service Market Expected To Post Revenue of US$6.45 Billion in 2016 According To Latest Report
- Cloud People: A Who's Who of Cloud Computing
- Global Micro Servers Market (2013 - 2018), By Processor Type (Intel, Arm, Amd), Component (Hardware, Software, Operating System), Application (Media Storage, Data Centers, Analytics, Cloud Computing) & Geography (North America, Europe, Apac, Row)
- How to Move Your Oracle Databases to Amazon EC2 Cloud
- Cloud Expo NY: Best Practices for Delivering Oracle Database as a Service
- Session Topics: 12th Cloud Expo / Cloud Expo New York
- Cloud Expo New York: Build Modern Business Applications
- Red Hat Reinforces Java Commitment
- Five Steps Toward Achieving Better Compliance with Identity Analytics
- Velocity Technology Solutions Introduces IBM Power Systems Universal Cloud Services at COMMON 2013
- Here Comes Oracle’s New Sparc Servers
- Java Cryptography | Part 3
- Cavalry Rides into Oracle’s Java Suit
- AJAX World RIA Conference & Expo Kicks Off in New York City
- The Top 250 Players in the Cloud Computing Ecosystem
- Oracle SOA Suite
- A Review Of Oracle Application Server 10g
- An Introduction to Abbot
- Java Product Review — Oracle JDeveloper An IDE Worth a Second Look
- Cloud People: A Who's Who of Cloud Computing
- Red Hat Named "Platinum Sponsor" of Virtualization Conference & Expo
- Universal Middleware: What's Happening With OSGi and Why You Should Care
- Report From the Oracle/PeopleSoft Frontline: Alienating PeopleSoft
- Cloud Expo New York Call for Papers Now Open
- The Oracle-Sun Buddyfest: What's It All Mean?



























