Click here to close now.


@CloudExpo Authors: Elizabeth White, Liz McMillan, Pat Romanski, AppDynamics Blog, Gregor Petri

Blog Feed Post

Interview with Gilad Parann-Nissany of Porticor

 logo virtual Interview with Gilad Parann Nissany of Porticor



(Originally posted by Virtual Strategy Magazine here)

VSM: It’s been a while since we’ve spoken, not since Q1 around Porticor’s company and initial product launch. What has the company been up to?

GPN: Thank you for asking. Porticor has been growing on the customer and partner front, and working hard on product innovations, which is why we are talking today. Since our launch we have signed key partnerships, including with Amazon Web Services, VMware, and HP. Customers and the industry continue to validate our solution, and Porticor this year has won some significant industry honors, including being named as the Most Innovative Company of the Year by the Stevie Awards Program.

VSM: And you have a new major release with the Porticor Virtual Private Data security solution? Can you tell us about it?

GPN: Yes, we have extended the functionality of the Porticor Virtual Data system to now protect and keep confidential the encryption keys while they are in use, further protecting data in virtual and cloud environments. As a result, we are helping to assure organizations that they can trust their virtual and cloud data to be safe.

VSM: How is this different than what Porticor previously released to protect organizations’ private data stored in virtual and cloud environments?

GPN: Porticor’s new release protects the encryption keys while in use, and previously the solution protected only data at rest. Specifically, the earlier solution introduced the industry to our patented split-key encryption technology, which protects data encryption keys while they are stored (at rest) by keeping the keys safely in the hands of the customer, not the security vendor or cloud service provider. We have now added the additional security assurance to protect the encryption keys even while in use.

VSM: What are the new use cases that can now be achieved securely in the cloud, and why?

GPN: With this new solution, there are many new private cloud and public cloud use case applications that open up. For example, a virtual bank service that must segregate and encrypt users’ data can now fully benefit from a virtual environment using this solution. Using Porticor, the ISV can now provide a secured virtual bank service while using a public cloud infrastructure. The ISV does not trust anyone but itself with the encryption keys and provides trust and control to its end users, while knowing the most sensitive data – its encryption keys – are secured while at rest and while in use.

VSM: Aren’t there current solutions already available addressing these issues?

GPN: No solution available keeps data encryption keys securely in the hands of the customer; and specific to Porticor’s new release, no solution available protects encryption keys while they are in use to fully secure virtual and cloud data. This is because of an innovation Porticor has rolled out which is the industry’s first commercial use of a highly technical mathematical algorithm called partially-homomorphic encryption technology.

VSM: Can you describe homomorphic technology, and how it’s used to protect virtual and cloud data?

GPN: Homomorphic encryption is a technique that enables mathematical operations to be performed on encrypted data. Porticor’s patent-pending technology implements partially homomorphic encryption techniques for combining and splitting encryption keys. It enables the Porticor VPD system to give the application access to the virtual and cloud data store without exposing the keys in an unencrypted state. This also ensures that if a master key is stolen, it can still never be used to break the entire virtual and cloud data store.

VSM: What is different about your solution? Why is this important?

GPN: Porticor’s system is the industry’s first data protection service delivering true trust to virtual and cloud environments by ensuring customer encryption keys are never exposed, either at rest (stored) or in use. Porticor is also the only data protection system that delivers data security across virtual disks, databases, distributed storage and file systems. This is important because Porticor solves the remaining obstacle to trust in the cloud – protecting the entire data store while keeping the encryption keys secure at all times.

VSM: What are some of the other benefits of this new technology?

GPN: With a lack of trust in the cloud, organizations are inhibited from fully leveraging the well-known business benefits the cloud has to offer. Now, organizations can benefit from the latest in cloud encryption technology from Porticor to leverage the benefits of the cloud, all with full confidence that their data will remain confidential, while maintaining compliance and the highest levels of cloud security. Being fully secure, Porticor also helps organizations meet compliance requirements for regulations such as SOX, HIPAA, PCI DSS, GLBA, EU Data Protection and the US Patriot Act, in these virtual and cloud environments.

VSM: What can we expect to see from Porticor in 2013?

GPN: Porticor’s unique technologies are essentially a “root of trust” for private and public cloud users. During 2013 we expect to continue strong growth with customers in industries like Finance, Health, Insurance, Media and Manufacturing. This allows them to adopt private and public clouds while being defended against a significant variety of threats.

VSM: It’s been great chatting with you today. Anything else you’d like to share about the state of virtualized data protection or the new Porticor solution?

GPN: This is the first commercial application of this type of homomorphic key encryption technique, and I know that many are unfamiliar with it. Porticor’s approach is unique in that it is open to rigorous mathematical proof and cryptographic analysis under explicit and well defined assumptions. For example, Dr. Alon Rosen, a Cryptography expert from the School of Computer Science at the Herzliya Interdisciplnary Center, has independently performed rigorous analysis, resulting in a proof that the approach and its associated protocols “securely realize the intended functionality.”

The post Interview with Gilad Parann-Nissany of Porticor appeared first on Porticor Cloud Security.

Read the original blog entry...

More Stories By Gilad Parann-Nissany

Gilad Parann-Nissany, Founder and CEO at Porticor is a pioneer of Cloud Computing. He has built SaaS Clouds for medium and small enterprises at SAP (CTO Small Business); contributing to several SAP products and reaching more than 8 million users. Recently he has created a consumer Cloud at - a cloud operating system that delighted hundreds of thousands of users while providing browser-based and mobile access to data, people and a variety of cloud-based applications. He is now CEO of Porticor, a leader in Virtual Privacy and Cloud Security.

@CloudExpo Stories
The buzz continues for cloud, data analytics and the Internet of Things (IoT) and their collective impact across all industries. But a new conversation is emerging - how do companies use industry disruption and technology enablers to lead in markets undergoing change, uncertainty and ambiguity? Organizations of all sizes need to evolve and transform, often under massive pressure, as industry lines blur and merge and traditional business models are assaulted and turned upside down. In this new da...
Containers are revolutionizing the way we deploy and maintain our infrastructures, but monitoring and troubleshooting in a containerized environment can still be painful and impractical. Understanding even basic resource usage is difficult - let alone tracking network connections or malicious activity. In his session at DevOps Summit, Gianluca Borello, Sr. Software Engineer at Sysdig, will cover the current state of the art for container monitoring and visibility, including pros / cons and li...
The Internet of Things (IoT) is growing rapidly by extending current technologies, products and networks. By 2020, Cisco estimates there will be 50 billion connected devices. Gartner has forecast revenues of over $300 billion, just to IoT suppliers. Now is the time to figure out how you’ll make money – not just create innovative products. With hundreds of new products and companies jumping into the IoT fray every month, there’s no shortage of innovation. Despite this, McKinsey/VisionMobile data...
As-a-service models offer huge opportunities, but also complicate security. It may seem that the easiest way to migrate to a new architectural model is to let others, experts in their field, do the work. This has given rise to many as-a-service models throughout the industry and across the entire technology stack, from software to infrastructure. While this has unlocked huge opportunities to accelerate the deployment of new capabilities or increase economic efficiencies within an organization, i...
There are so many tools and techniques for data analytics that even for a data scientist the choices, possible systems, and even the types of data can be daunting. In his session at @ThingsExpo, Chris Harrold, Global CTO for Big Data Solutions for EMC Corporation, will show how to perform a simple, but meaningful analysis of social sentiment data using freely available tools that take only minutes to download and install. Participants will get the download information, scripts, and complete en...
Containers are changing the security landscape for software development and deployment. As with any security solutions, security approaches that work for developers, operations personnel and security professionals is a requirement. In his session at @DevOpsSummit, Kevin Gilpin, CTO and Co-Founder of Conjur, will discuss various security considerations for container-based infrastructure and related DevOps workflows.
Manufacturing has widely adopted standardized and automated processes to create designs, build them, and maintain them through their life cycle. However, many modern manufacturing systems go beyond mechanized workflows to introduce empowered workers, flexible collaboration, and rapid iteration. Such behaviors also characterize open source software development and are at the heart of DevOps culture, processes, and tooling.
Between the compelling mockups and specs produced by analysts, and resulting applications built by developers, there exists a gulf where projects fail, costs spiral, and applications disappoint. Methodologies like Agile attempt to address this with intensified communication, with partial success but many limitations. In his session at DevOps Summit, Charles Kendrick, CTO and Chief Architect at Isomorphic Software, will present a revolutionary model enabled by new technologies. Learn how busine...
There are many considerations when moving applications from on-premise to cloud. It is critical to understand the benefits and also challenges of this migration. A successful migration will result in lower Total Cost of Ownership, yet offer the same or higher level of robustness. Migration to cloud shifts computing resources from your data center, which can yield significant advantages provided that the cloud vendor an offer enterprise-grade quality for your application.
IT data is typically silo'd by the various tools in place. Unifying all the log, metric and event data in one analytics platform stops finger pointing and provides the end-to-end correlation. Logs, metrics and custom event data can be joined to tell the holistic story of your software and operations. For example, users can correlate code deploys to system performance to application error codes.
The web app is agile. The REST API is agile. The testing and planning are agile. But alas, data infrastructures certainly are not. Once an application matures, changing the shape or indexing scheme of data often forces at best a top down planning exercise and at worst includes schema changes that force downtime. The time has come for a new approach that fundamentally advances the agility of distributed data infrastructures. Come learn about a new solution to the problems faced by software organ...
Internet of Things (IoT) will be a hybrid ecosystem of diverse devices and sensors collaborating with operational and enterprise systems to create the next big application. In their session at @ThingsExpo, Bramh Gupta, founder and CEO of, and Fred Yatzeck, principal architect leading product development at, discussed how choosing the right middleware and integration strategy from the get-go will enable IoT solution developers to adapt and grow with the industry, while at th...
The last decade was about virtual machines, but the next one is about containers. Containers enable a service to run on any host at any time. Traditional tools are starting to show cracks because they were not designed for this level of application portability. Now is the time to look at new ways to deploy and manage applications at scale. In his session at @DevOpsSummit, Brian “Redbeard” Harrington, a principal architect at CoreOS, will examine how CoreOS helps teams run in production. Attende...
“All our customers are looking at the cloud ecosystem as an important part of their overall product strategy. Some see it evolve as a multi-cloud / hybrid cloud strategy, while others are embracing all forms of cloud offerings like PaaS, IaaS and SaaS in their solutions,” noted Suhas Joshi, Vice President – Technology, at Harbinger Group, in this exclusive Q&A with Cloud Expo Conference Chair Roger Strukhoff.
Can call centers hang up the phones for good? Intuitive Solutions did. WebRTC enabled this contact center provider to eliminate antiquated telephony and desktop phone infrastructure with a pure web-based solution, allowing them to expand beyond brick-and-mortar confines to a home-based agent model. It also ensured scalability and better service for customers, including MUY! Companies, one of the country's largest franchise restaurant companies with 232 Pizza Hut locations. This is one example of...
SYS-CON Events announced today that VividCortex, the monitoring solution for the modern data system, will exhibit at the 17th International Cloud Expo®, which will take place on November 3–5, 2015, at the Santa Clara Convention Center in Santa Clara, CA. The database is the heart of most applications, but it’s also the part that’s hardest to scale, monitor, and optimize even as it’s growing 50% year over year. VividCortex is the first unified suite of database monitoring tools specifically desi...
Cloud computing delivers on-demand resources that provide businesses with flexibility and cost-savings. The challenge in moving workloads to the cloud has been the cost and complexity of ensuring the initial and ongoing security and regulatory (PCI, HIPAA, FFIEC) compliance across private and public clouds. Manual security compliance is slow, prone to human error, and represents over 50% of the cost of managing cloud applications. Determining how to automate cloud security compliance is critical...
Saviynt Inc. has announced the availability of the next release of Saviynt for AWS. The comprehensive security and compliance solution provides a Command-and-Control center to gain visibility into risks in AWS, enforce real-time protection of critical workloads as well as data and automate access life-cycle governance. The solution enables AWS customers to meet their compliance mandates such as ITAR, SOX, PCI, etc. by including an extensive risk and controls library to detect known threats and b...
You have your devices and your data, but what about the rest of your Internet of Things story? Two popular classes of technologies that nicely handle the Big Data analytics for Internet of Things are Apache Hadoop and NoSQL. Hadoop is designed for parallelizing analytical work across many servers and is ideal for the massive data volumes you create with IoT devices. NoSQL databases such as Apache HBase are ideal for storing and retrieving IoT data as “time series data.”
Clearly the way forward is to move to cloud be it bare metal, VMs or containers. One aspect of the current public clouds that is slowing this cloud migration is cloud lock-in. Every cloud vendor is trying to make it very difficult to move out once a customer has chosen their cloud. In his session at 17th Cloud Expo, Naveen Nimmu, CEO of Clouber, Inc., will advocate that making the inter-cloud migration as simple as changing airlines would help the entire industry to quickly adopt the cloud wit...