Welcome!

@CloudExpo Authors: Elizabeth White, Liz McMillan, Pat Romanski, Nate Vickery, William Schmarzo

Related Topics: @CloudExpo

@CloudExpo: Blog Feed Post

Encrypted Data in the Cloud?

With cloud computing there’s no longer a question about whether you should encrypt data

Encrypted Data in the Cloud? Be Sure to Control Your Own Keys

With cloud computing there’s no longer a question about whether you should encrypt data. That’s a given. The question today is, who should manage and control the encryption keys?

Whether talking to an infrastructure provider like Amazon or Microsoft, or a SaaS provider, it’s imperative to have the discussion about key control. The topic is more relevant than ever as more companies move regulated data into the cloud and as concerns about data privacy grow.

Protecting regulated data is top-of-mind in the U.S. where regulations such as PCI and HIPAA dictate that third parties not be able to access an organization’s sensitive data. Even if the data is strongly encrypted, it’s a compliance compromise if a cloud service provider has access to a full key that can decrypt the information without the data owner’s knowledge or permission.

European countries, especially Germany and France, are more concerned with data privacy. They are troubled by the fact that U.S.-based cloud vendors can be subpoenaed by the U.S. government to provide access to specific information, even if it resides outside the United States. Last April, Microsoft was ordered to hand over a customer’s emails to U.S. authorities, even though the data was held in a data center in Ireland. If Microsoft also held the data’s encryption key, the vendor could be compelled to provide that to authorities as well.

When it comes to processing and storing data in the cloud, organizations need to control their own encryption keys. What’s more, this ownership must be established before contracting for a cloud application or platform.

One key management and encryption company, Porticor, has an interesting way to address these issues. When we first introduced you to Porticor as a startup company in 2012, we mentioned the company uses a split-key approach to key management (see New key technology simplifies data encryption in the cloud). This approach has gained a lot of traction in the past two years, with a significant partnership with HP validating the notion of a “safe deposit box” for encryption keys that puts the customer in control.

Porticor provides both encryption schemes and key management technology, but it is the latter that is the distinct service offering. Porticor’s Virtual Private Data (VPD) solution is a cloud-based virtual appliance. The encryption engine and the key management function are software based and hosted in the cloud, allowing the solution to become part of the cloud infrastructure for platforms (e.g., AWS, VMware, HP Cloud Services, etc.) and for SaaS offerings.

According to Porticor CEO Gilad Parann-Nissany, the company has two customer segments. One is the end user organization that is deploying its applications on AWS or a similar cloud infrastructure. The other is SaaS providers who want to offer their customers a range of encryption schemes and, most importantly, the ability for those end customers to control their own keys.

In developing its Virtual Key Management Service, Porticor followed the principle of a bank safe deposit box. When data in the cloud is encrypted, the key is split such that Porticor holds one part of the key and the customer holds the other—the master key. As with a safe deposit box, the customer can’t decrypt the data without the key held by Porticor, and Porticor can’t decrypt the data without access to the customer’s master key. The keys must pair to provide access to the encrypted data, thus putting the user in control of the data. To further enhance security, the keys themselves are encrypted by the customer’s master key.

This solution has been designed to basically snap into cloud infrastructures, so it is apparently possible to bring up secure encrypted disks in a matter of minutes and entire database systems in a matter of hours. Porticor makes extensive use of APIs and offers RESTful APIs in order to integrate with cloud systems and applications.

In addition, Porticor’s solution can work on multiple levels. For example, customers can encrypt a complete database or a complete file store, and at the same time they can get granular in order to encrypt a single field of an application. Porticor’s customers often use these capabilities in tandem to address a specific need. This multi-level capability is especially important for SaaS providers that want to enable users to encrypt, say, a field containing a credit card number, but not necessarily the entire database. Moreover, different encryption schemes can be applied to each element that is being encrypted; for example, order-preserving encryption will be applied to the ZIP code field.

Porticor’s encryption and key management approach received quite a boost when HP selected the vendor to partner with for its own cloud-based Atalla security solution. Porticor’s technology has been integrated into the HP stack to provide secure cloud encryption. An HP cloud encryption customer can now automatically store their part of the encryption key – the master key – directly into a FIPS Level II compliant hardware security module that is part of the Atalla security system.

The imperative for encryption for data in the cloud grows stronger every day—for security, for compliance, for privacy, and for peace of mind. Organizations that are putting their data in the cloud need options in which they control the encryption keys. Porticor’s cloud-based Virtual Private Data system addresses those needs at the infrastructure level to reduce complexity while providing strong security.

The post Encrypted data in the cloud? Be sure to control your own keys appeared first on Porticor Cloud Security.

More Stories By Gilad Parann-Nissany

Gilad Parann-Nissany, Founder and CEO at Porticor is a pioneer of Cloud Computing. He has built SaaS Clouds for medium and small enterprises at SAP (CTO Small Business); contributing to several SAP products and reaching more than 8 million users. Recently he has created a consumer Cloud at G.ho.st - a cloud operating system that delighted hundreds of thousands of users while providing browser-based and mobile access to data, people and a variety of cloud-based applications. He is now CEO of Porticor, a leader in Virtual Privacy and Cloud Security.

@CloudExpo Stories
The past few years have brought a sea change in the way applications are architected, developed, and consumed—increasing both the complexity of testing and the business impact of software failures. How can software testing professionals keep pace with modern application delivery, given the trends that impact both architectures (cloud, microservices, and APIs) and processes (DevOps, agile, and continuous delivery)? This is where continuous testing comes in. D
Modern software design has fundamentally changed how we manage applications, causing many to turn to containers as the new virtual machine for resource management. As container adoption grows beyond stateless applications to stateful workloads, the need for persistent storage is foundational - something customers routinely cite as a top pain point. In his session at @DevOpsSummit at 21st Cloud Expo, Bill Borsari, Head of Systems Engineering at Datera, explored how organizations can reap the bene...
In a recent survey, Sumo Logic surveyed 1,500 customers who employ cloud services such as Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP). According to the survey, a quarter of the respondents have already deployed Docker containers and nearly as many (23 percent) are employing the AWS Lambda serverless computing framework. It’s clear: serverless is here to stay. The adoption does come with some needed changes, within both application development and operations. Tha...
"I focus on what we are calling CAST Highlight, which is our SaaS application portfolio analysis tool. It is an extremely lightweight tool that can integrate with pretty much any build process right now," explained Andrew Siegmund, Application Migration Specialist for CAST, in this SYS-CON.tv interview at 21st Cloud Expo, held Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA.
Digital transformation is about embracing digital technologies into a company's culture to better connect with its customers, automate processes, create better tools, enter new markets, etc. Such a transformation requires continuous orchestration across teams and an environment based on open collaboration and daily experiments. In his session at 21st Cloud Expo, Alex Casalboni, Technical (Cloud) Evangelist at Cloud Academy, explored and discussed the most urgent unsolved challenges to achieve f...
With tough new regulations coming to Europe on data privacy in May 2018, Calligo will explain why in reality the effect is global and transforms how you consider critical data. EU GDPR fundamentally rewrites the rules for cloud, Big Data and IoT. In his session at 21st Cloud Expo, Adam Ryan, Vice President and General Manager EMEA at Calligo, examined the regulations and provided insight on how it affects technology, challenges the established rules and will usher in new levels of diligence arou...
To get the most out of their data, successful companies are not focusing on queries and data lakes, they are actively integrating analytics into their operations with a data-first application development approach. Real-time adjustments to improve revenues, reduce costs, or mitigate risk rely on applications that minimize latency on a variety of data sources. In his session at @BigDataExpo, Jack Norris, Senior Vice President, Data and Applications at MapR Technologies, reviewed best practices t...
In his general session at 21st Cloud Expo, Greg Dumas, Calligo’s Vice President and G.M. of US operations, discussed the new Global Data Protection Regulation and how Calligo can help business stay compliant in digitally globalized world. Greg Dumas is Calligo's Vice President and G.M. of US operations. Calligo is an established service provider that provides an innovative platform for trusted cloud solutions. Calligo’s customers are typically most concerned about GDPR compliance, application p...
Mobile device usage has increased exponentially during the past several years, as consumers rely on handhelds for everything from news and weather to banking and purchases. What can we expect in the next few years? The way in which we interact with our devices will fundamentally change, as businesses leverage Artificial Intelligence. We already see this taking shape as businesses leverage AI for cost savings and customer responsiveness. This trend will continue, as AI is used for more sophistica...
Smart cities have the potential to change our lives at so many levels for citizens: less pollution, reduced parking obstacles, better health, education and more energy savings. Real-time data streaming and the Internet of Things (IoT) possess the power to turn this vision into a reality. However, most organizations today are building their data infrastructure to focus solely on addressing immediate business needs vs. a platform capable of quickly adapting emerging technologies to address future ...
In his Opening Keynote at 21st Cloud Expo, John Considine, General Manager of IBM Cloud Infrastructure, led attendees through the exciting evolution of the cloud. He looked at this major disruption from the perspective of technology, business models, and what this means for enterprises of all sizes. John Considine is General Manager of Cloud Infrastructure Services at IBM. In that role he is responsible for leading IBM’s public cloud infrastructure including strategy, development, and offering m...
"Evatronix provides design services to companies that need to integrate the IoT technology in their products but they don't necessarily have the expertise, knowledge and design team to do so," explained Adam Morawiec, VP of Business Development at Evatronix, in this SYS-CON.tv interview at @ThingsExpo, held Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA.
In his session at 21st Cloud Expo, Raju Shreewastava, founder of Big Data Trunk, provided a fun and simple way to introduce Machine Leaning to anyone and everyone. He solved a machine learning problem and demonstrated an easy way to be able to do machine learning without even coding. Raju Shreewastava is the founder of Big Data Trunk (www.BigDataTrunk.com), a Big Data Training and consulting firm with offices in the United States. He previously led the data warehouse/business intelligence and B...
Most technology leaders, contemporary and from the hardware era, are reshaping their businesses to do software. They hope to capture value from emerging technologies such as IoT, SDN, and AI. Ultimately, irrespective of the vertical, it is about deriving value from independent software applications participating in an ecosystem as one comprehensive solution. In his session at @ThingsExpo, Kausik Sridhar, founder and CTO of Pulzze Systems, discussed how given the magnitude of today's application ...
The 22nd International Cloud Expo | 1st DXWorld Expo has announced that its Call for Papers is open. Cloud Expo | DXWorld Expo, to be held June 5-7, 2018, at the Javits Center in New York, NY, brings together Cloud Computing, Digital Transformation, Big Data, Internet of Things, DevOps, Machine Learning and WebRTC to one location. With cloud computing driving a higher percentage of enterprise IT budgets every year, it becomes increasingly important to plant your flag in this fast-expanding busin...
Nordstrom is transforming the way that they do business and the cloud is the key to enabling speed and hyper personalized customer experiences. In his session at 21st Cloud Expo, Ken Schow, VP of Engineering at Nordstrom, discussed some of the key learnings and common pitfalls of large enterprises moving to the cloud. This includes strategies around choosing a cloud provider(s), architecture, and lessons learned. In addition, he covered some of the best practices for structured team migration an...
The “Digital Era” is forcing us to engage with new methods to build, operate and maintain applications. This transformation also implies an evolution to more and more intelligent applications to better engage with the customers, while creating significant market differentiators. In both cases, the cloud has become a key enabler to embrace this digital revolution. So, moving to the cloud is no longer the question; the new questions are HOW and WHEN. To make this equation even more complex, most ...
As you move to the cloud, your network should be efficient, secure, and easy to manage. An enterprise adopting a hybrid or public cloud needs systems and tools that provide: Agility: ability to deliver applications and services faster, even in complex hybrid environments Easier manageability: enable reliable connectivity with complete oversight as the data center network evolves Greater efficiency: eliminate wasted effort while reducing errors and optimize asset utilization Security: imple...
The dynamic nature of the cloud means that change is a constant when it comes to modern cloud-based infrastructure. Delivering modern applications to end users, therefore, is a constantly shifting challenge. Delivery automation helps IT Ops teams ensure that apps are providing an optimal end user experience over hybrid-cloud and multi-cloud environments, no matter what the current state of the infrastructure is. To employ a delivery automation strategy that reflects your business rules, making r...
SYS-CON Events announced today that Synametrics Technologies will exhibit at SYS-CON's 22nd International Cloud Expo®, which will take place on June 5-7, 2018, at the Javits Center in New York, NY. Synametrics Technologies is a privately held company based in Plainsboro, New Jersey that has been providing solutions for the developer community since 1997. Based on the success of its initial product offerings such as WinSQL, Xeams, SynaMan and Syncrify, Synametrics continues to create and hone in...