Welcome!

Cloud Security Authors: Elizabeth White, Pat Romanski, Maria C. Horton, Liz McMillan, Ravi Rajamiyer

Related Topics: @CloudExpo, Cloud Security

@CloudExpo: News Item

Trusting Data in the Cloud Is About Losing a Key

The online storage and collaboration market has been hot

The online storage and collaboration market has been hot, with early market entrants Dropbox, Box.net and YouSendIt appearing to have taken the initial lead in providing individuals and businesses with the ability to easily store, share, and send large files between multiple parties.

In the spirit of secure collaboration, at this year's RSA event, Ftopia and GuardTime announced a partnership that hopes to shake up the market a bit by raising even higher the pressing question of one's ability to trust their precious data in the cloud. To answer this question, the Ftopia service is designed to allow businesses to securely collaborate by sharing their files anywhere they want over the Internet without having to rely on trust. Rather, they provide the service with built-in data integrity features that utilize mathematics as its form of proof.

Ftopia does cloud-based data collaboration and storage, and together with GuardTime, a cloud security company, signed a deal to offer the market a provably secure collaboration and storage service. Ftopia uses GuardTime's keyless signature technology to digitally sign the clients' data as it is stored in Ftopia rooms.

As described in the public announcement, GuardTime's Keyless Signature technology provides proof of signing authority, time of the signature, and lifelong integrity for data stored in the cloud and in transit between business collaborators. The signature never expires and its verification is based solely on mathematics, eliminating the need for secrets or keys and the unwieldy management associated with traditional PKI technologies that fail in the cloud.

During an interview with Ftopia CEO Philippe Honigman, I was able to ask him what prompted the creation of the partnership and his new release. "As more information moves to the cloud as the primary place of storage, concerns about trust and security are growing as well," he said. "Traditional, defensive security measures, such as intrusion detection, intrusion prevention, strict network access control policies, or even the tried and true anti-malware technologies, are not enough anymore. Business customers are more likely to entrust their information to a third party when they know for certain - more specifically, when they can prove - that their data has not been altered in any way."

After a quick run-through of the capabilities with Honigman, the workflow appears to remain simple and seemingly unchanged. There is no additional action for the users to take on either end of the file sharing transaction. Each file gets its own signature. The signature is a small file that is automatically created and saved alongside the signed file. If the user wants proof that the file in question has not changed since the exact point in time that it was uploaded, they simply collect the file and its signature and use the verification tool provided by GuardTime to perform the comparison. If the signature can be verified, the file is guaranteed to be the same exact file and can be confirmed that it is that exact file from the exact point in time for which it was signed. If the signature cannot be verified, then the file cannot be guaranteed to be the same.

"The solution is both simple and powerful," said Honigman. "On the surface, it would appear that all that GuardTime is providing us is the ability to timestamp or simply sign a file. But, because the signature is keyless, meaning nobody is forced to manage any keys or keep any secrets, the client can get undeniable proof that the file has not been tampered with, not even by Ftopia."

GuardTime CEO Mike Gault says, "We solved the problem of trust by removing the reliance on keys or secrets to prove that the data remains intact. This is accomplished through a series of concatenated SHA-256 hashes for each file that are used to create and destroy a Merkle tree of hashes every second since the beginning of Unix time, 1970."

According to Guardtime, the resulting root hash, referred to by the company as the "Integrity Code", is published monthly in publications such as the Financial Times. To verify the integrity of the data, all one needs is the published Integrity Code, the original file, and its corresponding signature file. With these three pieces, any organization can use the tools provided or, if they are really paranoid, they could do the reverse hash function mathematics to prove that the file remains intact. In short, GuardTime claims that there is no need to rely on any tool, or any third party to gain proof.

It will be interesting to keep an eye on Ftopia to see how their clients use this feature. It seems that the value becomes painfully apparent when an organization is required by law or regulation to provide proof that their data has remained intact - especially if their own integrity was being questioned. Hopefully this is not the case for most organizations. Which company would want to get all twisted up in court because they couldn't prove they weren't involved in a coverup? I feel safe going out on a limb to say none of them.

More Stories By Victor Cruz

Victor Cruz is a writer whose articles have appeared in American Venture, Cloud Computing Journal, CommPro.biz, CSO Magazine, Communications News, Computer Technology Review, eSecurity Planet, Harvard Review, Medical Design Technology, and WebSecurity Journal. He has advised some 50 IT companies in the past 20 years on their marketing strategies. You can reach him at vcruz[at]mediapr.net

IoT & Smart Cities Stories
Moroccanoil®, the global leader in oil-infused beauty, is thrilled to announce the NEW Moroccanoil Color Depositing Masks, a collection of dual-benefit hair masks that deposit pure pigments while providing the treatment benefits of a deep conditioning mask. The collection consists of seven curated shades for commitment-free, beautifully-colored hair that looks and feels healthy.
The textured-hair category is inarguably the hottest in the haircare space today. This has been driven by the proliferation of founder brands started by curly and coily consumers and savvy consumers who increasingly want products specifically for their texture type. This trend is underscored by the latest insights from NaturallyCurly's 2018 TextureTrends report, released today. According to the 2018 TextureTrends Report, more than 80 percent of women with curly and coily hair say they purcha...
The textured-hair category is inarguably the hottest in the haircare space today. This has been driven by the proliferation of founder brands started by curly and coily consumers and savvy consumers who increasingly want products specifically for their texture type. This trend is underscored by the latest insights from NaturallyCurly's 2018 TextureTrends report, released today. According to the 2018 TextureTrends Report, more than 80 percent of women with curly and coily hair say they purcha...
We all love the many benefits of natural plant oils, used as a deap treatment before shampooing, at home or at the beach, but is there an all-in-one solution for everyday intensive nutrition and modern styling?I am passionate about the benefits of natural extracts with tried-and-tested results, which I have used to develop my own brand (lemon for its acid ph, wheat germ for its fortifying action…). I wanted a product which combined caring and styling effects, and which could be used after shampo...
The platform combines the strengths of Singtel's extensive, intelligent network capabilities with Microsoft's cloud expertise to create a unique solution that sets new standards for IoT applications," said Mr Diomedes Kastanis, Head of IoT at Singtel. "Our solution provides speed, transparency and flexibility, paving the way for a more pervasive use of IoT to accelerate enterprises' digitalisation efforts. AI-powered intelligent connectivity over Microsoft Azure will be the fastest connected pat...
There are many examples of disruption in consumer space – Uber disrupting the cab industry, Airbnb disrupting the hospitality industry and so on; but have you wondered who is disrupting support and operations? AISERA helps make businesses and customers successful by offering consumer-like user experience for support and operations. We have built the world’s first AI-driven IT / HR / Cloud / Customer Support and Operations solution.
Codete accelerates their clients growth through technological expertise and experience. Codite team works with organizations to meet the challenges that digitalization presents. Their clients include digital start-ups as well as established enterprises in the IT industry. To stay competitive in a highly innovative IT industry, strong R&D departments and bold spin-off initiatives is a must. Codete Data Science and Software Architects teams help corporate clients to stay up to date with the mod...
At CloudEXPO Silicon Valley, June 24-26, 2019, Digital Transformation (DX) is a major focus with expanded DevOpsSUMMIT and FinTechEXPO programs within the DXWorldEXPO agenda. Successful transformation requires a laser focus on being data-driven and on using all the tools available that enable transformation if they plan to survive over the long term. A total of 88% of Fortune 500 companies from a generation ago are now out of business. Only 12% still survive. Similar percentages are found throug...
Druva is the global leader in Cloud Data Protection and Management, delivering the industry's first data management-as-a-service solution that aggregates data from endpoints, servers and cloud applications and leverages the public cloud to offer a single pane of glass to enable data protection, governance and intelligence-dramatically increasing the availability and visibility of business critical information, while reducing the risk, cost and complexity of managing and protecting it. Druva's...
BMC has unmatched experience in IT management, supporting 92 of the Forbes Global 100, and earning recognition as an ITSM Gartner Magic Quadrant Leader for five years running. Our solutions offer speed, agility, and efficiency to tackle business challenges in the areas of service management, automation, operations, and the mainframe.