Welcome!

Cloud Security Authors: Liz McMillan, Yeshim Deniz, Elizabeth White, Ed Featherston, Pat Romanski

Related Topics: @CloudExpo, Cloud Security, @DXWorldExpo

@CloudExpo: Blog Feed Post

Hardware-Based Key Managers By @GiladPN | @CloudExpo [#Cloud]

The consensus is that data encryption is a critical first step to migrating to the cloud

Cloud Key Management vs. Hardware-Based Key Managers

Cloud security is a top concern for any organization migrating to the cloud. The threats are many.

For example, the fact your data resides in a shared, multi-tenant environment is a threat that has become a reality with the latest Xen virtualization bug, which allowed a malicious fully virtualized server to read data about other virtualized systems running on the same physical hardware or the hypervisor).

Other threats to cloud security include internal employees and even governments.

The consensus is that data encryption is a critical first step to migrating to the cloud; but in fact, encryption is the easy part. The real challenge lies with the management of the encryption keys. Allowing your cloud provider to encrypt your data and manage the encryption keys is as secure as parking your car in a public parking space and leaving the car keys in the ignition.

The problem with cloud key management options
When reviewing cloud key management, options are quickly narrowed down to two major approaches: hardware security modules and cloud key management systems.

Hardware Security Modules (or HSMs) have been the traditional key management solution for many years. By storing encryption keys on anti tampered hardware, physically locked and, in many cases, on a dedicated secure card, encryption keys were securely stored and used from within a physical data center.

But cloud computing is adding more parameters to the equation.

  • Hardware is not well adapted to the cloud and disrupts the economics and scaling you want.
  • As soon as an encryption key leaves the secure hardware (to encrypt an object in the cloud), it is no longer secured by the HSM.
  • Real-time systems require encryption keys in real-time. To deal with this issue, some vendors have created a virtual version of their HSMs.

o   Unfortunately, such virtual systems are becoming a single point of attack, and your most sensitive secret (your encryption keys) is now in the cloud together with your data.

o   To add to the confusion, some key management vendors will add compliance language to such virtual offerings, making it feel secure and trusted. But, in fact, the certification is only valid for the physical hardware, not the virtualized key management solution.

Split-key encryption and homomorphic key management
To effectively manage keys in the cloud, there’s a need for a fundamentally new approach. The new approach needs to allow customers to encrypt data while maintaining control of their encryption keys. It needs to be a fully virtual key management system, which will not compromise the encryption keys’ security, and will be scalable in size and across regions.

Split-key encryption and homomorphic key management are two cloud key management technologies which successful address these issues.

Split-key encryption, as the name insinuates, splits encryption keys between the security provider and the end customer. This assures that encryption keys are never known to any single entity (the cloud provider or the security vendor can never see nor access any keys). Furthermore, control is eventually held by the end customer, who constantly owns half of the key – a master key.

The best analogy is that of a safety deposit box with two keys: one belongs to the banker, the second belongs to the customer and only the combination of both can open or lock the box (this video demonstrates the concept visually).

Homomorphic encryption is an exciting and relatively new field of encryption. It enables a system to compute on an encrypted object without ever decrypting it. Innovative cloud security companies leverage homomorphic encryption to encrypt the encryption keys themselves; thus assuring that customers’ keys are never available in clear in the cloud.

“Evolve or Die”
Over a year ago, PwC had issued a whitepaper titled “Evolve or Die: How the Cloud is Shaping the IT Organization.” The title summarizes the situation very accurately. The cloud is a reality, and as any CIO will tell you, the question of migrating to the cloud is “when” and no longer “why.”

When it comes to cloud security, encryption is critical, but trusted and virtual key management is the hardest challenge. As more and more organizations migrate to cloud computing, we expect the adoption of innovative technologies such as key-splitting and homomorphic key management will lead the cloud encryption era.

The post Cloud Key Management vs. Hardware-Based Key Managers (HSMs) appeared first on Porticor Cloud Security.

Read the original blog entry...

More Stories By Gilad Parann-Nissany

Gilad Parann-Nissany, Founder and CEO at Porticor is a pioneer of Cloud Computing. He has built SaaS Clouds for medium and small enterprises at SAP (CTO Small Business); contributing to several SAP products and reaching more than 8 million users. Recently he has created a consumer Cloud at G.ho.st - a cloud operating system that delighted hundreds of thousands of users while providing browser-based and mobile access to data, people and a variety of cloud-based applications. He is now CEO of Porticor, a leader in Virtual Privacy and Cloud Security.

@ThingsExpo Stories
DXWorldEXPO LLC announced today that All in Mobile, a mobile app development company from Poland, will exhibit at the 22nd International CloudEXPO | DXWorldEXPO. All In Mobile is a mobile app development company from Poland. Since 2014, they maintain passion for developing mobile applications for enterprises and startups worldwide.
"Akvelon is a software development company and we also provide consultancy services to folks who are looking to scale or accelerate their engineering roadmaps," explained Jeremiah Mothersell, Marketing Manager at Akvelon, in this SYS-CON.tv interview at 21st Cloud Expo, held Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA.
JETRO showcased Japan Digital Transformation Pavilion at SYS-CON's 21st International Cloud Expo® at the Santa Clara Convention Center in Santa Clara, CA. The Japan External Trade Organization (JETRO) is a non-profit organization that provides business support services to companies expanding to Japan. With the support of JETRO's dedicated staff, clients can incorporate their business; receive visa, immigration, and HR support; find dedicated office space; identify local government subsidies; get...
The current age of digital transformation means that IT organizations must adapt their toolset to cover all digital experiences, beyond just the end users’. Today’s businesses can no longer focus solely on the digital interactions they manage with employees or customers; they must now contend with non-traditional factors. Whether it's the power of brand to make or break a company, the need to monitor across all locations 24/7, or the ability to proactively resolve issues, companies must adapt to...
"We view the cloud not as a specific technology but as a way of doing business and that way of doing business is transforming the way software, infrastructure and services are being delivered to business," explained Matthew Rosen, CEO and Director at Fusion, in this SYS-CON.tv interview at 18th Cloud Expo (http://www.CloudComputingExpo.com), held June 7-9 at the Javits Center in New York City, NY.
DXWorldEXPO LLC announced today that the upcoming DXWorldEXPO | CloudEXPO New York event will feature 10 companies from Poland to participate at the "Poland Digital Transformation Pavilion" on November 12-13, 2018.
As data explodes in quantity, importance and from new sources, the need for managing and protecting data residing across physical, virtual, and cloud environments grow with it. Managing data includes protecting it, indexing and classifying it for true, long-term management, compliance and E-Discovery. Commvault can ensure this with a single pane of glass solution – whether in a private cloud, a Service Provider delivered public cloud or a hybrid cloud environment – across the heterogeneous enter...
More and more brands have jumped on the IoT bandwagon. We have an excess of wearables – activity trackers, smartwatches, smart glasses and sneakers, and more that track seemingly endless datapoints. However, most consumers have no idea what “IoT” means. Creating more wearables that track data shouldn't be the aim of brands; delivering meaningful, tangible relevance to their users should be. We're in a period in which the IoT pendulum is still swinging. Initially, it swung toward "smart for smart...
DXWorldEXPO LLC announced today that ICC-USA, a computer systems integrator and server manufacturing company focused on developing products and product appliances, will exhibit at the 22nd International CloudEXPO | DXWorldEXPO. DXWordEXPO New York 2018, colocated with CloudEXPO New York 2018 will be held November 11-13, 2018, in New York City. ICC is a computer systems integrator and server manufacturing company focused on developing products and product appliances to meet a wide range of ...
Major trends and emerging technologies – from virtual reality and IoT, to Big Data and algorithms – are helping organizations innovate in the digital era. However, to create real business value, IT must think beyond the ‘what’ of digital transformation to the ‘how’ to harness emerging trends, innovation and disruption. Architecture is the key that underpins and ties all these efforts together. In the digital age, it’s important to invest in architecture, extend the enterprise footprint to the cl...
Coca-Cola’s Google powered digital signage system lays the groundwork for a more valuable connection between Coke and its customers. Digital signs pair software with high-resolution displays so that a message can be changed instantly based on what the operator wants to communicate or sell. In their Day 3 Keynote at 21st Cloud Expo, Greg Chambers, Global Group Director, Digital Innovation, Coca-Cola, and Vidya Nagarajan, a Senior Product Manager at Google, discussed how from store operations and ...
Headquartered in Plainsboro, NJ, Synametrics Technologies has provided IT professionals and computer systems developers since 1997. Based on the success of their initial product offerings (WinSQL and DeltaCopy), the company continues to create and hone innovative products that help its customers get more from their computer applications, databases and infrastructure. To date, over one million users around the world have chosen Synametrics solutions to help power their accelerated business or per...
Dion Hinchcliffe is an internationally recognized digital expert, bestselling book author, frequent keynote speaker, analyst, futurist, and transformation expert based in Washington, DC. He is currently Chief Strategy Officer at the industry-leading digital strategy and online community solutions firm, 7Summits.
We are seeing a major migration of enterprises applications to the cloud. As cloud and business use of real time applications accelerate, legacy networks are no longer able to architecturally support cloud adoption and deliver the performance and security required by highly distributed enterprises. These outdated solutions have become more costly and complicated to implement, install, manage, and maintain.SD-WAN offers unlimited capabilities for accessing the benefits of the cloud and Internet. ...
In an era of historic innovation fueled by unprecedented access to data and technology, the low cost and risk of entering new markets has leveled the playing field for business. Today, any ambitious innovator can easily introduce a new application or product that can reinvent business models and transform the client experience. In their Day 2 Keynote at 19th Cloud Expo, Mercer Rowe, IBM Vice President of Strategic Alliances, and Raejeanne Skillern, Intel Vice President of Data Center Group and ...
Bill Schmarzo, author of "Big Data: Understanding How Data Powers Big Business" and "Big Data MBA: Driving Business Strategies with Data Science," is responsible for setting the strategy and defining the Big Data service offerings and capabilities for EMC Global Services Big Data Practice. As the CTO for the Big Data Practice, he is responsible for working with organizations to help them identify where and how to start their big data journeys. He's written several white papers, is an avid blogge...
Founded in 2000, Chetu Inc. is a global provider of customized software development solutions and IT staff augmentation services for software technology providers. By providing clients with unparalleled niche technology expertise and industry experience, Chetu has become the premiere long-term, back-end software development partner for start-ups, SMBs, and Fortune 500 companies. Chetu is headquartered in Plantation, Florida, with thirteen offices throughout the U.S. and abroad.
Bill Schmarzo, author of "Big Data: Understanding How Data Powers Big Business" and "Big Data MBA: Driving Business Strategies with Data Science," is responsible for setting the strategy and defining the Big Data service offerings and capabilities for EMC Global Services Big Data Practice. As the CTO for the Big Data Practice, he is responsible for working with organizations to help them identify where and how to start their big data journeys. He's written several white papers, is an avid blogge...
From 2013, NTT Communications has been providing cPaaS service, SkyWay. Its customer’s expectations for leveraging WebRTC technology are not only typical real-time communication use cases such as Web conference, remote education, but also IoT use cases such as remote camera monitoring, smart-glass, and robotic. Because of this, NTT Communications has numerous IoT business use-cases that its customers are developing on top of PaaS. WebRTC will lead IoT businesses to be more innovative and address...
Charles Araujo is an industry analyst, internationally recognized authority on the Digital Enterprise and author of The Quantum Age of IT: Why Everything You Know About IT is About to Change. As Principal Analyst with Intellyx, he writes, speaks and advises organizations on how to navigate through this time of disruption. He is also the founder of The Institute for Digital Transformation and a sought after keynote speaker. He has been a regular contributor to both InformationWeek and CIO Insight...