| By Gilad Parann-Nissany | Article Rating: |
|
| November 1, 2012 08:41 AM EDT | Reads: |
1,210 |
(Originally posted by Gary Hilson here)
Cloud security startup Porticor has updated its Virtual Private Data (VPD) system to help companies encrypt data stored in the cloud and protect encryption keys. Porticor’s VPD combines encryption and its own proprietary key management service to protect enterprise data stored in public, private and hybrid clouds that run on VMWare and Amazon Web Services.
Porticor’s VDP consists of two elements: the Porticor Virtual Appliance and the Virtual Key Management Service. Customers deploy the Virtual Appliance within a public or private cloud instance. The appliance encrypts data using the AES-256 algorithm. The Virtual Key Management Service, which is run from Portico’s own cloud, splits the encryption key used to encrypt data in the Virtual Appliance into two separate keys. One of these keys, the master key, is kept encrypted even while in use.
Data security is one of the top concerns for enterprises looking to adopt public cloud services, but the challenge is how to juggle convenient access to data and while managing security through use of encryption keys, said Scott Crawford, research director of Enterprise Management Associates. “Organizations have concerns, and rightly so, about encryption key management, which must be taken seriously to ensure the availability of protected data.”
Crawford said Porticor’s concept is not new, but the company’s implementation for cloud environments is rather novel. He noted there are encryption options for specific SaaS services such as Salesforce.com, which acquired SaaS encryption provider Navajo Systems last year.
“Porticor is primarily targeting Infrastructure-as-a-Service, however, it’s a capability that would be available to application developers if they wanted to build their own application and expose it to customers and partners,” said Crawford.
According to the InformationWeek 2012 Data Encryption Surveyreleased earlier this year, there’s “growing angst” over encryption of data off-site in the cloud, while enterprises continue to have concerns over the interoperability between encryption products.
Meanwhile, respondents to the InformationWeek 2012 State of Cloud Computing Survey admit that security is a big worry; among nine possible concerns, the three associated with security came in first, second and third, and 44% said they believe risks are greater in the cloud vs. 6% who say providers do a better job at security than they could do internally.
Richard Stiennon, chief research analyst, IT-Harvest, says Porticor’s approach is unique and potentially disruptive. He said there other ways to accomplish what Porticor does, but the VPD system is a more flexible. “I expect it to be able to fit into a lot of other cloud-base services.”
Stiennon said Porticor addresses a significant business problem for enterprises – how they can securely store data in the cloud. Existing methods include having to download a software agent that encrypts the data locally and sends it up to the cloud, and all involve a level of complex key management. “You’ve probably either got shared keys, which is not a good thing, or you have your own key, which is susceptible to theft or just losing it.”
Stiennon said few security vendors aside from companies such as SpiderOak give enterprise customers control over their encryption keys. The Porticor’s VPD system’s use of homomorphic encryption means the owner of the cloud service does not have access to customer data.
“To me this is the most important thing,” said Stiennon, because enterprises cannot extend trust to service providers of any sort because providers are subject to subpoena, for example. “Under the Porticor encryption model, the service provider would not be able to divulge customer data regardless of a subpoena because they would not have access to the encryption keys.”
The new release of Porticor VPD is available now. Pricing starts at $65 per month per Porticor Virtual Appliance. Porticor, which is headquartered in Israel, was founded in 2010.
The post Porticor Beefs Up Cloud Security with Split-Key Encryption appeared first on Porticor Cloud Security.
Read the original blog entry...
Published November 1, 2012 Reads 1,210
Copyright © 2012 SYS-CON Media, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
More Stories By Gilad Parann-Nissany
Gilad Parann-Nissany, Founder and CEO at Porticor is a pioneer of Cloud Computing. He has built SaaS Clouds for medium and small enterprises at SAP (CTO Small Business); contributing to several SAP products and reaching more than 8 million users. Recently he has created a consumer Cloud at G.ho.st - a cloud operating system that delighted hundreds of thousands of users while providing browser-based and mobile access to data, people and a variety of cloud-based applications. He is now CEO of Porticor, a leader in Virtual Privacy and Cloud Security.
- Cloud People: A Who's Who of Cloud Computing
- Windows Azure IaaS Reaches General Availability
- AMD and Adobe Collaborate on Upcoming Version of Adobe Premiere Pro Software to Enable Breakthrough Video Editing Performance Through Open Standards
- Enterasys Spotlights SDN's Impact on Traditional Networking in Upcoming Webinar
- New Relic Q1 2013 Blazes Past Growth Targets and Reaches 40,000 Active Customer Accounts
- GDS International Confirms Unprecedented Delegation for Upcoming Next Generation Telecoms Europe Summit in May
- UNIT4 Business Software: Three Retail Accounting Tips to Help Retailers Leverage the Cloud and Back Office Systems
- Velocity Technology Solutions Introduces IBM Power Systems Universal Cloud Services at COMMON 2013
- CompuCom Announces Sale to Thomas H. Lee Partners
- AMAX Launches StorMax(TM) CFS, powered by IBM(R) General Parallel File System(TM) (GPFS(TM))
- OneNeck(R) IT Services, an Enterprise Cloud Services and Managed Hosting Company, Announces the General Availability of Their Award-Winning Desktop-as-a-Service Offering
- Riverbed Strengthens Commitment to Federal Market; Achieves Common Criteria Certification for Network Performance Management Solution
- Cloud People: A Who's Who of Cloud Computing
- Windows Azure IaaS Reaches General Availability
- AMD and Adobe Collaborate on Upcoming Version of Adobe Premiere Pro Software to Enable Breakthrough Video Editing Performance Through Open Standards
- Enterasys Spotlights SDN's Impact on Traditional Networking in Upcoming Webinar
- New Relic Q1 2013 Blazes Past Growth Targets and Reaches 40,000 Active Customer Accounts
- Salesforce.com Executives to Participate in Upcoming Investor Events
- Gravitant Supports General Dynamics Information Technology in Offering New Cloud Brokerage Services to Government Entities
- Global Micro Servers Market (2013 - 2018), By Processor Type (Intel, Arm, Amd), Component (Hardware, Software, Operating System), Application (Media Storage, Data Centers, Analytics, Cloud Computing) & Geography (North America, Europe, Apac, Row)
- SUSE Receives Common Criteria Security Certifications
- Basho Announces Open Source Riak CS and General Availability of Riak CS Enterprise v1.3
- GDS International Confirms Unprecedented Delegation for Upcoming Next Generation Telecoms Europe Summit in May
- UNIT4 Business Software: Three Retail Accounting Tips to Help Retailers Leverage the Cloud and Back Office Systems
- "HP's Problem Ain't the SAP Install," Says Sun's Schwartz
- Cloud People: A Who's Who of Cloud Computing
- Red Hat Named "Platinum Sponsor" of Virtualization Conference & Expo
- Web Services Strategy - SAP Platform
- Cloud Expo 2011 East To Attract 10,000 Delegates and 200 Exhibitors
- Cloud Expo and The End of Tech Recession
- JCP EC Elections Have BEA, SAP, Nokia, IBM, Philips in the Running
- BEA, IBM, Oracle, SAP, IONA, Siebel and Sybase Announce "Service Component Architecture" Specification
- Oracle To Keynote Cloud Computing Expo
- SAP Is Using Adobe Flex
- SOA, Virtualization and Web 2.0: BEA's Deputy CTO Connects the Dots
- Cloud Expo, Inc. Announces Cloud Expo 2011 New York Venue




























