Welcome!

SAP HANA Cloud Authors: Elizabeth White, Liz McMillan, Pat Romanski, William Schmarzo, Ian Khan

Blog Feed Post

Porticor Beefs Up Cloud Security with Split-Key Encryption

 NWC logo Porticor Beefs Up Cloud Security with Split Key Encryption

 

(Originally posted by Gary Hilson here)

Cloud security startup Porticor has updated its Virtual Private Data (VPD) system to help companies encrypt data stored in the cloud and protect encryption keys. Porticor’s VPD combines encryption and its own proprietary key management service to protect enterprise data stored in public, private and hybrid clouds that run on VMWare and Amazon Web Services.

Porticor’s VDP consists of two elements: the Porticor Virtual Appliance and the Virtual Key Management Service. Customers deploy the Virtual Appliance within a public or private cloud instance. The appliance encrypts data using the AES-256 algorithm. The Virtual Key Management Service, which is run from Portico’s own cloud, splits the encryption key used to encrypt data in the Virtual Appliance into two separate keys. One of these keys, the master key, is kept encrypted even while in use.

The VPD system uses partialhomomorphic encryptiontechniques to split the encryption key. Homomorphic encryption enables mathematical operations to be performed on encrypted data. This means the master key can remain encrypted even as it encrypts and decrypts data stored in the cloud. The company says that if a master key is stolen, it can’t be used to access a data store.

Data security is one of the top concerns for enterprises looking to adopt public cloud services, but the challenge is how to juggle convenient access to data and while managing security through use of encryption keys, said Scott Crawford, research director of Enterprise Management Associates. “Organizations have concerns, and rightly so, about encryption key management, which must be taken seriously to ensure the availability of protected data.”

Crawford said Porticor’s concept is not new, but the company’s implementation for cloud environments is rather novel. He noted there are encryption options for specific SaaS services such as Salesforce.com, which acquired SaaS encryption provider Navajo Systems last year.

“Porticor is primarily targeting Infrastructure-as-a-Service, however, it’s a capability that would be available to application developers if they wanted to build their own application and expose it to customers and partners,” said Crawford.

According to the InformationWeek 2012 Data Encryption Surveyreleased earlier this year, there’s “growing angst” over encryption of data off-site in the cloud, while enterprises continue to have concerns over the interoperability between encryption products.

Meanwhile, respondents to the InformationWeek 2012 State of Cloud Computing Survey admit that security is a big worry; among nine possible concerns, the three associated with security came in first, second and third, and 44% said they believe risks are greater in the cloud vs. 6% who say providers do a better job at security than they could do internally.

Richard Stiennon, chief research analyst, IT-Harvest, says Porticor’s approach is unique and potentially disruptive. He said there other ways to accomplish what Porticor does, but the VPD system is a more flexible. “I expect it to be able to fit into a lot of other cloud-base services.”

Stiennon said Porticor addresses a significant business problem for enterprises – how they can securely store data in the cloud. Existing methods include having to download a software agent that encrypts the data locally and sends it up to the cloud, and all involve a level of complex key management. “You’ve probably either got shared keys, which is not a good thing, or you have your own key, which is susceptible to theft or just losing it.”

Stiennon said few security vendors aside from companies such as SpiderOak give enterprise customers control over their encryption keys. The Porticor’s VPD system’s use of homomorphic encryption means the owner of the cloud service does not have access to customer data.

“To me this is the most important thing,” said Stiennon, because enterprises cannot extend trust to service providers of any sort because providers are subject to subpoena, for example. “Under the Porticor encryption model, the service provider would not be able to divulge customer data regardless of a subpoena because they would not have access to the encryption keys.”

The new release of Porticor VPD is available now. Pricing starts at $65 per month per Porticor Virtual Appliance. Porticor, which is headquartered in Israel, was founded in 2010.

The post Porticor Beefs Up Cloud Security with Split-Key Encryption appeared first on Porticor Cloud Security.

Read the original blog entry...

More Stories By Gilad Parann-Nissany

Gilad Parann-Nissany, Founder and CEO at Porticor is a pioneer of Cloud Computing. He has built SaaS Clouds for medium and small enterprises at SAP (CTO Small Business); contributing to several SAP products and reaching more than 8 million users. Recently he has created a consumer Cloud at G.ho.st - a cloud operating system that delighted hundreds of thousands of users while providing browser-based and mobile access to data, people and a variety of cloud-based applications. He is now CEO of Porticor, a leader in Virtual Privacy and Cloud Security.

@ThingsExpo Stories
SYS-CON Events announced today that BMC Software has been named "Siver Sponsor" of SYS-CON's 18th Cloud Expo, which will take place on June 7-9, 2015 at the Javits Center in New York, New York. BMC is a global leader in innovative software solutions that help businesses transform into digital enterprises for the ultimate competitive advantage. BMC Digital Enterprise Management is a set of innovative IT solutions designed to make digital business fast, seamless, and optimized from mainframe to mo...
SYS-CON Events announced today that MobiDev will exhibit at SYS-CON's 18th International Cloud Expo®, which will take place on June 7-9, 2016, at the Javits Center in New York City, NY. MobiDev is a software company that develops and delivers turn-key mobile apps, websites, web services, and complex software systems for startups and enterprises. Since 2009 it has grown from a small group of passionate engineers and business managers to a full-scale mobile software company with over 200 develope...
As cloud and storage projections continue to rise, the number of organizations moving to the cloud is escalating and it is clear cloud storage is here to stay. However, is it secure? Data is the lifeblood for government entities, countries, cloud service providers and enterprises alike and losing or exposing that data can have disastrous results. There are new concepts for data storage on the horizon that will deliver secure solutions for storing and moving sensitive data around the world. ...
SoftLayer operates a global cloud infrastructure platform built for Internet scale. With a global footprint of data centers and network points of presence, SoftLayer provides infrastructure as a service to leading-edge customers ranging from Web startups to global enterprises. SoftLayer's modular architecture, full-featured API, and sophisticated automation provide unparalleled performance and control. Its flexible unified platform seamlessly spans physical and virtual devices linked via a world...
SYS-CON Events announced today that ContentMX, the marketing technology and services company with a singular mission to increase engagement and drive more conversations for enterprise, channel and SMB technology marketers, has been named “Sponsor & Exhibitor Lounge Sponsor” of SYS-CON's 18th Cloud Expo, which will take place on June 7-9, 2016, at the Javits Center in New York City, New York. “CloudExpo is a great opportunity to start a conversation with new prospects, but what happens after the...
Companies can harness IoT and predictive analytics to sustain business continuity; predict and manage site performance during emergencies; minimize expensive reactive maintenance; and forecast equipment and maintenance budgets and expenditures. Providing cost-effective, uninterrupted service is challenging, particularly for organizations with geographically dispersed operations.
The IoTs will challenge the status quo of how IT and development organizations operate. Or will it? Certainly the fog layer of IoT requires special insights about data ontology, security and transactional integrity. But the developmental challenges are the same: People, Process and Platform. In his session at @ThingsExpo, Craig Sproule, CEO of Metavine, will demonstrate how to move beyond today's coding paradigm and share the must-have mindsets for removing complexity from the development proc...
SYS-CON Events announced today TechTarget has been named “Media Sponsor” of SYS-CON's 18th International Cloud Expo, which will take place on June 7–9, 2016, at the Javits Center in New York City, NY, and the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. TechTarget is the Web’s leading destination for serious technology buyers researching and making enterprise technology decisions. Its extensive global networ...
SYS-CON Events announced today that Commvault, a global leader in enterprise data protection and information management, has been named “Bronze Sponsor” of SYS-CON's 18th International Cloud Expo, which will take place on June 7–9, 2016, at the Javits Center in New York City, NY, and the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. Commvault is a leading provider of data protection and information management...
The essence of data analysis involves setting up data pipelines that consist of several operations that are chained together – starting from data collection, data quality checks, data integration, data analysis and data visualization (including the setting up of interaction paths in that visualization). In our opinion, the challenges stem from the technology diversity at each stage of the data pipeline as well as the lack of process around the analysis.
Designing IoT applications is complex, but deploying them in a scalable fashion is even more complex. A scalable, API first IaaS cloud is a good start, but in order to understand the various components specific to deploying IoT applications, one needs to understand the architecture of these applications and figure out how to scale these components independently. In his session at @ThingsExpo, Nara Rajagopalan is CEO of Accelerite, will discuss the fundamental architecture of IoT applications, ...
A strange thing is happening along the way to the Internet of Things, namely far too many devices to work with and manage. It has become clear that we'll need much higher efficiency user experiences that can allow us to more easily and scalably work with the thousands of devices that will soon be in each of our lives. Enter the conversational interface revolution, combining bots we can literally talk with, gesture to, and even direct with our thoughts, with embedded artificial intelligence, wh...
SYS-CON Events announced today that Tintri Inc., a leading producer of VM-aware storage (VAS) for virtualization and cloud environments, will exhibit at the 18th International CloudExpo®, which will take place on June 7-9, 2016, at the Javits Center in New York City, New York, and the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA.
SYS-CON Events announced today that MangoApps will exhibit at SYS-CON's 18th International Cloud Expo®, which will take place on June 7-9, 2016, at the Javits Center in New York City, NY. MangoApps provides modern company intranets and team collaboration software, allowing workers to stay connected and productive from anywhere in the world and from any device. For more information, please visit https://www.mangoapps.com/.
SYS-CON Events announced today that Alert Logic, Inc., the leading provider of Security-as-a-Service solutions for the cloud, will exhibit at SYS-CON's 18th International Cloud Expo®, which will take place on June 7-9, 2016, at the Javits Center in New York City, NY. Alert Logic, Inc., provides Security-as-a-Service for on-premises, cloud, and hybrid infrastructures, delivering deep security insight and continuous protection for customers at a lower cost than traditional security solutions. Ful...
In his session at 18th Cloud Expo, Bruce Swann, Senior Product Marketing Manager at Adobe, will discuss how the Adobe Marketing Cloud can help marketers embrace opportunities for personalized, relevant and real-time customer engagement across offline (direct mail, point of sale, call center) and digital (email, website, SMS, mobile apps, social networks, connected objects). Bruce Swann has more than 15 years of experience working with digital marketing disciplines like web analytics, social med...
SYS-CON Events announced today Object Management Group® has been named “Media Sponsor” of SYS-CON's 18th International Cloud Expo, which will take place on June 7–9, 2016, at the Javits Center in New York City, NY, and the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA.
SYS-CON Events announced today that EastBanc Technologies will exhibit at SYS-CON's 18th International Cloud Expo®, which will take place on June 7-9, 2016, at the Javits Center in New York City, NY. EastBanc Technologies has been working at the frontier of technology since 1999. Today, the firm provides full-lifecycle software development delivering flexible technology solutions that seamlessly integrate with existing systems – whether on premise or cloud. EastBanc Technologies partners with p...
WebRTC is bringing significant change to the communications landscape that will bridge the worlds of web and telephony, making the Internet the new standard for communications. Cloud9 took the road less traveled and used WebRTC to create a downloadable enterprise-grade communications platform that is changing the communication dynamic in the financial sector. In his session at @ThingsExpo, Leo Papadopoulos, CTO of Cloud9, will discuss the importance of WebRTC and how it enables companies to fo...
The IoT is changing the way enterprises conduct business. In his session at @ThingsExpo, Eric Hoffman, Vice President at EastBanc Technologies, discuss how businesses can gain an edge over competitors by empowering consumers to take control through IoT. We'll cite examples such as a Washington, D.C.-based sports club that leveraged IoT and the cloud to develop a comprehensive booking system. He'll also highlight how IoT can revitalize and restore outdated business models, making them profitable...