Andrew Rose serves Security & Risk Professionals. See the full Analyst bio.
Visit Forrester.com to learn how we make Security & Risk Professionals successful every day.
A Christmas Present From MIT?
Posted by Andrew Rose on December 20, 2011
- 259 Recommendations
- 0 comments
As much as the cloud computing model makes sense to me, my security sensibilities cry out about information risk every time I start to consider actual implementation for data of value across an enterprise.
A model which has always made sense has been to place only encrypted data in the cloud, holding the keys locally. This solution gives you control over data access, bypassing any Patriot Act concerns, but allows realization of the benefits of a shared, cloud infrastructure. It has always been recognized, however, that this solution has a number of drawbacks, such as:
- The immense corporate sensitivity of the encryption keys utilised. These keys become essential to doing business. If they are corrupted, lost or held hostage by hacktivists, for example, then the organization stops dead in the water.
- The difficulty of creating indexes, searching and applying transactions across encrypted data stores. If the concept is to keep the keys away from the cloud environment then actions such as indexing, searching or running database functions become very challenging.
In 2009 an IBM cryptographer named Craig Gentry wrote a PhD dissertation describing a solution to the second of these challenges, unfortunately it too had a drawback – his homomorphic encryption solution would increase transaction times by a factor of one trillion.
MIT have now, however, outlined a simpler solution to the problem. CryptDB seeks to address the same challenges but claims to add only 25% to the transaction time. I’m sure it’s not perfect, but it is a positive step toward answering a difficult question and cloud vendors should be interested in how such a feat of encryption wizardry can enable a wider adoption of their services.
Categories:
search forrester's blogs
Secure the digital business future.
Attend Forrester’s Forum for Security & Risk Professionals EMEA, June 10-11, London UK
Analyst Blogs
- Andras Cser (31)
- Andrew Rose (17)
- Chris McClean (54)
- Christopher Sherman (1)
- Edward Ferrara (20)
- Eve Maler (19)
- Heidi Shey (9)
- John Kindervag (28)
- Khalid Kark (13)
- Laura Koetzle (2)
- Nick Hayes (5)
- Rick Holland (20)
- Stephanie Balaouras (50)
Top Categories
- CISO (2)
- cloud (2)
- Cyberinsurance (2)
- data security (2)
- Risk Management (2)
- Security & Risk (2)
- 2013 (1)
- access control (1)
- Application Development (1)
- Asset Management (1)
- See all
Archives
- January 2013 (2)
- November 2012 (1)
- August 2012 (1)
- July 2012 (1)
- May 2012 (1)
- March 2012 (3)
- February 2012 (2)
- January 2012 (1)
- December 2011 (2)
- October 2011 (1)
- July 2011 (2)