Encryption & Security at Storage Visions 2015
January 2015 – At Storage Visions 2015, there was a panel discussion and presentations on the security of data in today’s devices and the methods of protecting this information in multi-tenant facilities such as cloud service providers and on mobile devices. The discussions focused on the use of self-encrypting drives, key management and data recovery. The issues focused on the practical implementations of NIST 800-111 and the TCG recommendations.
The challenge has been that a great deal of personal information is held in multiple places such as on the mobile phone and backed up in the cloud. In the event of a lost or stolen device, there are competing camps as to what is the best approach to protect this data and “clear” the device. A leading technology is to store the personal information and the authentication keys in the cloud and only have an index link reside on the mobile device. This runs into the challenge of hackers attacking the cloud site and accessing the data.
Alternative solutions include two and three part keys that have indexes in the mobile device, a trusted third party that has both authentication keys and end target locations at the index point, and finally the target websites/servers that use the authentication keys. This practice is well suited to the new consumer electronics (CE) products that have light CPUs and can’t support a full local encryption engine. The challenge is in having always available connectivity of the CE device to the trusted authentication server, and securing this connection. While it is targeted to be “hacker resistant”, the high value of the assets inside make it a prime target, and there is high susceptibility to DDOS attacks which limit their availability.


