IBM Security’s new service allows customers to try out fully homomorphic encryption (FHE), an emerging technology that the vendor says will improve hybrid cloud security as customers move data to the cloud or between multiple clouds and on-premises locations.
“As data becomes more portable and hybrid cloud becomes more embedded within our application architectures, and customers are more and more concerned about where is my data going and who’s able to see it, touch it, our ability to insulate them from some of the issues that arise because data has to be decrypted as it’s traversing that complex web of now hybrid-cloud infrastructure is a significant differentiator,” said Eric Maass, director of strategy and emerging technology for IBM Security Services.
FHE allows data to remain encrypted even while being processed or analyzed in cloud or third-party environments. The new IBM Security Homomorphic Encryption Services provide companies with support and a testing environment to develop prototype applications that can take advantage of FHE.
Some of the initial use cases include performing analytics on encrypted data, conducting encrypted searches while concealing search query and content, and training artificial intelligence (AI) and machine learning (ML) models while maintaining existing privacy and confidentiality controls.
Additionally, FHE is based on lattice cryptography which is considered quantum safe – or resistant to breakage by future quantum-computing speeds.
IBM Security Homomorphic Encryption ServicesSpecifically, the new IBM Security Homomorphic Encryption Services provides customers with:
- IBM-developed FHE tools, which provide templates for use cases such as encrypted search, AI, and ML.
- Guidance, consulting, and support from IBM cryptography experts, to help companies build the skills needed to design and work with FHE-enabled applications.
- A scalable hosting environment on IBM Cloud for developers to begin experimenting and building prototypes for their own FHE-enabled applications.
It essentially boils down to two components, Maass said. The first part of the new services centers around educating customers and their developers about FHE. “There’s new types of tooling, and there’s new types of libraries that are going to be unfamiliar to developers, including things like how the data needs to be prepared,” he explained. “We’re not just going to pull data directly out of the database. It needs to go through a preparation process to be utilized with FHE.”
Second, customers will need help with the computing environment, Maass said. While FHE has become more efficient in the decade since it’s been in development by IBM and other researchers, it’s still very compute intensive. “And it requires certain forms of technology, like the ability to manage and store lattice encryption keys that there’s not commercial, off-the-shelf technology for,” Maass said. IBM’s service addresses these challenges by giving customers access to a managed compute environment where they can operate FHE-enabled applications without having to build and manage the infrastructure, he added.
Comments