Cloud

6/20/2018
02:12 PM
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

Intel VP Talks Data Security Focus Amid Rise of Blockchain, AI

Intel vice president Rick Echevarria discusses the challenges of balancing data security with new technologies like blockchain and artificial intelligence.

It's tough for businesses to make use of data as it grows in volume and complexity, pouring in from multiple sources and systems. As organizations use new technologies like artificial intelligence and blockchain to process and store data, they have a responsibility to ensure data is protected.

"How do we enable those workloads to transform the business, and to the best of our abilities prevent security from getting in the way?" says Rick Echevarria, vice president of Intel's Software and Services Group, and general manager of Platform Security, in an interview with Dark Reading.

At Cyber Week, now taking place in Israel, Echevarria will discuss how he's navigating the challenges in new tech. Machine learning algorithms often require access to sensitive data but limiting access to the necessary data could limit the potential for AI. As for technical considerations related to blockchain, the security of information is as important as scalability.

Getting Smarter on AI  

When it comes to trends around AI, he says, there are two implementations: security for AI, where the focus is on protecting data and algorithms, and AI for security, in which tools leverage AI to detect advanced threats. Echevarria's focus is on security for AI.

"The reason for that is because people are deploying artificial intelligence today, and we want to make sure they're really aware of, and understand, the importance of security to underpin those workloads," he explains.

Echevarria points to two use cases in which Intel is addressing the AI challenge. The first is multi-party machine learning, which relies on the assumption that you can bring data to a central location. Tools like Intel's hardware-based Trusted Execution Environments grant access to critical data and ensure algorithms' integrity.

The second is federated learning, intended for applications where data can't be moved to a central location. In this case, data owners on the edges of the infrastructure work together to develop models themselves. Here, Echevarria says, many businesses encounter challenges.

"It's really about enabling access to data across organizations that really want to collaborate but sometimes because of privacy can't share data in the way they want to," he explains. The challenge is often seen in industries like healthcare and financial services, where teams may want to share threat intelligence but don't have the permission to share data.

Intel plans to support more extensive data sharing by teaming up with organizations like Docker, Fortanix, and Duality. With Docker, for example, a partnership will focus on making AI more secure and sharable by hardening containers with Intel's silicon-based security tech. Fortanix is adding to its Runtime Encryption tool to secure algorithms with Intel SGX enclaves.

Buckling Down on Blockchain

Some of the challenges in AI are consistent with challenges in blockchain, says Echevarria, who notes that Intel sees opportunity in blockchain as a platform. This week Intel is addressing scalability, security, and privacy of blockchain with updates in what it calls "Off-Chain Computing" along with partnerships with Enigma and SAP.

Intel has already teamed up with Microsoft to work on securing the blockchain. Back in May, the Microsoft Azure team, along with Microsoft Research, Intel, Windows, and the Microsoft Developer Tools division, announced it had been working to bring Intel's Trusted Execution Environments (Intel SGX, Virtualization Based Security) to the cloud.

Most recently, Intel partnered with SAP to build a blockchain proof-of-concept and improve efficiency for SAP's blockchain-as-a-service platform. Enigma has developed a privacy protocol that uses Intel SGX to secure data; it plans to integrate this into private smart contracts on the Ethereum public ledger.

Echevarria also speaks to plans to improve off-chain computing, in which transactions are not publicly accessible on the blockchain, specifically related to smart contracts. Businesses can do a better job of executing smart contracts in a more secure fashion, he says.

Related Content:

 Why Cybercriminals Attack: A DARK READING VIRTUAL EVENT Wednesday, June 27. Industry experts will offer a range of information and insight on who the bad guys are – and why they might be targeting your enterprise. Go here for more information on this free event.

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
What We Talk About When We Talk About Risk
Jack Jones, Chairman, FAIR Institute,  7/11/2018
Ticketmaster Breach Part of Massive Payment Card Hacking Campaign
Jai Vijayan, Freelance writer,  7/10/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Locked device, Ha! I knew there was another way in.
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-10886
PUBLISHED: 2018-07-16
ant before version 1.9.12 unzip and untar targets allows the extraction of files outside the target directory. A crafted zip or tar file submitted to an Ant build could create or overwrite arbitrary files with the privileges of the user running Ant.
CVE-2018-10859
PUBLISHED: 2018-07-16
git-annex is vulnerable to an Information Exposure when decrypting files. A malicious server for a special remote could trick git-annex into decrypting a file that was encrypted to the user's gpg key. This attack could be used to expose encrypted data that was never stored in git-annex
CVE-2018-14324
PUBLISHED: 2018-07-16
The demo feature in Oracle GlassFish Open Source Edition 5.0 has TCP port 7676 open by default with a password of admin for the admin account. This allows remote attackers to obtain potentially sensitive information, perform database operations, or manipulate the demo via a JMX RMI session, aka a &q...
CVE-2018-14325
PUBLISHED: 2018-07-16
In MP4v2 2.0.0, there is an integer underflow (with resultant memory corruption) when parsing MP4Atom in mp4atom.cpp.
CVE-2018-14326
PUBLISHED: 2018-07-16
In MP4v2 2.0.0, there is an integer overflow (with resultant memory corruption) when resizing MP4Array for the ftyp atom in mp4array.h.