Cloud

6/20/2018
02:12 PM
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

Intel VP Talks Data Security Focus Amid Rise of Blockchain, AI

Intel vice president Rick Echevarria discusses the challenges of balancing data security with new technologies like blockchain and artificial intelligence.

It's tough for businesses to make use of data as it grows in volume and complexity, pouring in from multiple sources and systems. As organizations use new technologies like artificial intelligence and blockchain to process and store data, they have a responsibility to ensure data is protected.

"How do we enable those workloads to transform the business, and to the best of our abilities prevent security from getting in the way?" says Rick Echevarria, vice president of Intel's Software and Services Group, and general manager of Platform Security, in an interview with Dark Reading.

At Cyber Week, now taking place in Israel, Echevarria will discuss how he's navigating the challenges in new tech. Machine learning algorithms often require access to sensitive data but limiting access to the necessary data could limit the potential for AI. As for technical considerations related to blockchain, the security of information is as important as scalability.

Getting Smarter on AI  

When it comes to trends around AI, he says, there are two implementations: security for AI, where the focus is on protecting data and algorithms, and AI for security, in which tools leverage AI to detect advanced threats. Echevarria's focus is on security for AI.

"The reason for that is because people are deploying artificial intelligence today, and we want to make sure they're really aware of, and understand, the importance of security to underpin those workloads," he explains.

Echevarria points to two use cases in which Intel is addressing the AI challenge. The first is multi-party machine learning, which relies on the assumption that you can bring data to a central location. Tools like Intel's hardware-based Trusted Execution Environments grant access to critical data and ensure algorithms' integrity.

The second is federated learning, intended for applications where data can't be moved to a central location. In this case, data owners on the edges of the infrastructure work together to develop models themselves. Here, Echevarria says, many businesses encounter challenges.

"It's really about enabling access to data across organizations that really want to collaborate but sometimes because of privacy can't share data in the way they want to," he explains. The challenge is often seen in industries like healthcare and financial services, where teams may want to share threat intelligence but don't have the permission to share data.

Intel plans to support more extensive data sharing by teaming up with organizations like Docker, Fortanix, and Duality. With Docker, for example, a partnership will focus on making AI more secure and sharable by hardening containers with Intel's silicon-based security tech. Fortanix is adding to its Runtime Encryption tool to secure algorithms with Intel SGX enclaves.

Buckling Down on Blockchain

Some of the challenges in AI are consistent with challenges in blockchain, says Echevarria, who notes that Intel sees opportunity in blockchain as a platform. This week Intel is addressing scalability, security, and privacy of blockchain with updates in what it calls "Off-Chain Computing" along with partnerships with Enigma and SAP.

Intel has already teamed up with Microsoft to work on securing the blockchain. Back in May, the Microsoft Azure team, along with Microsoft Research, Intel, Windows, and the Microsoft Developer Tools division, announced it had been working to bring Intel's Trusted Execution Environments (Intel SGX, Virtualization Based Security) to the cloud.

Most recently, Intel partnered with SAP to build a blockchain proof-of-concept and improve efficiency for SAP's blockchain-as-a-service platform. Enigma has developed a privacy protocol that uses Intel SGX to secure data; it plans to integrate this into private smart contracts on the Ethereum public ledger.

Echevarria also speaks to plans to improve off-chain computing, in which transactions are not publicly accessible on the blockchain, specifically related to smart contracts. Businesses can do a better job of executing smart contracts in a more secure fashion, he says.

Related Content:

 Why Cybercriminals Attack: A DARK READING VIRTUAL EVENT Wednesday, June 27. Industry experts will offer a range of information and insight on who the bad guys are – and why they might be targeting your enterprise. Go here for more information on this free event.

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Microsoft President: Governments Must Cooperate on Cybersecurity
Kelly Sheridan, Staff Editor, Dark Reading,  11/8/2018
5 Reasons Why Threat Intelligence Doesn't Work
Jonathan Zhang, CEO/Founder of WhoisXML API and TIP,  11/7/2018
Why Password Management and Security Strategies Fall Short
Steve Zurier, Freelance Writer,  11/7/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Flash Poll
Online Malware and Threats: A Profile of Today's Security Posture
Online Malware and Threats: A Profile of Today's Security Posture
This report offers insight on how security professionals plan to invest in cybersecurity, and how they are prioritizing their resources. Find out what your peers have planned today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-2491
PUBLISHED: 2018-11-13
When opening a deep link URL in SAP Fiori Client with log level set to "Debug", the client application logs the URL to the log file. If this URL contains malicious JavaScript code it can eventually run inside the built-in log viewer of the application in case user opens the viewer and taps...
CVE-2018-2473
PUBLISHED: 2018-11-13
SAP BusinessObjects Business Intelligence Platform Server, versions 4.1 and 4.2, when using Web Intelligence Richclient 3 tiers mode gateway allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.
CVE-2018-2476
PUBLISHED: 2018-11-13
Due to insufficient URL Validation in forums in SAP NetWeaver versions 7.30, 7.31, 7.40, an attacker can redirect users to a malicious site.
CVE-2018-2477
PUBLISHED: 2018-11-13
Knowledge Management (XMLForms) in SAP NetWeaver, versions 7.30, 7.31, 7.40 and 7.50 does not sufficiently validate an XML document accepted from an untrusted source.
CVE-2018-2478
PUBLISHED: 2018-11-13
An attacker can use specially crafted inputs to execute commands on the host of a TREX / BWA installation, SAP Basis, versions: 7.0 to 7.02, 7.10 to 7.11, 7.30, 7.31, 7.40 and 7.50 to 7.53. Not all commands are possible, only those that can be executed by the <sid>adm user. The commands execut...