Cloud

6/20/2018
02:12 PM
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

Intel VP Talks Data Security Focus Amid Rise of Blockchain, AI

Intel vice president Rick Echevarria discusses the challenges of balancing data security with new technologies like blockchain and artificial intelligence.

It's tough for businesses to make use of data as it grows in volume and complexity, pouring in from multiple sources and systems. As organizations use new technologies like artificial intelligence and blockchain to process and store data, they have a responsibility to ensure data is protected.

"How do we enable those workloads to transform the business, and to the best of our abilities prevent security from getting in the way?" says Rick Echevarria, vice president of Intel's Software and Services Group, and general manager of Platform Security, in an interview with Dark Reading.

At Cyber Week, now taking place in Israel, Echevarria will discuss how he's navigating the challenges in new tech. Machine learning algorithms often require access to sensitive data but limiting access to the necessary data could limit the potential for AI. As for technical considerations related to blockchain, the security of information is as important as scalability.

Getting Smarter on AI  

When it comes to trends around AI, he says, there are two implementations: security for AI, where the focus is on protecting data and algorithms, and AI for security, in which tools leverage AI to detect advanced threats. Echevarria's focus is on security for AI.

"The reason for that is because people are deploying artificial intelligence today, and we want to make sure they're really aware of, and understand, the importance of security to underpin those workloads," he explains.

Echevarria points to two use cases in which Intel is addressing the AI challenge. The first is multi-party machine learning, which relies on the assumption that you can bring data to a central location. Tools like Intel's hardware-based Trusted Execution Environments grant access to critical data and ensure algorithms' integrity.

The second is federated learning, intended for applications where data can't be moved to a central location. In this case, data owners on the edges of the infrastructure work together to develop models themselves. Here, Echevarria says, many businesses encounter challenges.

"It's really about enabling access to data across organizations that really want to collaborate but sometimes because of privacy can't share data in the way they want to," he explains. The challenge is often seen in industries like healthcare and financial services, where teams may want to share threat intelligence but don't have the permission to share data.

Intel plans to support more extensive data sharing by teaming up with organizations like Docker, Fortanix, and Duality. With Docker, for example, a partnership will focus on making AI more secure and sharable by hardening containers with Intel's silicon-based security tech. Fortanix is adding to its Runtime Encryption tool to secure algorithms with Intel SGX enclaves.

Buckling Down on Blockchain

Some of the challenges in AI are consistent with challenges in blockchain, says Echevarria, who notes that Intel sees opportunity in blockchain as a platform. This week Intel is addressing scalability, security, and privacy of blockchain with updates in what it calls "Off-Chain Computing" along with partnerships with Enigma and SAP.

Intel has already teamed up with Microsoft to work on securing the blockchain. Back in May, the Microsoft Azure team, along with Microsoft Research, Intel, Windows, and the Microsoft Developer Tools division, announced it had been working to bring Intel's Trusted Execution Environments (Intel SGX, Virtualization Based Security) to the cloud.

Most recently, Intel partnered with SAP to build a blockchain proof-of-concept and improve efficiency for SAP's blockchain-as-a-service platform. Enigma has developed a privacy protocol that uses Intel SGX to secure data; it plans to integrate this into private smart contracts on the Ethereum public ledger.

Echevarria also speaks to plans to improve off-chain computing, in which transactions are not publicly accessible on the blockchain, specifically related to smart contracts. Businesses can do a better job of executing smart contracts in a more secure fashion, he says.

Related Content:

 Why Cybercriminals Attack: A DARK READING VIRTUAL EVENT Wednesday, June 27. Industry experts will offer a range of information and insight on who the bad guys are – and why they might be targeting your enterprise. Go here for more information on this free event.

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Veterans Find New Roles in Enterprise Cybersecurity
Kelly Sheridan, Staff Editor, Dark Reading,  11/12/2018
Understanding Evil Twin AP Attacks and How to Prevent Them
Ryan Orsi, Director of Product Management for Wi-Fi at WatchGuard Technologies,  11/14/2018
7 Free (or Cheap) Ways to Increase Your Cybersecurity Knowledge
Curtis Franklin Jr., Senior Editor at Dark Reading,  11/15/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Flash Poll
Online Malware and Threats: A Profile of Today's Security Posture
Online Malware and Threats: A Profile of Today's Security Posture
This report offers insight on how security professionals plan to invest in cybersecurity, and how they are prioritizing their resources. Find out what your peers have planned today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-19349
PUBLISHED: 2018-11-17
In SeaCMS v6.64, there is SQL injection via the admin_makehtml.php topic parameter because of mishandling in include/mkhtml.func.php.
CVE-2018-19350
PUBLISHED: 2018-11-17
In SeaCMS v6.6.4, there is stored XSS via the member.php?action=chgpwdsubmit email parameter during a password change, as demonstrated by a data: URL in an OBJECT element.
CVE-2018-19341
PUBLISHED: 2018-11-17
The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information via a U3D sample because of a "Read Access Violation near NULL starting at FoxitReader...
CVE-2018-19342
PUBLISHED: 2018-11-17
The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information via a U3D sample because of a "Read Access Violation starting at U3DBrowser+0x00000000...
CVE-2018-19343
PUBLISHED: 2018-11-17
The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (out-of-bounds read), obtain sensitive information, or possibly have unspecified other impact via a U3D sample because of a "Data from Faul...