May 31, 2017 Jiqiang Lu with the GPGPU used to crack the A5/1 cipher. Credit: A*STAR Institute for Infocomm Research
Every day we store and transfer sensitive digital data, post personal information on social media, and provide valuable details to companies when we use their services. Keeping secure the 2.5 quintillion (2.5 million billion) bytes of data created every day from outside attack is a mammoth task. The potential for breaching security is vast, due to a plethora of available services and the many weak links that appear in the chain whenever data is moved. A further consideration is who should have access to data, taking the issue beyond technology into the social and political realm.
These challenges demand a huge global effort from computer technicians and researchers across the world. Research groups at A*STAR are using their technical expertise to monitor online services, identify vulnerable areas of data management, and develop software and hardware that keep data secure. Their work is not only defending data against attack, but also maintaining easy access to it for authorized users.
Managing mobiles
Arguably, the first line of defense against data misuse should be implemented in the Global System for Mobile Communications (GSM), the world's most widely-used wireless telephony technology. With a 90 per cent share of the market, around 4.5 billion customers rely on the security of GSM to protect their communications.
"GSM was first deployed 25 years ago and has become the global standard for mobile communications," says Jiqiang Lu at the A*STAR Institute for Infocomm Research (I2R).
The A5/1 stream cipher, the encryption scheme that GSM uses to protect data, has been successfully attacked before to test its security, but almost all the attacks were hypothetical in the sense of their impact on the real-world security of GSMthey either required a large amount of complex data or had a long attack time, meaning they could be mitigated and blocked by existing GSM security protocols. Lu and co-workers decided to investigate whether a detailed and fast-acting attack on the GSM A5/1 cipher could reveal fundamental weaknesses in the system. Using a computer setup costing just US$15,000 in 2013, the researchers employed a powerful algorithm to explore the A5/1 cryptosystem, and obtained 984 gigabytes of information about the system structure over 55 days. They used this information to launch attacks that pulled data from the GSM in just 9 secondsusually too quick for interception by security protocolsand illustrated that A5/1 would be vulnerable if it were to be attacked by sufficiently skilled hackers.
"The GSM should immediately upgrade its encryption algorithm to a stronger one," says Lu.
Containing the cloud
While Lu's team continue to protect our data as it flies around the global mobile network, another group at I2R which includes Jia Xu is examining the cloud storage providers that have revolutionized how we archive and share data. By entrusting large organizations to store multiple copies of our data on cloud servers around the world, we are freed from worrying about our phone, laptop or USB drive being lost, stolen or broken. But how can we be sure that these organizations will keep our data secure?
Xu and co-workers have designed cryptographic algorithms for cloud storage that not only protect the integrity of data, but also control who can access it.
"The core challenge in cloud storage is to balance three factors: efficiency, security, and usability," says Xu. "Cloud providers would like their services to be almost as efficient and low-cost as when no security features are implemented, while customers want the user interface to be as simple to use as possible." The research community is attempting to identify security vulnerabilities in existing cloud services, and to design new hardware and software solutions to resolve them.
Some security weaknesses arise from so-called deduplication techniques, which identify and remove duplicated copies of the same file, allowing cloud providers such as Dropbox to save server storage space and network bandwidth. Xu and co-workers identified severe security vulnerabilities in certain types of deduplication that could be exploited using attacking software.
Dropbox disabled cross-user deduplication in 2012. However, the new algorithms developed by Xu and the team will allow deduplication to be used alongside robust encryption, thereby improving efficiency while protecting data stored in the cloud.
The value of our data
Most of us have made large amounts of information available to organizations through shopping online and posting on social media. These activities have created extremely large datasets, known as Big Data, which can be analyzed to reveal human behavior patterns and trends. This valuable information is often sold to other organizations.
"Companies are hungry for more data, to enable them to better understand and profile users," says Lux Anantharaman who heads the Business Analytics Translation center in I2R. "They know the power of Big Data to provide targeted ads, known as personalized marketing, but profiling can also lead to price discrimination called personalized pricing, which most users are not aware of. For example, some airline websites price tickets differently based on the user's device operating systemMac OS users get charged more."
Anantharaman is concerned that most users are not aware of the value of their data, or the fact that when they use 'free' online services they are actually 'paying' for them with their data. Companies then explore the data with analytical computing tools and use the information, along with the latest insights on human behavior from social scientists and economists, to shape the choices offered to their customers.
"The 'big' keep accumulating more and more data about the 'small'," says Anantharaman. "We, the small, are slowly becoming aware of this fact, but generally we feel helpless and resigned about it. Moreover, government regulations haven't kept pace with technology, and often take the side of big organizations, doing a disservice to the users. For example, recent US government measures allow internet service providers to access a user's browsing history without the user's permission."
Anantharaman is adamant that the best way to overcome these difficulties is by educating users and improving government regulation. "This might sound odd from a technology person, but Big Data is not just about technology, it is about how data are used, which is a legal and social issue," he says. "For this reason, our research focuses not just on technological mechanisms, but also explores how regulations and education can help users better understand the power and pitfalls of Big Data privacy."
Quantum complications
While we grapple with data safety in the computing systems that we already use, other scientists are developing technology that could completely transform the field of data security for the devices of tomorrow. In contrast to ordinary computers whose logical 'bits' can only take values of 0 or 1, quantum computers use 'qubits' that can have values of 0, 1 or a combination of both values. This capability opens up an entirely new domain of logic and mathematics, allowing quantum computers to solve complex problems in a fraction of the time it would take a conventional machine. This revolution will arrive with great benefits, but will bring its own problems, as Leonid Krivitsky at the A*STAR Data Storage Institute explains:
"Many cryptography systems rely on hard problems such as prime factorizationthe fact that it is very difficult to figure out the prime factors of a given number. However, theoretical work has shown that the factorization problem could be solved very quickly using a quantum computer. So, once a universal quantum computer is built, it could hack ciphers which were previously thought to be unbreakable."
This might seem alarming, but there is no reason to panic. Functional quantum computers are still a long way off, and to counteract the potential threats, many groups around the world are contributing to the growing field of quantum cryptography, which will redefine our protocols of secure communication. In fact, the new cryptography algorithms made available by quantum computers could provide ultra-high data security long before any risks become a concern.
"I foresee the use of a quantum communication channel as a backup resource for highly sensitive transactions, where security is more important than the transmission speed," says Krivitsky.
For now, though, the challenge is to physically build a stable quantum computer. Krivitsky and co-workers are exploring the possibility of using tiny defects in synthetic diamonds to act as nodes which process and store quantum information.
"We place several diamonds on a single chip and communicate with optical links, similar to those which form the background of the internet," says Krivitsky. "Our innovations will enable transmission of quantum information over long distances and contribute to the development of a worldwide quantum network."
Safeguarding the future
The task of keeping our data secure is clearly a complicated and interdisciplinary challenge. A*STAR researchers are not only developing new technical initiatives, but also working at the forefront of global efforts to raise awareness of data security. By looking for chinks in the armor of global systems like GSM and cloud storage, educating the public about the commercial value of their data, and planning for the future paradigm shift that might be brought about by quantum computers, it is reassuring to know that the brightest minds at A*STAR are focused on keeping our data safe.
Explore further: A user-controlled file security scheme for cloud services
By securing data files with a 'need-to-know' decryption key, researchers at Singapore's Agency for Science, Technology and Research (A*STAR) have developed a way to control access to cloud-hosted data in real time, adding ...
While technologies that currently run on classical computers, such as Watson, can help find patterns and insights buried in vast amounts of existing data, quantum computers will deliver solutions to important problems where ...
Cloud storage services, like Dropbox and Gmail, may soon be able to better manage your content, giving you more storage capacity while still being unable to 'read' your data.
IBM announced today it has successfully built and tested its most powerful universal quantum computing processors. The first new prototype processor will be the core for the first IBM Q early-access commercial systems. The ...
We are producing more data than ever before, with more than 2.5 quintillion bytes produced every day, according to computer giant IBM. That's a staggering 2,500,000,000,000 gigabytes of data and it's growing fast.
The encryption codes that safeguard internet data today won't be secure forever.
Nest Labs is adding Google's facial recognition technology to a high-resolution home-security camera, offering a glimpse of a future in which increasingly intelligent, internet-connected computers can see and understand what's ...
A creator of the Android software powering most of the world's smartphones stepped into the competitive hardware market on Tuesday with a new handset called Essential.
Delivering packages with drones can reduce carbon dioxide emissions in certain circumstances as compared to truck deliveries, a new study from University of Washington transportation engineers finds.
A new interactive design tool developed by Carnegie Mellon University's Robotics Institute enables both novices and experts to build customized legged or wheeled robots using 3D-printed components and off-the-shelf actuators.
Apple is reportedly working on a chip called the Apple Neural Engine, which would be dedicated to carrying out artificial intelligence (AI) processing on its mobile devices.
A chess-playing robot stole the show as Asia's largest tech fair kicked off in Taiwan Tuesday with artificial intelligence centre stage.
Please sign in to add a comment. Registration is free, and takes less than a minute. Read more
Original post:
Ensuring the security of digital information - Phys.Org
- Setting up a Virtual Server on Ninefold - Video [Last Updated On: February 26th, 2012] [Originally Added On: February 26th, 2012]
- ScaleXtreme Automates Cloud-Based Patch Management For Virtual, Physical Servers [Last Updated On: February 28th, 2012] [Originally Added On: February 28th, 2012]
- Secure Cloud Computing Software manages IT resources. [Last Updated On: February 28th, 2012] [Originally Added On: February 28th, 2012]
- Dell unveils new servers, says not a PC company [Last Updated On: February 28th, 2012] [Originally Added On: February 28th, 2012]
- Wyse to Launch Client Infrastructure Management Software as a Service, Enabling Simple and Secure Management of Any ... [Last Updated On: February 28th, 2012] [Originally Added On: February 28th, 2012]
- As the App Culture Builds, Dell Accelerates its Shift to Services with New Line of Servers, Flash Capabilities [Last Updated On: February 28th, 2012] [Originally Added On: February 28th, 2012]
- Terraria - Cloud In A Ballon - Video [Last Updated On: February 28th, 2012] [Originally Added On: February 28th, 2012]
- Ethernet Alliance Interoperability Demo Showcases High-Speed Cloud Connections [Last Updated On: February 28th, 2012] [Originally Added On: February 28th, 2012]
- RSA and Zscaler Teaming Up to Deliver Trusted Access for Cloud Computing [Last Updated On: February 28th, 2012] [Originally Added On: February 28th, 2012]
- [NEC Report from MWC2012] NEC-Cloud-Marketplace - Video [Last Updated On: February 28th, 2012] [Originally Added On: February 28th, 2012]
- IBM SmartCloud Virtualized Server Recovery - Video [Last Updated On: February 28th, 2012] [Originally Added On: February 28th, 2012]
- BeyondTrust Launches PowerBroker Servers Windows Edition [Last Updated On: February 29th, 2012] [Originally Added On: February 29th, 2012]
- Ericsson joins OpenStack cloud infrastructure community [Last Updated On: February 29th, 2012] [Originally Added On: February 29th, 2012]
- ScaleXtreme Cloud-Based Patch Management Open for New Customers [Last Updated On: March 1st, 2012] [Originally Added On: March 1st, 2012]
- RootAxcess - Getting Started - Video [Last Updated On: March 1st, 2012] [Originally Added On: March 1st, 2012]
- How to Create a Terraria Server 1.1.2 (All Links Provided) - Video [Last Updated On: March 1st, 2012] [Originally Added On: March 1st, 2012]
- Dell #1 in Hyperscale Servers (Steve Cumings) - Video [Last Updated On: March 1st, 2012] [Originally Added On: March 1st, 2012]
- Managing SAP on Power Systems with Cloud technologies delivers superior IT economics - Video [Last Updated On: March 1st, 2012] [Originally Added On: March 1st, 2012]
- AMD Acquires Cloud Server Maker SeaMicro for $334M USD [Last Updated On: March 3rd, 2012] [Originally Added On: March 3rd, 2012]
- Web Host 1&1 Provides More Flexibility with Dynamic Cloud Server [Last Updated On: March 3rd, 2012] [Originally Added On: March 3rd, 2012]
- Leap Day brings down Microsoft's Azure cloud service [Last Updated On: March 3rd, 2012] [Originally Added On: March 3rd, 2012]
- RightMobileApps White Label Program - Video [Last Updated On: March 3rd, 2012] [Originally Added On: March 3rd, 2012]
- bzst server ban #2 - Video [Last Updated On: March 3rd, 2012] [Originally Added On: March 3rd, 2012]
- “Cloud storage served from an array would cost $2 a gigabyte” [Last Updated On: March 6th, 2012] [Originally Added On: March 6th, 2012]
- More Flexibility with the 1&1 Dynamic Cloud Server [Last Updated On: March 6th, 2012] [Originally Added On: March 6th, 2012]
- Hub’s future jobs may be in cloud [Last Updated On: March 6th, 2012] [Originally Added On: March 6th, 2012]
- Cloud computing growing jobs, says Microsoft [Last Updated On: March 6th, 2012] [Originally Added On: March 6th, 2012]
- TurnKey Internet Launches WebMatrix, a New Application in Partnership with Microsoft [Last Updated On: March 6th, 2012] [Originally Added On: March 6th, 2012]
- Cebit 2012: SAP Cloud Computing Strategy - Introduction - Video [Last Updated On: March 6th, 2012] [Originally Added On: March 6th, 2012]
- Dome9 Security Launches Industry's First Free Cloud Security for Unlimited Number of Servers [Last Updated On: March 7th, 2012] [Originally Added On: March 7th, 2012]
- Servers Are Refreshed With Intel's New E5 Chips [Last Updated On: March 7th, 2012] [Originally Added On: March 7th, 2012]
- Samsung's AllShare Play pushes pictures from phone to cloud and TV [Last Updated On: March 7th, 2012] [Originally Added On: March 7th, 2012]
- Google drops the price of Cloud Storage service [Last Updated On: March 7th, 2012] [Originally Added On: March 7th, 2012]
- New Intel Server Technology: Powering the Cloud to Handle 15 Billion Connected Devices [Last Updated On: March 7th, 2012] [Originally Added On: March 7th, 2012]
- Swisscom IT Services Launches Cloud Storage Services Powered by CTERA Networks [Last Updated On: March 7th, 2012] [Originally Added On: March 7th, 2012]
- KineticD Releases Suite of Cloud Backup Offerings for SMBs [Last Updated On: March 7th, 2012] [Originally Added On: March 7th, 2012]
- First Look: Samsung Allshare Play - Video [Last Updated On: March 7th, 2012] [Originally Added On: March 7th, 2012]
- Bill The Server Guy Introduces the New Intel XEON e5-2600 (Romley) Server CPU's - Video [Last Updated On: March 7th, 2012] [Originally Added On: March 7th, 2012]
- New Cisco servers have Intel Xeon E5 inside [Last Updated On: March 8th, 2012] [Originally Added On: March 8th, 2012]
- Cisco rolls out UCS servers with Intel Xeon E5 chips [Last Updated On: March 8th, 2012] [Originally Added On: March 8th, 2012]
- From scooters to servers: The best of Launch, Day One [Last Updated On: March 8th, 2012] [Originally Added On: March 8th, 2012]
- Computer Basics: What is the Cloud? - Video [Last Updated On: March 9th, 2012] [Originally Added On: March 9th, 2012]
- Could the digital 'cloud' crash? [Last Updated On: March 10th, 2012] [Originally Added On: March 10th, 2012]
- Dome9 Security Launches Free Cloud Security For Unlimited Number Of Servers [Last Updated On: March 10th, 2012] [Originally Added On: March 10th, 2012]
- Cloud computing 'made in Germany' stirs debate at CeBIT [Last Updated On: March 11th, 2012] [Originally Added On: March 11th, 2012]
- New Key Technology Simplifies Data Encryption in the Cloud [Last Updated On: March 11th, 2012] [Originally Added On: March 11th, 2012]
- Can a private cloud drive energy efficiency in datacentres? [Last Updated On: March 12th, 2012] [Originally Added On: March 12th, 2012]
- Porticor's new key technology simplifies data encryption in the cloud [Last Updated On: March 12th, 2012] [Originally Added On: March 12th, 2012]
- Borders + Gratehouse Adds Three New Clients in Cloud Sector [Last Updated On: March 12th, 2012] [Originally Added On: March 12th, 2012]
- Dell to invest $700 mn in R&D, unveils 12G servers [Last Updated On: March 13th, 2012] [Originally Added On: March 13th, 2012]
- Defiant Kaleidescape To Keep Shipping Movie Servers [Last Updated On: March 13th, 2012] [Originally Added On: March 13th, 2012]
- Data Centre Transformation Master Class 3: Cloud Architecture - Video [Last Updated On: March 13th, 2012] [Originally Added On: March 13th, 2012]
- DotNetNuke Tutorial - Great hosting tool - PowerDNN Control Suite - part 1/3 - Video #310 - Video [Last Updated On: March 13th, 2012] [Originally Added On: March 13th, 2012]
- Cloud Computing - 28/02/12 - Video [Last Updated On: March 13th, 2012] [Originally Added On: March 13th, 2012]
- SYS-CON.tv @ 9th Cloud Expo | Nand Mulchandani, CEO and Co-Founder of ScaleXtreme - Video [Last Updated On: March 13th, 2012] [Originally Added On: March 13th, 2012]
- Oni Launches New Cloud Services for Enterprises Using CA Technologies Cloud Platform [Last Updated On: March 14th, 2012] [Originally Added On: March 14th, 2012]
- SmartStyle Advanced Technology - Video [Last Updated On: March 14th, 2012] [Originally Added On: March 14th, 2012]
- SmartStyle Infrastructure - Video [Last Updated On: March 14th, 2012] [Originally Added On: March 14th, 2012]
- The Hidden Risk of a Meltdown in the Cloud [Last Updated On: March 14th, 2012] [Originally Added On: March 14th, 2012]
- FireHost Launches Secure Cloud Data Center in Phoenix, Arizona [Last Updated On: March 14th, 2012] [Originally Added On: March 14th, 2012]
- Panda Security Launches New Channel Partner Recruitment Campaign: "Security to the Power of the Cloud" [Last Updated On: March 14th, 2012] [Originally Added On: March 14th, 2012]
- NetSTAR, Inc. Announces Safe and Secure Web Browsers for iPhones, iPads, and Android Devices [Last Updated On: March 14th, 2012] [Originally Added On: March 14th, 2012]
- Amazon Cloud Powered by 'Almost 500,000 Servers' [Last Updated On: March 15th, 2012] [Originally Added On: March 15th, 2012]
- NetSTAR Announces Secure Web Browsers For iPhones, iPads, And Android Devices [Last Updated On: March 15th, 2012] [Originally Added On: March 15th, 2012]
- Be Prepared For When the Cloud Really Fails [Last Updated On: March 15th, 2012] [Originally Added On: March 15th, 2012]
- Dr. Cloud explains dinCloud's hosted virtual server solution - Video [Last Updated On: March 15th, 2012] [Originally Added On: March 15th, 2012]
- New estimate pegs Amazon's cloud at nearly half a million servers [Last Updated On: March 15th, 2012] [Originally Added On: March 15th, 2012]
- Amazon’s Web Services Uses 450K Servers [Last Updated On: March 15th, 2012] [Originally Added On: March 15th, 2012]
- Saving File On Internet - Cloud Computing - Video [Last Updated On: March 15th, 2012] [Originally Added On: March 15th, 2012]
- DotNetNuke Tutorial - Great hosting tool - PowerDNN Control Suite - part 2/3 - Video #311 - Video [Last Updated On: March 15th, 2012] [Originally Added On: March 15th, 2012]
- Linux servers keep growing, Windows & Unix keep shrinking [Last Updated On: March 15th, 2012] [Originally Added On: March 15th, 2012]
- Cloud Desktop from Compute Blocks - Video [Last Updated On: March 16th, 2012] [Originally Added On: March 16th, 2012]
- Amazon EC2 cloud is made up of almost half-a-million Linux servers [Last Updated On: March 17th, 2012] [Originally Added On: March 17th, 2012]
- HP trots out new line of “self-sufficient” servers [Last Updated On: March 17th, 2012] [Originally Added On: March 17th, 2012]
- Cloud Web Hosting Reviews - Australian Cloud Hosting Providers - Video [Last Updated On: March 17th, 2012] [Originally Added On: March 17th, 2012]
- Using Porticor to protect data in a snapshot scenario in AWS - Video [Last Updated On: March 17th, 2012] [Originally Added On: March 17th, 2012]
- CDW - Charles Barkley - New Office - Video [Last Updated On: March 17th, 2012] [Originally Added On: March 17th, 2012]
- Nearly a Half Million Servers May Power Amazon Cloud [Last Updated On: March 17th, 2012] [Originally Added On: March 17th, 2012]
- Morphlabs CEO Winston Damarillo talks about their mCloud Rack - Video [Last Updated On: March 20th, 2012] [Originally Added On: March 20th, 2012]
- AMD reaches for the cloud with new server chips [Last Updated On: March 20th, 2012] [Originally Added On: March 20th, 2012]