Ads by TechWords

See your link here
Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
 

IBM Almaden Research Center's Sovereign Information Integration Privacy-Minded Security

Double-encrypted data allows for security checks, but without violating privacy rules.

September 12, 2005 12:00 PM ET

Computerworld - Information sharing is a thorny subject these days. The whole idea of the Internet is to make anything available to anyone in real time. Instant access is the mantra of the modern world. Yet this philosophy collides solidly with privacy rights and the need for security.

Take the case of an airline working with the government on antiterrorist issues. The airline's passenger lists might have to be compared to a Homeland Security terrorism watch list, yet both sides have a vested interest in protecting their databases. The authorities really need to know only that Johnny Dangerous is on Flight 450 and should never find out the names of the other passengers (thereby protecting their privacy and the airline from privacy violation complaints), and the airline should never get to see who else is on the government watch list. Problems like this make security a real challenge today.

"Security vs. privacy is a false choice," says Rakesh Agrawal, IBM fellow at the IBM Almaden Research Center in San Jose. "By making technological advances, we can have both without impeding the flow of information."

IBM's Sovereign Information Integration (SII) technology is an attempt to solve this dilemma. It enables companies to gain value from their data while complying with privacy policies and legislation. Current approaches to information integration -- centralized data warehouses and federations - are based on the assumption that all of the information in each database can be revealed to the other databases. This may not actually be desired, however, in cases such as those involving medical information, national security, law enforcement, intellectual property law, and business networks and partnerships.

"IBM's solution is for each party to encrypt its own data and then send it to the other party to encrypt again," says David Rabb, a consultant at Rabb Associates Inc., a Chappaqua, N.Y.-based company that evaluates database technologies. "If the encryption methods are commutative, meaning you get the same result whichever encryption is applied first, then a name or ID number appearing in both files would have the same double-encrypted value and be recognized as a match."

Thus, double-encrypted data can be compared without violating disclosure rules. Nonmatching values, on the other hand, would be unreadable by either party, because they would be protected by the other party's encryption. Furthermore, this innovative encryption technique also enables information sharing via a Web-based query interface.

The system was developed by Agrawal along with a team consisting of Ramakrishnan Srikant, Alexandre Evfimievski and Dmitri Asonov. It was funded out of the $5 billion that IBM invests in research and development annually. SII is the functional component of IBM's Hippocratic Database, which ties into health care applications to let users indicate who should have access to certain patient data.

Agrawal says his team is now exploring the use of commercially available hardware to speed up the query execution of SII, as well as identifying additional application areas for the technology.

"We are validating technology with our customers and would like to make the technology available through customer partnerships as well as product and service offerings," he says. "We expect that SII will facilitate innovative new methods of business collaboration sensitive to privacy and regulatory issues."

Robb is a Computerworld contributing writer in Los Angeles.



Additional Resources

POLL RESULTS
Accelerate your knowledge of the IT world you inhabit by viewing the results of a series of polls taken by your IT peers. These polls of 100+ IT professionals each are available for full viewing. They cover key topics such as virtualization, processor performance, green IT, cloud computing and many others. Be a part of the buzz.
WHITE PAPER
Technology is complex. Keeping it running productively shouldn't be. To that end, you want to minimize the number of solutions needed in-house to simplify operations, maintenance, and support. Kodak offers a best-practices model. One company provides support for both scanner and software, for fast problem resolution without vendor finger-pointing. Download now!
WHITE PAPER
Utilizing demand intelligence improves the precision of pricing, product assortments, channel/store placement, and promotion, which are all essential for sustainable revenue management performance. Learn more, download this free whitepaper today.

White Papers & Webcasts

Differentiating With Technical Support: JBoss Customer Support Study
JBoss' expert technical support services is clearly acknowledged by its client base. The comprehensive nature by which their service is unsurpassed. Every category...  

Managing And Protecting Your Ever Increasing Mobile Assets
(Source: Absolute Software) Your users are becoming more mobile each day. This is great for productivity - yet challenging for IT control. Natalie...

The JBoss SOA Assessment Tool: Spend Less, Do More
SOA does not have to be overly complex or expensive. The JBoss SOA Assessment Tool can help you chart a course to a...  

IDC Webcast: Linux Adoption in a Global Recession
Join Al Gillen from IDC and Michael Applebaum from Novell in this on-demand webcast to see how Linux has emerged as an even...

The CIO's New Guide to Design of Global IT Infrastructure
Is it possible to eliminate the impact of distance? This paper explores the 5 key principles successful CIOs are using to redesign IT...  

Novell Opens PR Video
Is the Linux desktop for me? Customers are looking for ways to be more flexible and save money. Using Linux offers a great...

IBM Lotus Notes Performance Brief
This is a Performance Brief that illustrates how Riverbed Steelhead appliances accelerate Lotus Notes R7....  

2 Minutes to IT workload automation
Take just 2 minutes to watch this short CONTROL-M flash video. Well show you how BMC CONTROL-M can put money back into your...

Business Value of Performance IDC Whitepaper
Are you looking for a comprehensive solution that addresses insufficient or congested bandwidth, impaired application performance, slow remote backup and replication or obstacles...  

Security Configuration Management
In this web video, follow along with Jim Hansen, Senior Product Manager with Big Fix, as he explains why Security Configuration Management is...