Home | About | RSS Feed | Contact and Publicity Guidelines | Comment Policy the Law, the Universe, and Everything 

advertise-here4


Slip Opinions


Whatever happened to Henry Simons? (fp)

Wow -- that's some very scary poll results (kw)

The scarlet ankle bracelet. (fp)

Every good article should have one idea. (fp)

Family values in market turnover culture. (fp)

Banks really create value: probably $58 billion in overdraft fees & credit card penalties in 2009. (fp)

A Citizens United dream: Exxon could have deployed 10% of its 2008 profits to outspend every presidential and senatorial candidate that year. (fp)

Eternal Earth-Bound Pets promises to adopt your pet if you are raptured. (fp)

Habermas doesn't tweet, but does interview well. (fp)

Lessig on Google, copyright, orphans, and the future of access to information. (kw)

Our Podcast

Subscribe to Law Talk

law-rev-contents2.jpg


  • Posts by Author

  • Categories

  • Archives


  • Recent Comments

    • Kristina on Spring 2010: Is the Window Open?

    • PrometheeFeu on The Advantages and Disadvantages of Rewards

    • PoNyman on Very scary poll results

    • Civ Pro King on Privacy Rights in Death Photos: Catsuouras Case Decided

    • ParatrooperJJ on Privacy Rights in Death Photos: Catsuouras Case Decided

    • Lotta on The Take Away About Take Home Exams

    • Alan on Constitutional Rorschach Test (or Zen Koan)

    • Colin Crowe on The Take Away About Take Home Exams

    • Glomarization on Links and short thoughts on Amazonfail

    • Vinca on Book Review: Divergent Opinions: Why Community Matters — A Review of Sunstein’s Going to Extremes

    • A.J. Sutter on My Letter to the Economist on Climate Change

    • Keri Brooks on Spring 2010: Is the Window Open?

    • Illinois on Spring 2010: Is the Window Open?

    • Ken Rhodes on Constitutional Rorschach Test (or Zen Koan)

    • Ken Rhodes on My Letter to the Economist on Climate Change

  •  

    Site Meter

New Developments in Cryptography and Privacy

posted by Deven Desai

ofb_encryptionAccording to Help Net Security, Craig Gentry, a researcher at IBM, appears to have found a way to allow “the deep and unlimited analysis of encrypted information – data that has been intentionally scrambled – without sacrificing confidentiality.” The solution involves a an “ideal lattice.” I’ll leave the explanation of all the math to the math/computer science folks. As the Help Net article notes, the solution seems to enable some great advantages for anyone providing cloud computing for:

computer vendors storing the confidential, electronic data of others will be able to fully analyze data on their clients’ behalf without expensive interaction with the client, and without seeing any of the private data. With Gentry’s technique, the analysis of encrypted information can yield the same detailed results as if the original data was fully visible to all.

It all sounds wonderful. One could have encrypted data and let others data mine while maintaining anonymity or privacy. Yet, something seemed odd to me. So I did what lawyers do, I called someone who knew more about computer science and asked for some help. That person explained that yes this could mean one could query an encrypted database without decrypting the data. The example to consider is a database of book purchases. One could ask how many people bought both book A and book B and see that result without ever seeing what a specific person purchased. Great, right? Not so fast.

As this person reminded me, with other sources of information one can figure out what a specific person did. That reminded me of the AOL debacle. With a little work, people were able to figure out who the anonymous subjects were.

All of which highlights that privacy is not binary. The cluster of information and the ability to analyze it seems often, if not always, to lead to problems about the use of information. So if this breakthrough allows a company or the government to claim that we should remain calm and all is well, we may want to remain clam but show how all may not be well. A few regulations about the use of the data even if supposedly anonymous, might allow the beneficial aspects of the solution to thrive while limiting the harms that can occur.

Image: WikiCommons
By: Gwenda; License: Public Domain
(My apologies to CS folks if the image does not match the breakthrough’s area of encryption)


 June 30, 2009 at 11:35 am  Tags: cloud computing, cryptography, Privacy  Posted in: Cyberlaw, Google & Search Engines, Privacy, Privacy (Consumer Privacy), Privacy (Electronic Surveillance), Privacy (Law Enforcement), Technology   Print This Post Print This Post

Responses (7)

  1. Steven M. Bellovin - June 30, 2009 at 12:16 pm

    Your overall point is very correct — privacy at one layer does not mean protection at another layer.

    It’s also way too soon to start worrying about the practical applications. To quote (with permission) some email sent by a colleague of mine:

    It is an awesome result — the first ever fully homomorphic encryption, a primitive that is *very* powerful for tons of applications (hence the hype), and something many believed is not possible (or at least very difficult to achieve). The only catch is, he succeeded to do this primitive with very computationally expensive crypto, so it’s not practical yet. In other words — the primitive itself has a ton of very practical applications.

    The primitive was implemented not efficiently enough.The hope is that this will inspire improvements and follow on work, now that we know it’s possible, that will make it practical. But there is a long way to go.

    (And no, the diagram bears no relation to this work; it shows a so-called “mode of operation” of a standard cipher like the Advanced Encryption Standard, and is about 30 years old…)

  2. Deven - June 30, 2009 at 2:29 pm

    Steven

    Thanks. First I agree, quite an accomplishment. Second, I am not sure that one has to wait to think about the possible problems. We often wait too long and react rather than come up with a better balance. NOW I think you are saying that there should not be a regulation that would stop this type of research and progress in the field. If so, amen. That type of reaction would be foolish.

    Last, thanks for the clarification as to what the image is about. I was not trying to show the breakthrough. I was hoping that the image is of something to which the breakthrough might apply. That being said, do you have any guidance as to what would be a better image? In other words an image of the type of encryption that the work relates to? Thanks in advance for any and all help.

  3. joe - June 30, 2009 at 4:04 pm

    Hi! (and greetings fellow CITP resident… at least a pre-greeting for when you arrive!)

    Just to clarify, and I’m by no means an expert: homomorphic encryption is a neat type of encryption where a mathematical operation on the cyphertext (the encrypted stuff) translates to the same operation in the cleartext (the unencrypted data). So, if I encrypt a value like “1″ and then “add” the encrypted result to itself, when I decrypt the value will be “2″. In general, this should work for a set of operations, and I’m not sure the database example above is right (it depends on what one means by “query”).

    Oh, and there’s no “image” that I can imagine for this… I guess a candidate would be one person locking something in a box, someone else performing something with the box to change it and the original person opening the new box to find something different inside… but that is not even close. I give up. :)

  4. Steven M. Bellovin - June 30, 2009 at 5:29 pm

    You’re quite correct about what homomorphic encryption is, but that form has been known for ~30 years, and is no more expensive than public key encryption. What’s new here is fully homomorphic encryption, where you can do multiplication as well as addition. My cryptotheoretician friends tell me it’s a tremendous theoretical achievement — but it may never be practical.

    The scheme is based on something called “ideal lattices”. I have no idea what they are; my courses in that type of math were very long ago. That said, they’re a special form of lattice. I could explain them, but there’s not much point… (I did put a picture of a simple lattice at http://www.cs.columbia.edu/~smb/lattice.png — feel free to use it, but I have no idea if it’s an ideal lattice, nor do I know if it’s in any way related to the kinds of lattices used for this scheme.)

    The best analogy I can give is Roman numerals. To a first approximation, any (reasonably small) number can be written that way. You can do arithmetic with them, and then translate the result back and get the proper answer. To someone who didn’t know the scheme, trying to understand why XXVII+XIX was XLVI would be rather difficult. (And efficiency? Imagine trying to do long division in Roman numerals!)

    Database searching is one of the simpler things that can, in principle, be done with a fully homomorphic encryption scheme. There are many others; I’ll be happy to describe some, publicly or privately, if anyone is interested. Various forms of privacy-protecting searches are of great interest to various parts of the government — indeed, it’s one of my own research areas, funded by just such a part. Their interest is dual: they do indeed want to protect privacy, but a privacy-preserving scheme is also a more secure scheme, since if the database is compromised the attacker can learn much less.

    As for the larger question — Deven is quite correct; one should never be sanguine. But the real reason to think about the issue is not this new development, but what’s already here…

  5. Jens - July 1, 2009 at 7:34 am

    Privacy-preserving data-mining? Take a look at the work of Professor Chris Clifton …

  6. kswong - July 6, 2009 at 8:58 am

    Hi All,

    Is it possible for us to compare two ciphertexts encrypted with the same key without decryption?

  7. joe - July 9, 2009 at 6:51 am

    BTW, Schneier just wrote a brief article on this development: http://www.schneier.com/blog/archives/2009/07/homomorphic_enc.html

Leave a Reply

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word


  • « Previous post
  • Next post »

Authors

Daniel J. Solove
Kaimipono Wenger
Dave Hoffman
Nate Oman
Frank Pasquale
Deven Desai
Danielle Citron
Lawrence Cunningham
Sarah Waldeck
Jaya Ramji-Nogales
Solangel Maldonado
Gerard Magliocca

Guests

Adam Benforado
Mark Edwards
Michelle Harner
Kristin Johnson
Jeffrey Kahn
Alex Kreit
Viva Moffat
Adam Steinman










Previous Guests

Michael Abramowicz
Michelle Adams
Robert Ahdieh
Michelle Anderson
Laura Appleman
Ann Bartow
Francesca Bignami
Jeremy Blumenthal
Kathleen Boozang
Bruce Boyden
Donald Braman
Al Brophy
Neil H. Buchanan
Bill Burke-White
Scott Burris
Paul Butler
Naomi Cahn
Anupam Chander
Miriam Cherry
Jack Chin
Jennifer Collins
Thomas Crocker
Allison Danner
Brannon Denning
Deven Desai
Mike Dimino
Mark Edwards
David Fagundes
Christine Haight Farley
Kim Ferzan
Dan Filler
Michael Froomkin
Amanda Frost
Timothy Glynn
Rachel Godsil
Eric Goldman
David Gray
Craig Green
Tristin Green
Jeffrey Harrison
Erica Hashimoto
Carissa Hessick
Laura Heymann
Robert Hillman
Christine Hurt
Darian Ibrahim
John Ip
Kevin Johnson
Dan Kahan
Brian Kalt
Sam Kamin
Michael Kang
Chimène Keitner
Orin Kerr
Nancy Kim
Heidi Kitrosser
Adam Kolber
Russell Korobkin
Anita S. Krishnakumar
Susan Kuo
Greg Lastowka
Sarah Lawsky
Erik Lillquist
Jeff Lipshaw
Jonathan Lipson
Jacqueline Lipton
Joseph Liu
Michael Madison
Solangel Maldonado
Jason Mazzone
Linda McClain
William McGeveran
Salil Mehra
Carrie Menkel-Meadow
Max Minzner
Scott Moss
Eric Muller
Jaya Ramji-Nogales
Helen Norton
Elizabeth Nowicki
Paul Ohm
Michael O'Shea
David Opderback
Kristen Osenga
Rafael Pardo
Marcy Peek
Eduardo Peñalver
Robert Percival
David Post
Shruti Rana
Geoffrey Rapp
Neil Richards
Lori Ringhand
Alice Ristroph
Susan Scafidi
Paul Secunda
Jonathan Siegel
Jessica Silbey
Peter Smith
Charles Sullivan
Rick Swedloff
Steph Tai
Andrew Taslitz
Robert Tsai
Jenia Turner
Steve Vladeck
Spencer Weber Waller
Howard Wasserman
Melissa Waters
Frank Wu
Alfred Yen
Corey Yung
David Zaring
Timothy Zick
Michael Zimmer
Jonathan Zittrain

Ownership

Concurring Opinions is a
general-interest legal blog
operated by Concurring
Opinions LLC, a Pennsylvania
Limited Liability Corporation.

Blogroll

Above the Law
ACS Blog
Althouse
Balkinization
Becker-Posner Blog
BlackProf
BoingBoing
Chicago Law Faculty Blog
Conglomerate
CrimLaw
Crime & Federalism
CrimProf Blog
Crooked Timber
Discourse.net
Dorf on Law
Election Law
Emergent Chaos
The Faculty Lounge
Feminist Law Profs
43(B)log
Freakonomics Blog
Freedom to Tinker
Google Blogoscoped
How Appealing
Ideoblog
Info/Law
Instapundit.com
Juris Novus
Jurisdynamics
Law and Humanities Blog
Law and Letters
Law Librarian Blog
Legal Profession Blog
Legal Theory Blog
Legal Times Blog
Leiter Reports
Brian Leiter's Law School Reports
Lessig Blog
Madisonian Theory
Media Law Blog
Mirror of Justice
The Moderate Voice
National Security Advisors
Opinio Juris
Point of Law
PrawfsBlawg
ProfessorBainbridge.com
Property Prof Blog
Red Tape Chronicles
The Right Coast
Schneier on Security
SCOTUSBlog
Security Dilemmas
Sentencing Law and Policy
Simple Justice
Sivacracy.net
The Situationist
Susan Crawford
TalkLeft
Talking Points Memo
TaxProf Blog
Tech & Marketing Law
Truth on the Market
Volokh Conspiracy
WorkPlace Prof Blog
WSJ Law Blog
Wonkette
The Yin Blog


© Concurring Opinions

Powered by WordPress