Box launches new service for security-conscious enterprises

A new EKM offering lets organizations retain control over their encryption

Few would deny the appeal of the cloud for enterprise file storage and sharing, but for some organizations -- particularly those in heavily regulated industries -- security concerns can outweigh those potential benefits.

Enter Box Enterprise Key Management (EKM), a new solution now in beta that aims to give businesses the ability to maintain exclusive control over their encryption keys.

Hard on the heels of its initial public offering late last month, Box on Tuesday unveiled Box EKM, a service that targets security-conscious organizations with technology delivered in partnership with Amazon Web Services and Gemalto.

"In the old days, if you wanted to encrypt and protect data inside your organization, IT could set it up," said Rand Wacker, Box's vice president of enterprise products. "But if you tried to share something across organizations, that's usually where stuff broke down."

Aimed at users in highly regulated industries such as finance, government, legal and healthcare as well as geographies such as Germany, Box EKM is designed to help enterprises reap the rewards of cloud computing while still maintaining control over encryption, he said.

All content stored on Box is already encrypted, Wacker noted. What's new is that Box EKM externalizes management of the associated encryption keys.

"When a customer uploads a file, it's encrypted with a unique key for that file," he said. "What happens today is that the file-specific key is encrypted by an internal key-management system."

With the new capability, however, customers get control over that key and the auditing of it.

The key infrastructure is provided by a dedicated AWS CloudHSM appliance leveraging Gemalto's SafeNet Hardware Security Modules (HSM) for key encryption and protection. Customers retain full control of their keys and cryptographic operations while Amazon manages and maintains the hardware.

Box EKM not only separates encrypted data and the keys used to manage it, but also creates an audit log for the customer's review.

The security controls are designed to be transparent to users while giving customer IT and audit teams full visibility, Wacker said. Neither Box nor Amazon have access, he stressed.

Toyota Motor Sales and World Bank Group are among the organizations testing the new capability, Wacker said.

General availability of the new service is expected this spring. Pricing will be on a per-user basis.

"Right now this targets large enterprises with some pretty hefty resources," said Rich Mogull, CEO with Securosis.

"I do think it is highly appealing for them, especially in financials and other regulated industries," Mogull said. "It's also appealing to enterprises concerned with government or cloud-provider snooping."

Eventually, "bring your own key" will become common in cloud computing, he added, though it could take many years.

"I've heard at least one of the proxy-based encryption vendors for SaaS is doing somewhere around $50M in business, so clearly there is a market," Mogull said -- "especially for something that won't break the SaaS apps functionality like proxies do."

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags cloud computinginternetsoftwareapplicationsBox.net

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Katherine Noyes

IDG News Service
Show Comments

Cool Tech

Toys for Boys

Family Friendly

Stocking Stuffer

SmartLens - Clip on Phone Camera Lens Set of 3

Learn more >

Christmas Gift Guide

Click for more ›

Brand Post

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Aysha Strobbe

Microsoft Office 365/HP Spectre x360

Microsoft Office continues to make a student’s life that little bit easier by offering reliable, easy to use, time-saving functionality, while continuing to develop new features that further enhance what is already a formidable collection of applications

Michael Hargreaves

Microsoft Office 365/Dell XPS 15 2-in-1

I’d recommend a Dell XPS 15 2-in-1 and the new Windows 10 to anyone who needs to get serious work done (before you kick back on your couch with your favourite Netflix show.)

Maryellen Rose George

Brother PT-P750W

It’s useful for office tasks as well as pragmatic labelling of equipment and storage – just don’t get too excited and label everything in sight!

Cathy Giles

Brother MFC-L8900CDW

The Brother MFC-L8900CDW is an absolute stand out. I struggle to fault it.

Luke Hill

MSI GT75 TITAN

I need power and lots of it. As a Front End Web developer anything less just won’t cut it which is why the MSI GT75 is an outstanding laptop for me. It’s a sleek and futuristic looking, high quality, beast that has a touch of sci-fi flare about it.

Emily Tyson

MSI GE63 Raider

If you’re looking to invest in your next work horse laptop for work or home use, you can’t go wrong with the MSI GE63.

Featured Content

Product Launch Showcase

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?