Searchable Strong Encryption takes CipherCloud on new path

graphic of clouds made out of padlocks

Harold Wilson was undoubtedly right when he famously stated that a week was a long time in politics. Were he alive today he might discover that things happen a little more slowly in the cloud.

It was precisely three months ago when I wrote enthusiastically about the potential benefits of Homomorphic Encryption (HE) within the cloud space. Back then I spoke of a technology that enabled encrypted data to be thrown into the cloud, processed without any need for decryption and then chucked back at you as a still-encrypted result from that processing as being "a bit knee-trembling for a data security geek like me".

It's early in the morning as I write this, but let me tell you the news coming from the direction of CipherCloud has positively given me a When Harry Met Sally moment.

You see the trouble with the whole Homomorphic Encryption solution has always been that, without actually knowing anything at all about the data being processed (courtesy of it being encrypted up the wazoo), the cloud server fails when you start searching for stuff. If you are looking for a search term but the server doesn't know what data it has stored or even what the search term itself is (as that's also encrypted) then all it can do is give a virtual shrug of the shoulders and send you everything it has and say 'you decrypt this stuff and find it then'.

Researchers at the Massachusetts Institute of Technology (MIT) along with some help from Microsoft had apparently solved the problem, in theory, by way of an algorithm. The result of this is a functional-encryption scheme where the cloud server runs a single computation on a homomorphically encrypted result and so can ask if a record is a match without seeing the search term itself or the data it's processing.

Unfortunately, it remains a theoretical exercise as the computational resources required to get it working mean it just isn't practical in any real world sphere. What CipherCloud has done, by taking a slightly different approach to the problem of searching encrypted data in the cloud, most certainly is practical, and it's here now.

Searchable Strong Encryption (SSE), the technology in question, works alongside the CipherCloud encryption gateway - the Linux-based software appliance which encrypts data in real time as it heads for the cloud. By effectively placing a search index into the gateway, CipherCloud has managed to find a practical way of searching cloud data that is protected with AES 256-bit encryption while maintaining compliance with government regulations and industry schemes. It's actually a pretty simple concept, by leveraging the gateway architecture you get secure local indexing and full searchability whilst data continues to be strongly encrypted in the cloud but without the kind of complex local database deployment other solutions may require.

OK, so it's not quite as Star Trek as the Homomorphic Encryption stuff, and it does tie you into a vendor-specific service, but right now, and to paraphrase the old lady in the New York diner, "I'll have what they are having".

Davey Winder

Davey is a three-decade veteran technology journalist specialising in cybersecurity and privacy matters and has been a Contributing Editor at PC Pro magazine since the first issue was published in 1994. He's also a Senior Contributor at Forbes, and co-founder of the Forbes Straight Talking Cyber video project that won the ‘Most Educational Content’ category at the 2021 European Cybersecurity Blogger Awards.

Davey has also picked up many other awards over the years, including the Security Serious ‘Cyber Writer of the Year’ title in 2020. As well as being the only three-time winner of the BT Security Journalist of the Year award (2006, 2008, 2010) Davey was also named BT Technology Journalist of the Year in 1996 for a forward-looking feature in PC Pro Magazine called ‘Threats to the Internet.’ In 2011 he was honoured with the Enigma Award for a lifetime contribution to IT security journalism which, thankfully, didn’t end his ongoing contributions - or his life for that matter.

You can follow Davey on Twitter @happygeek, or email him at davey@happygeek.com.

Latest in Cloud Security
AI chatbot text dialogue boxes in difference colours above a digital circuit board with lines of light emanating from it
Enterprise AI is surging, but is security keeping up?
Cloud storage concept image showing digitized cloud symbol with data flows.
AI is putting your cloud workloads at risk
Logo of Google Cloud, which recently announced the Wiz acquisition, pictured at Mobile World Congress 2025 in Barcelona, Spain.
The Wiz acquisition stakes Google's claim as the go-to hyperscaler for cloud security – now it’s up to AWS and industry vendors to react
Wiz logo pictured on a laptop screen.
Google confirms Wiz acquisition in record-breaking $32 billion deal
A multicolored, CGI padlock set against blue and yellow glowing slabs representing SWG and next-gen SWG in a cloud environment.
What is a secure web gateway (SWG) and next-gen SWG?
Cloud computing concept image showing a cloud symbol with electricity flowing to it, signifying cloud uptime capabilities.
Surging CNAPP investment is a big opportunity for the channel
Latest in Feature
Matt Clifford speaking at Treasury Connect conference in 2023
Who is Matt Clifford?
Open source vulnerabilities concept image showing HTML code on a computer screen.
Open source risks threaten all business users – it’s clear we must get a better understanding of open source software
An abstract CGI image of a large green cuboid being broken in half with yellow, orange, and red cubes to represent ransomware resilience and data encryption.
Building ransomware resilience to avoid paying out
The words "How effective are AI agents?" set against a dark blue background bearing the silhouettes of flowchart rectangles and diamonds to represent the computation and decisions made by AI agents. The words "AI agents" are yellow, while the others are white. The ITPro Podcast logo is in the bottom right-hand corner.
How effective are AI agents?
An illustration showing a mouth with speech bubbles and question marks and a stylized robot alien representing an AI assistant chirping away with symbols and ticks, to represent user annoyance with AI assistants.
On-device AI assistants are meant to be helpful – why do I find them so annoying?
A range of HP devices set on pedestals on the keynote stage at HP Amplify 2025 in Nashville, with a large screen in the background bearing the HP logo against a white background. The devices include AI PCs, laptops, and printers.
HP hones its edge AI ambitions at Amplify 2025