[00:00.870 --> 00:05.770] Something else I thought was kind of weird, URLs, but that's just my personal opinion. [00:07.890 --> 00:09.230] Regulations, there's a ton of them. [00:12.630 --> 00:15.570] Obviously, everybody's probably familiar with HIPAA. [00:15.830 --> 00:18.690] I'm guessing that there's a few of these others that you guys have seen. [00:19.270 --> 00:23.990] Everybody's signed one of those stupid disclosure forms when they go in to pick up their pharmaceuticals. [00:23.990 --> 00:26.110] Just legal pharmaceuticals. [00:31.290 --> 00:36.350] So, real quick, the problem didn't really exist about 50 years ago. [00:37.110 --> 00:45.190] Thereabouts, I mean, you still had identity theft and people in the wild, wild west would change their name a couple of times. [00:46.510 --> 00:48.050] But it wasn't widespread. [00:49.410 --> 00:59.510] Obviously, about 10 years ago, in the rush to make everything available and online, people forgot about privacy. [01:00.710 --> 01:08.030] And so, within the past 10 years, they've kind of tried to figure out how the hell to fix everything that they broke. [01:11.670 --> 01:16.350] So, I found that kind of interesting, 304 million people in the U.S. [01:16.470 --> 01:19.290] and 227,000 disclosures. [01:22.490 --> 01:30.250] If I had to guess, I'd say that probably everybody in this audience, with the exception of maybe 15 people, have had some sort of disclosure. [01:30.250 --> 01:33.470] Whether they actually received a notice or not. [01:35.630 --> 01:38.590] And that's my favorite example right there in the middle. [01:39.430 --> 01:40.970] Veterans, et cetera, et cetera. [01:42.770 --> 01:44.690] So, it happens to everybody. [01:46.450 --> 01:51.870] A couple of interesting websites, et cetera. [01:51.870 --> 02:00.530] There are people that are out there exposing what idiots are out there putting all this information on the Internet, in the politicians, et cetera. [02:00.790 --> 02:03.290] The Virginia watchdog is probably my favorite. [02:04.150 --> 02:05.730] She does pretty good work. [02:06.670 --> 02:16.490] In fact, being from Florida, I found Jeb, W's brother, Jeb, or George W's brother, Jeb, our former governor. [02:16.490 --> 02:20.830] If you're interested, there's his social security number in the middle. [02:21.410 --> 02:22.910] His wife's on there, too. [02:24.030 --> 02:25.010] Nice lady. [02:25.510 --> 02:26.190] Spanish. [02:29.310 --> 02:31.590] I'm not going to play this because it's long. [02:32.070 --> 02:36.750] But, basically, 20 million records in Riverside. [02:36.870 --> 02:44.130] This will be in the PowerPoint presentation if you guys go online to arousis.com. [02:44.130 --> 02:45.710] We've got this on there. [02:45.930 --> 02:49.750] This whole presentation as well as the movies at the end. [02:51.650 --> 02:56.430] Movies of the presentation at the end are on there as well. [02:59.910 --> 03:01.030] So, okay. [03:01.950 --> 03:02.750] PII adjustments. [03:03.050 --> 03:07.610] So, this is the actual anonymization or pseudonymization portion. [03:09.330 --> 03:12.630] You've got two main changes that you can make. [03:12.630 --> 03:14.110] You either have a random number. [03:14.370 --> 03:19.530] And anybody in here attend the Debian deal a couple of minutes ago? [03:20.010 --> 03:20.490] Okay. [03:20.650 --> 03:21.370] Perfect example. [03:21.570 --> 03:22.650] You screw up with RNG. [03:22.650 --> 03:24.090] You screw up everything else. [03:26.870 --> 03:28.270] So, random numbers. [03:28.470 --> 03:33.930] As far as the random numbers go, we've got the three main at the top. [03:35.810 --> 03:43.330] Obviously, if you go through and have a lookup table, you've got to trust whoever owns the lookup table. [03:44.690 --> 03:48.270] And administrators aren't the only ones that have access to that. [03:49.410 --> 03:52.510] Not that anybody here would ever try to break into a computer. [03:52.510 --> 03:54.310] But it does happen. [03:54.990 --> 03:59.790] So, the second one is some sort of mathematical function. [04:02.770 --> 04:07.250] Some sort of mathematical function replaces the PII. [04:07.410 --> 04:11.070] And we'll look at the different methods of doing that in a couple of seconds. [04:11.890 --> 04:13.870] NP-hard mathematical functions. [04:14.850 --> 04:17.710] Anything that you use to pretty much do crypto with. [04:21.570 --> 04:22.050] Okay. [04:25.370 --> 04:27.290] So, anonymization, pseudonymization. [04:29.010 --> 04:30.590] Anonymization, you can't put it back. [04:32.730 --> 04:34.190] You remove it, it's gone. [04:35.550 --> 04:40.070] There's no way of reforming the person that the information came from. [04:41.450 --> 04:43.590] Pseudonymization, you can go through and put it back. [04:43.970 --> 04:46.210] I'm going to use anonymization for all of it. [04:46.350 --> 04:48.090] Just please bear with me. [04:50.210 --> 04:50.870] Let's see. [04:51.070 --> 05:00.050] Normalization is kind of interesting if you go through and expect that Rob, Bob, and Robert are all the same person. [05:00.310 --> 05:05.110] This was something that was a problem in Las Vegas when they were trying to catch cheats out there. [05:05.890 --> 05:09.310] Bob Smith suddenly became Robert Smith and they couldn't figure that out. [05:09.310 --> 05:18.150] The example at the end of this has an airline watch list that we'll go through. [05:18.950 --> 05:20.990] And with those particular people... [05:24.430 --> 05:25.390] Power settings. [05:25.730 --> 05:37.090] With those people, obviously, if Bob Smith hops on the plane and Robert Smith, this is the one that's on the watch list, you probably don't want him hopping on board. [05:37.090 --> 05:41.810] Not that anybody would ever be denied entrance onto an airplane that's here. [05:42.950 --> 05:43.730] Never mind. [05:45.570 --> 05:46.570] Let's see. [05:52.320 --> 05:52.880] Okay. [05:53.140 --> 05:55.760] At the bottom there, who has access to the table? [05:55.760 --> 05:56.460] Google. [05:56.740 --> 06:00.700] That's a pretty well-known problem and I think we'll talk about that a couple seconds later. [06:00.920 --> 06:03.020] But it's so well-known I'm not going to cover it. [06:03.080 --> 06:06.300] Basically, you have to lock it up in some form or fashion. [06:06.560 --> 06:14.760] Google does that as far as who has access to the data that they collect from everybody that uses the website. [06:16.440 --> 06:27.760] They have procedures in place so that you can't go back through and figure out who did the search on Jeb Bush, Virginia Watchdog, and Tampa or something like that. [06:30.800 --> 06:33.680] So, this is the actual anonymization. [06:37.220 --> 06:43.340] If you notice, obviously, social security number and address, those are direct identifiers. [06:43.540 --> 06:48.600] You can find, theoretically, anyone with just those pieces of information. [06:49.640 --> 06:59.240] When you start going into the others, those gray portions, you get into the HIPAA requirements that we were talking about, PII, a couple of seconds ago. [06:59.240 --> 07:05.060] And you can start putting people back together if you have enough of them. [07:05.740 --> 07:14.660] So, you actually, if you want to truly anonymize the data, you're going to end up with the guy's first name, maybe, the state that he's in. [07:15.320 --> 07:17.700] I think you'd even have to skip his age. [07:18.220 --> 07:21.900] But anyways, that's the anonymization portion. [07:22.740 --> 07:26.740] So, everything from now on is anonymization, whether it removes everything or not. [07:27.420 --> 07:28.220] We'll deal. [07:29.200 --> 07:30.340] Data replacement. [07:31.040 --> 07:31.980] Let's see. [07:33.600 --> 07:34.800] De-identification. [07:34.960 --> 07:40.920] You can actually go through if you just use a straight RNG and start replacing all the PII. [07:41.080 --> 07:42.220] You can replace everything. [07:43.080 --> 07:51.040] Going back and actually trying to reconstitute anything of use or value is where you start getting into some difficulties. [07:52.000 --> 07:56.020] In particular, if you want to do, like, medical research. [07:56.760 --> 07:59.820] The company was founded by a medical doctor. [07:59.900 --> 08:03.060] So, it's kind of the natural HIPAA related. [08:03.300 --> 08:04.900] That's where most of this stuff came from. [08:05.120 --> 08:10.740] You want your doctor to be able to go through and figure out that you visited a couple of different hospitals. [08:12.580 --> 08:19.000] You don't necessarily want to have two different random numbers pointing to you at those two different hospitals. [08:21.300 --> 08:22.140] Let's see. [08:23.720 --> 08:28.300] Again, this is straightforward as far as the replacements go. [08:28.940 --> 08:32.120] The tables lock those down as best as possible. [08:34.400 --> 08:38.460] So, hashing is where we get into the first of the mathematical functions. [08:43.080 --> 08:44.300] What can I say about it? [08:44.440 --> 08:45.040] It's a hash. [08:45.280 --> 08:47.120] It's supposed to be a one-way function. [08:48.740 --> 08:51.780] Obviously, with some of the collision problems that we've had in the past. [08:52.720 --> 08:56.580] If you have that information, it's not necessarily going to be one-way. [08:56.580 --> 09:03.000] And you can go through and start reconstituting, especially if you have something as simple as a nine-digit number. [09:04.680 --> 09:08.620] You can reconstitute that as far as hash collisions go. [09:11.300 --> 09:12.660] So, let's see. [09:15.300 --> 09:16.480] Example, there you go. [09:16.920 --> 09:18.820] Replacing them with math functions. [09:19.820 --> 09:21.400] Some of the popular ones there. [09:21.400 --> 09:27.940] You start getting into the SHA functions and you've got a reasonable expectation of good math there. [09:30.280 --> 09:32.180] Encryption, asymmetric versus symmetric. [09:32.360 --> 09:33.760] I wanted to talk about that for a reason. [09:33.980 --> 09:34.060] Oh. [09:35.320 --> 09:37.680] So, asymmetric, you're going to... [09:37.680 --> 09:42.600] Obviously, the private key holder gets to control who can see whatever data. [09:44.360 --> 09:47.800] A couple of the companies that actually use the PKI version. [09:53.220 --> 09:56.740] It's that trade-off that was the purpose of this talk. [09:57.220 --> 10:00.140] If you've got the hash function, it's one way. [10:00.280 --> 10:01.800] Theoretically, you can't go backwards. [10:01.800 --> 10:13.980] If you're using a private key, public key crypto, the person that actually owns the data, you have to get the okay authorization from them. [10:14.120 --> 10:19.280] And if you're using the symmetric key crypto, there's kind of a trade-off. [10:19.280 --> 10:36.060] You can either have the in-person using public key, kind of a hybrid thing, or have somebody that's trusted, like the government, that can go through and kind of say, hey, you know, a warrant is issued, yada, yada, yada. [10:39.700 --> 10:45.840] That trusted third party as a moderator, that's where you start getting into who do you trust. [10:47.960 --> 10:48.760] Let's see. [10:49.620 --> 11:05.660] So, one of the interesting things as far as cryptography goes, at least with our product, if you have pointers for all these things, and I'll go into that a little bit more, that two-way function can very easily become one-way if you delete the reverse pointer. [11:05.940 --> 11:07.940] That's why I was asking about the databases earlier. [11:10.040 --> 11:12.760] So, four companies that do this. [11:17.260 --> 11:21.580] Custodiacs and Sapir are very well-known over in Europe, in the EU. [11:22.040 --> 11:24.740] This is a big problem over there, yada, yada, yada. [11:27.200 --> 11:29.200] We'll talk about that more in a couple of seconds. [11:30.200 --> 11:39.560] Sapir uses the hash and symmetric crypto because they don't have a slick way of going one way versus two. [11:43.940 --> 11:48.800] Nora and Anna were developed... there's more detail if you guys download this. [11:49.140 --> 11:50.040] There's more detail. [11:50.180 --> 11:55.900] Unfortunately, with 55 minutes, we're not going to get to the other portion going through 75-plus slides. [11:56.140 --> 12:02.360] So, you guys can download this if you want a little more detail on how these different companies do their pseudonymization. [12:04.380 --> 12:06.300] So, data mining. [12:06.580 --> 12:10.700] We'll concentrate on that because earlier we talked about table lookup. [12:11.080 --> 12:12.240] Pretty well understood. [12:12.420 --> 12:13.220] Lock the files down. [12:14.780 --> 12:19.880] As far as replacement goes, we'll talk about hash versus crypto. [12:19.880 --> 12:21.500] The whole reason this started... [12:21.500 --> 12:24.400] I was at some conference in DC, go figure. [12:25.300 --> 12:30.960] And the guy that did Nora, Steve Jobs type, very energetic. [12:31.220 --> 12:34.120] I mean, the guy's got his finger in the light socket all the time. [12:34.660 --> 12:37.400] And he gave a keynote speech. [12:37.760 --> 12:42.680] Spoke with him and a couple of, like, hardcore crusty NSA types. [12:42.680 --> 12:52.540] And they were mentioning that you would never want to go through and use cryptography for a one-way function because... [12:52.540 --> 12:54.860] Or do something like this with hashing. [12:55.200 --> 12:56.120] A one-way function. [12:58.220 --> 12:59.100] Try this again. [12:59.360 --> 12:59.560] Hold on. [13:00.780 --> 13:01.280] Okay. [13:01.600 --> 13:11.740] You would never want to try to do something where you can reconstitute the data because they have really big computers, I think was what they said. [13:12.100 --> 13:12.620] So. [13:13.940 --> 13:14.700] All right. [13:16.460 --> 13:18.300] So here's the actual problems. [13:18.580 --> 13:19.800] We mentioned... [13:21.520 --> 13:23.020] We'll mention Debian next. [13:25.540 --> 13:27.360] Collisions, brute force key length. [13:27.520 --> 13:30.080] We talked about that a little earlier in the Debian talk. [13:30.300 --> 13:35.160] The guys are mentioning that people are out there using 8,000 bit keys. [13:35.160 --> 13:38.000] And there's no real need. [13:41.340 --> 13:44.680] I'll show the brute force statistics in just a second. [13:44.840 --> 13:48.840] But, I mean, it's decades if you're going to brute force them. [13:49.020 --> 13:50.960] There's going to be another flaw that you can find. [13:51.380 --> 13:57.360] Whether it's poor key choices, weak keys, you should go through and blacklist all of those keys. [13:57.640 --> 14:02.640] There's weak keys even without going through the Debian flaw that you should just never use. [14:02.640 --> 14:04.000] And we pull those out. [14:04.260 --> 14:06.180] A couple of the other companies pull them out as well. [14:08.680 --> 14:09.400] Let's see. [14:13.520 --> 14:16.760] So, you've got the broken hash functions in the middle. [14:18.040 --> 14:21.140] They can go through and you've got that collision problem. [14:21.360 --> 14:36.400] As soon as you have that fixed amount of data, you're kind of hosed because the whole purpose behind pseudonymization is to go through and have, you know, my social security number equal some random each and every time that I'm going through and using it. [14:38.240 --> 14:43.560] So, that's one of the reasons that you cannot put random numbers in there. [14:47.430 --> 14:50.890] Oh, the GPU thing at the bottom, there was some study. [14:51.490 --> 14:54.090] I think the link is on the bottom there. [14:54.150 --> 14:54.810] You can't read it. [14:54.990 --> 14:58.690] But they went through and are pre-calculating hash tables. [14:58.830 --> 15:20.030] And there's enough memory on graphics processors that you can go through, put all these hashes into the cards memory and run through the tables very quickly, have an order one search against them and essentially find it in a fixed known quantity of time. [15:22.990 --> 15:24.890] So, here we go about Debian. [15:26.010 --> 15:27.550] I thought it was six years ago. [15:27.710 --> 15:28.340] I guess it was 2006. [15:28.750 --> 15:29.570] My apologies. [15:31.210 --> 15:35.790] Netscape had a SSL flaw once upon a time. [15:35.790 --> 15:38.350] Basically, any of these are going to have some problem. [15:40.150 --> 15:44.530] Relying on crypto with the weak keys in there, kind of difficult. [15:45.850 --> 15:48.350] Hash functions, we talked about that. [15:48.670 --> 15:58.330] You don't want XYZ, you don't want my social security number to point to two different numbers, especially within the same record. [15:58.590 --> 16:01.090] That defeats the whole purpose of pseudonymization. [16:08.630 --> 16:10.210] Hardware security modules. [16:11.330 --> 16:20.410] Obviously, crypto modules, if you have a flaw in them, you can go through and break anything that's actually encrypted with them. [16:20.950 --> 16:23.890] HSMs kind of eliminate most of those issues. [16:26.950 --> 16:27.830] Let's see. [16:28.810 --> 16:29.830] Cold boot risk. [16:30.450 --> 16:37.470] So, if you have an overflow in the crypto module, which theoretically, those things have been pretty well combed over. [16:37.910 --> 16:44.590] But if you have a risk, if you have a flaw in the crypto module, you're kind of hosed. [16:46.570 --> 16:49.450] Cold boot wise, I mean, you're releasing the keys. [16:49.450 --> 16:53.230] And that was the whole point behind the cold boot attack. [16:56.560 --> 16:57.970] There's the brute force numbers. [17:01.420 --> 17:03.770] It will take... [17:04.240 --> 17:12.850] So, for a military intelligence agency with a 128-bit key, it says infeasible. [17:13.930 --> 17:17.310] So, nation states theoretically can't brute force a 128. [17:17.590 --> 17:19.730] I would bump that up to 512, probably. [17:21.250 --> 17:24.090] But, I mean, the numbers are there. [17:24.290 --> 17:24.690] It's... [17:24.690 --> 17:30.450] If you actually have to go through and start doing that many calculations, it's just invisible. [17:32.350 --> 17:33.130] Let's see. [17:33.270 --> 17:33.790] Weak keys. [17:33.790 --> 17:36.570] So, another thing that can go through if you... [17:38.390 --> 18:00.090] If you go through and have a limited number of keys, if you're not doing proper rotation, et cetera, et cetera, you can go through and handle a statistical attack and figure out what information is actually there, either because speech patterns are pretty well understood or because... [18:00.830 --> 18:08.070] I mean, there's just ways of going back through and figuring out what information was encrypted because it shows up consistently. [18:08.310 --> 18:13.730] I think that's how we broke one of the ciphers during the World War II. [18:19.900 --> 18:21.880] Speaking way too damn fast, aren't I? [18:23.660 --> 18:24.380] Let's see. [18:24.540 --> 18:25.040] Mitigations. [18:25.360 --> 18:28.600] So, we get into hashes. [18:31.320 --> 18:33.740] RNG incorporation doesn't work. [18:35.340 --> 18:40.700] Crypto, you can go through and get the FIPS validation, common criteria validations. [18:41.320 --> 18:47.100] Theoretically, those will go through and actually make sure that you're implementing your crypto properly. [18:47.840 --> 18:49.060] OpenSSL went through that. [18:50.100 --> 18:52.120] It's more or less secured. [18:52.120 --> 18:55.960] Obviously, it's not going to work that well long term. [18:58.840 --> 19:01.640] Because there's always going to be some other software flaw. [19:03.260 --> 19:08.520] Key storage, keep them in the HSM so you can't read them out of memory somewhere. [19:12.320 --> 19:14.860] So, the trusted third party for lookup tables. [19:15.920 --> 19:20.020] That's kind of one of the bases behind some of the stuff that we do. [19:22.140 --> 19:25.500] And unfortunately, the government's going to use them. [19:25.660 --> 19:27.100] They're going to do something somewhere. [19:27.720 --> 19:31.500] So, it's kind of better to reign them in at least a little bit up front. [19:31.900 --> 19:35.060] So that, you know, you guys can't go through and find my information. [19:35.580 --> 19:37.020] Because they did something stupid. [19:37.020 --> 19:44.440] So, right now, they can be using lookup tables or handing out watch lists. [19:44.680 --> 19:51.140] And suddenly, Muhammad Atta and Hossein Atta both get pulled over just because of their names. [19:51.760 --> 19:53.100] You want one of the guys. [19:53.100 --> 19:53.900] You don't want the other. [19:58.160 --> 19:59.080] Let's see. [19:59.680 --> 20:00.440] Oh, key rotation. [20:01.440 --> 20:11.920] So, if you aren't pulling the keys frequently enough, that's where you get into that statistical analysis attack against the crypto. [20:16.210 --> 20:16.990] Let's see. [20:24.100 --> 20:25.380] Pretty straightforward, I hope. [20:32.060 --> 20:34.080] You probably don't want me to read the rest of it. [20:36.080 --> 20:36.710] All right. [20:36.990 --> 20:40.040] Now, we'll get into the demonstration, which is probably why most of you guys are here. [20:40.040 --> 20:44.620] In order to do that, I'm going to have to do a quick explanation of how we do things. [20:45.490 --> 20:47.210] I promise to keep it quick. [20:48.710 --> 20:56.970] And then we'll get to the airline passenger example, because you guys said that you're more technically savvy than the rest of the world. [21:00.650 --> 21:01.150] Okay. [21:02.770 --> 21:09.310] We go through, have a fast key server, encrypt everything, and then dump it into a database. [21:09.310 --> 21:12.330] So, all the keys are encrypted. [21:12.690 --> 21:14.710] All the pointers to the keys are encrypted. [21:15.510 --> 21:18.710] And there's something else that's encrypted. [21:18.910 --> 21:20.090] Oh, the data is encrypted. [21:22.770 --> 21:25.170] You know, that's the little part that's important. [21:26.230 --> 21:26.970] Go figure. [21:27.210 --> 21:28.390] So, you create a file. [21:28.610 --> 21:29.450] You create a key. [21:29.730 --> 21:31.770] That red line there is supposed to be a key pointer. [21:32.350 --> 21:33.050] It's hot. [21:33.170 --> 21:33.630] It's red. [21:33.870 --> 21:34.810] It's unencrypted. [21:35.970 --> 21:37.030] You encrypt it. [21:37.190 --> 21:37.990] You store it. [21:38.330 --> 21:39.190] You encrypt the key. [21:39.350 --> 21:40.010] You store that. [21:43.530 --> 21:44.150] That's a... [21:44.150 --> 21:46.750] You've got a crypto module that you're going to be working in in there. [21:48.430 --> 21:53.290] The only thing that you store with the actual data is the encrypted pointer. [21:53.570 --> 21:55.250] You can go through and reconstitute. [21:55.350 --> 21:57.370] You'll see that in the database tables in a couple of seconds. [21:59.190 --> 22:00.570] You want to decrypt it. [22:01.070 --> 22:01.890] You go through. [22:01.890 --> 22:03.430] There's an authorization step. [22:05.030 --> 22:07.390] There's ACLs that you can put against the... [22:07.390 --> 22:09.410] Who can actually access the key pointers. [22:11.750 --> 22:12.830] Look up use. [22:13.110 --> 22:14.610] It's pushed down to the crypto module. [22:15.310 --> 22:16.430] You decrypt. [22:17.030 --> 22:20.890] Everything goes happy when you stop opening the file. [22:21.090 --> 22:23.710] It only opens a limited amount of information at a time. [22:23.710 --> 22:25.310] So, 4K blocks. [22:25.530 --> 22:28.090] It's a block version of the cipher. [22:30.210 --> 22:31.190] Let's see. [22:33.710 --> 22:34.370] Okay. [22:34.790 --> 22:36.330] So, anonymized data sets. [22:36.970 --> 22:40.550] All of these work because of what we call that hidden link. [22:40.690 --> 22:45.310] Which is that encrypted key pointer down at the bottom of the red box. [22:48.150 --> 22:48.590] Okay. [22:48.910 --> 22:50.390] We do everything with symmetric keys. [22:51.130 --> 22:53.050] The hidden link is a key pointer. [22:53.210 --> 22:54.550] It's encrypted with a symmetric key. [22:54.830 --> 22:56.250] The ACLs against it. [22:56.330 --> 22:57.550] And you can scale this thing. [23:02.840 --> 23:03.500] Let's see. [23:03.820 --> 23:04.800] The ACLs. [23:04.860 --> 23:07.780] So, this has some insider threat capabilities and protections. [23:09.520 --> 23:11.800] That may or may not be of use to any of you guys. [23:12.040 --> 23:16.540] If any of you actually run, you know, servers or anything along those lines. [23:16.540 --> 23:18.460] That you don't want other people in. [23:18.760 --> 23:20.760] That's one way of taking care of it. [23:23.100 --> 23:28.900] And then, because of the federation, you can do tiered hierarchies of key material. [23:29.460 --> 23:31.840] And that allows you to do multi-domain. [23:34.800 --> 23:37.780] Probably not as important with the group here. [23:37.960 --> 23:42.840] But, hey, it's kind of interesting if you want to keep, like, company confidential information. [23:42.840 --> 23:45.800] You want to keep that off of the public website. [23:46.340 --> 23:49.660] And you want your SEC type of information. [23:49.760 --> 23:51.840] You want all three of those at different tiers. [23:52.000 --> 23:54.540] So that you don't get slapped with lawsuits. [24:00.140 --> 24:03.080] Like I said, everything's done with RDBMS. [24:03.380 --> 24:07.300] We've got a deal that actually links into a bunch of different databases. [24:09.320 --> 24:14.240] Authorized access, you can then go through and access the protected data records. [24:14.980 --> 24:16.200] Here's how it works. [24:19.260 --> 24:20.700] You've got the alias... [24:20.700 --> 24:22.240] This thing's not going to point, is it? [24:22.380 --> 24:23.820] You've got the alias right there. [24:24.140 --> 24:25.200] That's that hidden link. [24:25.300 --> 24:26.420] That's the encrypted key pointer. [24:26.420 --> 24:37.760] And as soon as you actually have data that comes in up here, you're going to go through, pull out all the non-sensitive data, the non-PII stuff that we talked about earlier. [24:38.000 --> 24:42.160] The first name, first three digits of the ZIP Code, et cetera, et cetera. [24:42.500 --> 24:49.700] And then you will pull out the sensitive stuff, send it over to this anonymization service agent. [24:51.360 --> 24:57.380] That can be in-house if you're trying to do this in-house, if you're trying to protect your information directly. [24:57.900 --> 25:22.660] If you're dealing with somebody like the airlines and they're dealing with somebody like the FBI, DHS, or the Department of Justice can actually hold that, be that third party, hold the keys, and control, not allow warrantless type searches. [25:25.200 --> 25:28.740] At the bottom, you go through and you get that pseudonym. [25:29.760 --> 25:34.540] And with that pseudonym, I'll show you exactly what that is in the database tables. [25:36.040 --> 25:46.600] But it's encrypted, it's actually doubly, triply encrypted, which allows you a method of going through and restoring everything after the fact. [25:47.480 --> 25:52.660] You put that pseudonym back in with the non-sensitive data, and then you can do data searches against it. [25:52.800 --> 26:02.620] If you have to find maybe somebody in the medical community, somebody that visits a couple of different hospitals, that's the example that's in here. [26:02.780 --> 26:03.860] You can look at it. [26:04.560 --> 26:05.920] Actually, we might look at it, too. [26:06.440 --> 26:25.380] But in the medical community, if somebody goes through to a couple of different hospitals, and they have, I don't know, typhoid or, you know, Ebola, the second hospital, you'd probably want to know that it's the same person going to the second hospital, [26:25.380 --> 26:29.320] versus having two people and suddenly having an outbreak. [26:31.940 --> 26:34.520] Medical information, that's what I was just talking about. [26:35.980 --> 26:37.940] Okay, radiation poisoning, sorry. [26:38.880 --> 26:40.280] Want to know if it's the same person? [26:41.660 --> 26:46.700] You can go through, pull out all the protected information, kind of blur it a little bit. [26:47.160 --> 26:48.780] We're using crypto to do it. [26:49.760 --> 26:50.980] It's HIPAA compliant. [26:51.680 --> 26:56.520] I'll show you the example for this in a second, and we'll go through both of those simultaneously. [26:58.580 --> 27:03.880] And for the airline passengers, actually, yeah, we'll do this. [27:04.160 --> 27:10.940] For the airline passengers, you've got a no-fly list, and that's what we were talking about earlier with the hashing. [27:11.100 --> 27:12.800] You can go through, yeah, the bomb. [27:16.300 --> 27:19.660] You want to find out if the yellow guy is any of the other colors. [27:21.920 --> 27:40.440] In this particular example, we go through, because a passport number is unique to the different countries, we go through and hash or combine the country code and the actual passport number. [27:40.440 --> 27:51.320] You can put three, four, five different columns within a database together to make the alias that will then be encrypted, et cetera, et cetera. [27:52.800 --> 27:57.280] And then use all of that to determine if this guy has the bomb or not. [27:58.680 --> 28:03.720] Unfortunately, you can't do this directly because of that. [28:05.040 --> 28:11.400] Like I said, the EU has... privacy is a fundamental right over there. [28:12.080 --> 28:19.720] Unlike here, where we say, you know, if you're in the finance space, hey, you shouldn't disclose somebody's bank number. [28:19.860 --> 28:26.060] And if you're in the medical space, you shouldn't expose their social security number. [28:26.060 --> 28:28.480] Over there, you shouldn't expose anything. [28:29.200 --> 28:30.520] Kind of a different viewpoint. [28:32.500 --> 28:38.360] If we actually tried to do something like this over here, you'd probably bankrupt a couple of different companies. [28:39.000 --> 28:41.300] And Halliburton might be one of them. [28:41.420 --> 28:41.620] No. [28:47.770 --> 28:48.790] So, same thing. [28:48.990 --> 28:53.210] You go through, pull out pieces of information, including the passport number and the country code. [28:53.210 --> 28:58.930] And then you return the country code because that's not actually PII. [29:01.880 --> 29:04.940] And then this safe harbor is the only reason that U.S. [29:05.020 --> 29:07.940] companies can actually do business with the European Union. [29:08.400 --> 29:15.540] That we kind of promise that we're not going to disclose the information as much as we can promise. [29:15.760 --> 29:23.440] And that was a big problem back about 10 years ago, 15 years ago with IBM, some of the multinational conglomerates. [29:24.380 --> 29:25.240] Multinational companies. [29:25.540 --> 29:27.100] They just had too many... [29:27.100 --> 29:33.680] They weren't doing business well enough because they couldn't share information between their company in France and their company in Germany. [29:35.000 --> 29:41.360] So, they got everything straightened out in the EU with the data protection privacy directive. [29:42.260 --> 29:45.060] And now they're trying to get everything straightened out with the U.S. [29:45.100 --> 29:46.620] They kind of have that in place now. [29:47.060 --> 29:48.840] And this EU, U.S. [29:48.900 --> 29:51.140] safe harbor is how they did it. [29:53.400 --> 29:53.840] Okay. [29:54.300 --> 29:56.840] So, the database will look sort of like this. [29:57.020 --> 30:01.380] You've got the different airlines, country code, passport number. [30:01.680 --> 30:03.780] And we're going to combine those two. [30:04.180 --> 30:06.020] And the anonymization service... [30:06.020 --> 30:08.180] I don't know if you guys can see this at the end or not. [30:09.740 --> 30:11.420] But that's that encrypted pointer. [30:11.560 --> 30:12.720] There's the little lock on it. [30:12.720 --> 30:22.320] And this is essentially a ticket, a pointer to the key that actually everything was encrypted with. [30:27.050 --> 30:27.610] Okay. [30:28.570 --> 30:30.890] Give me a second to see if I can... [30:48.380 --> 30:54.040] So, as is often the case, the best laid plans don't quite work out the way they are supposed to. [30:54.620 --> 30:58.280] I guess this does not have the resolution that one would expect. [30:58.860 --> 31:01.780] So, we've got two anonymization demos here. [31:01.900 --> 31:05.420] The first one is the medical that we just talked about. [31:07.120 --> 31:08.080] These work. [31:08.260 --> 31:11.840] They're actually going through and kind of creating random data. [31:13.260 --> 31:16.440] If anybody wants to fool around with them, we can set that up. [31:17.360 --> 31:19.920] We've got these built into movies already. [31:20.440 --> 31:24.840] And you get to hear my lovely voice for more than five minutes. [31:32.090 --> 31:32.770] Okay. [31:32.770 --> 31:34.490] We're going to generate some data. [31:38.090 --> 31:38.590] Come on. [31:38.830 --> 31:39.250] There we go. [31:40.410 --> 31:46.710] The CPT and ICD codes, those are the diagnosis and patient codes. [31:48.070 --> 31:50.690] I mean, the diagnosis and treatment codes. [31:50.690 --> 31:56.210] Those are what the medical community, the researchers, would actually want to correlate against. [31:56.590 --> 32:01.330] And you've got the SSN number, which is the piece that we want to keep private. [32:02.250 --> 32:04.010] We pull out the SSN. [32:04.250 --> 32:20.350] Now, one of the things that ends up happening with these row numbers, that's kind of an identifier that you could theoretically go through and work backwards if you were to hack the trusted third service. [32:20.870 --> 32:27.950] You could work that back into the end consumer of the data. [32:28.170 --> 32:31.650] However, you'd have to take care of a couple of different locations. [32:31.650 --> 32:35.650] And that defense in depth thing kind of comes into play at that point. [32:37.090 --> 32:39.890] One other way around it is just to... [32:39.890 --> 32:41.490] The person on the... [32:41.490 --> 32:48.970] The person that's actually generating the data, the hospital, would go through and put random numbers in there against the... [32:48.970 --> 32:54.710] Instead of the row numbers and just submit all of it in order with random numbers in there. [32:56.090 --> 32:58.530] So we would anonymize everything, [33:06.800 --> 33:09.680] wait about six seconds. [33:10.880 --> 33:14.180] We'll go through at the very end of this and look at the pointers themselves. [33:14.500 --> 33:17.860] That might make this look a little more sensical. [33:18.900 --> 33:21.960] But straightforward, it's encrypted. [33:22.520 --> 33:27.040] It's going to come out to a consistent length because it's a block cipher. [33:29.580 --> 33:31.120] And there's the data. [33:31.120 --> 33:31.140] Okay. [33:34.470 --> 33:35.190] Anonymize it. [33:35.330 --> 33:38.810] Just put everything back into the rows that we started out with. [33:38.970 --> 33:42.590] And you should have the diagnosis and treatment codes at the end. [33:46.710 --> 33:48.970] And that's submit to the data center. [33:49.110 --> 33:52.010] Those are the people that we're trusting with all this information. [34:04.260 --> 34:04.820] Okay. [34:05.380 --> 34:06.360] View submitted data. [34:06.360 --> 34:15.300] So if you were to go through and find a couple of people that visited a couple of locations. [34:15.420 --> 34:16.580] We'll grab these two. [34:17.140 --> 34:18.380] 115, 116. [34:19.000 --> 34:21.400] You've got a treatment code and diagnosis code. [34:21.540 --> 34:22.380] So these people... [34:22.380 --> 34:27.960] This person came in on who knows if it was two separate occasions or not. [34:27.960 --> 34:34.140] But you can go through and figure out because they have the same alias. [34:34.680 --> 34:36.900] You can figure out who they were. [34:37.200 --> 34:43.880] And if the CDC wanted to go through and find those two people that had been exposed to the radiation. [34:44.220 --> 34:46.020] Figure out if it was one person or two. [34:46.020 --> 34:48.260] They can go through and... [34:49.660 --> 34:50.540] What did I say? [34:50.600 --> 34:50.960] 115. [34:57.150 --> 34:58.250] Reverse the identity. [34:58.530 --> 34:59.670] Grab the social security number. [34:59.890 --> 35:00.970] And continue on. [35:02.570 --> 35:11.650] The reason that all of this works is because of the tables themselves. [35:12.050 --> 35:18.430] So you've got a pointer and a reverse pointer that are included in these tables. [35:18.430 --> 35:22.670] And you've got a hashed SSN. [35:22.910 --> 35:29.770] So the third party service is going to need to know when somebody's already in the table. [35:29.910 --> 35:33.930] So you end up storing a hash of these, in this particular case, the social security number. [35:35.830 --> 35:39.710] And if new data comes in, you don't want to give a different alias. [35:39.710 --> 35:41.130] That kind of defeats the whole purpose. [35:41.330 --> 35:46.670] So you want to find out if person A and person B went to different hospitals. [35:46.670 --> 35:49.110] Or if it's person A going to both hospitals. [35:50.210 --> 35:54.230] So you would go through and use the hash to make that determination. [35:54.290 --> 36:01.190] If it already exists, you return the hidden link here. [36:01.910 --> 36:06.170] Actually, you end up returning the alias, which is down a little bit further. [36:07.550 --> 36:18.130] If you look at this hidden link, you've got a key server identifier that allows you to figure out who it is that generated the key. [36:18.790 --> 36:19.650] And I returned it. [36:20.550 --> 36:23.950] And then you've got the equals at the end. [36:24.190 --> 36:25.510] That's Base64 encoding. [36:26.570 --> 36:29.470] And then here's the encrypted pointer. [36:35.450 --> 36:38.770] Down at the bottom, you've got your reverse lookups. [36:39.490 --> 36:45.410] And within this, this first one is the encrypted hidden link. [36:45.550 --> 36:49.410] And the whole point behind it is that this is the reverse lookup. [36:49.410 --> 36:54.230] So I'll show you the pointers if you want in a couple of seconds. [36:56.870 --> 36:58.310] The reverse hidden link. [37:00.770 --> 37:03.490] And the hidden link for the reverse. [37:03.670 --> 37:06.530] So that you can find the key pointer back into this. [37:06.970 --> 37:07.990] Hold on one second. [37:10.030 --> 37:10.810] There we go. [37:14.000 --> 37:16.640] So this might make it a little more sensical. [37:19.880 --> 37:25.860] When you have the data come in, you put the hash in place so that you can actually find it again. [37:26.040 --> 37:26.760] We talked about that. [37:26.980 --> 37:34.620] You encrypt the data and you have the forward and reverse pointers there. [37:35.120 --> 37:36.400] That's what you were just seeing. [37:36.920 --> 37:39.220] Right there and right there. [37:39.220 --> 37:45.880] And those allow you to go back and forth between the tables and actually recreate everything. [37:46.180 --> 37:53.900] If you delete this second table, you can go through and make this a one-way function. [37:54.120 --> 37:54.900] It defeats the purpose. [37:58.590 --> 38:07.170] And what I wanted to show in here, I hope that nobody can actually read any of this and that there's nothing straightforward. [38:07.490 --> 38:10.510] There's nothing that you can discern from any of this information. [38:12.210 --> 38:13.490] So, any questions? [38:14.190 --> 38:15.930] Do you want to see the airline one? [38:16.050 --> 38:19.190] It's more of the same as far as the tables go. [38:19.390 --> 38:19.930] Yes, sir. [38:20.190 --> 38:22.490] The encrypted social security number. [38:22.730 --> 38:23.010] Uh-huh. [38:23.070 --> 38:23.190] An [38:26.510 --> 38:29.790] application that will be rewritten in the database that will be, you know... [38:29.790 --> 38:31.430] You would actually... [38:31.430 --> 38:37.970] If you were to implement this in a database, it's very easy to put in up front. [38:39.250 --> 38:43.810] If you want to put it in after the fact, you've got to put this extra pointer in here. [38:44.830 --> 38:47.790] You've got to put a pointer on the end of each one. [38:47.950 --> 38:48.670] Just the pointer. [38:49.370 --> 38:52.290] Because everything else you can do is a lookup from there. [38:54.070 --> 38:54.650] Yes, ma'am. [38:55.630 --> 38:57.390] The hospitals, I guess. [38:58.010 --> 38:59.550] How is, you know... [38:59.550 --> 39:01.030] Obviously, the data is not useful. [39:04.450 --> 39:05.990] But I mean... [39:06.610 --> 39:08.810] I guess what I have to ask is... [39:08.810 --> 39:10.450] So, who is storing the data actually? [39:10.570 --> 39:11.430] You're storing the data? [39:12.570 --> 39:13.990] There's a couple of different choices. [39:14.310 --> 39:17.250] You can either have, like, the IT department... [39:17.250 --> 39:17.950] I'm sorry. [39:23.710 --> 39:28.850] I think she's asking who stores the data. [39:29.010 --> 39:29.150] Yeah. [39:29.330 --> 39:29.730] Come on up. [39:30.170 --> 39:32.170] I want you to explain, like... [39:33.330 --> 39:38.110] I understand that you have, like, this encrypted data and then you have a hash to the encrypted data. [39:38.510 --> 39:42.110] And then from there you have your pointers that connect the two or something like that. [39:42.110 --> 39:44.850] But all of that is just a one-to-one link. [39:45.970 --> 39:47.650] So, I mean... [39:47.650 --> 39:48.550] All of it's encrypted. [39:48.850 --> 39:49.150] Yes. [39:49.150 --> 39:49.970] It's all encrypted. [39:50.350 --> 39:50.510] Right. [39:50.690 --> 39:56.130] But, I mean, ultimately, like, if you could identify a person to their pointer... [39:56.130 --> 39:59.010] I assume different hospitals have, like, different pointers that they're storing. [39:59.350 --> 40:00.590] How is this useful? [40:01.010 --> 40:01.790] The different... [40:02.790 --> 40:03.310] Sorry. [40:03.630 --> 40:04.170] That's okay. [40:04.410 --> 40:07.330] The different hospitals can be given different pointers. [40:08.450 --> 40:17.370] If you're doing this as a third-party service, or if you're doing this for the greater good, you're going to have... you have to have a central service. [40:17.990 --> 40:25.710] Because what ends up happening is you have to have some way of re-associating back into, you know, an alias. [40:26.030 --> 40:29.750] If I give you a social security number, it has to point back to something. [40:31.810 --> 40:43.950] What you can do is give different aliases to different hospitals or different insurance companies, and then anonymize just within that particular application. [40:44.090 --> 40:45.390] Can they get data-mined based on the pointer? [40:45.610 --> 40:46.770] They cannot... [40:46.770 --> 40:48.070] Well, they can... [40:48.070 --> 40:48.510] Okay. [40:48.890 --> 40:53.310] If you give everybody the same alias, you can data-mine against that pointer. [40:54.590 --> 40:57.290] And that's what would happen in, like, a medical research. [40:57.570 --> 40:59.310] And you can also do this on the fly. [40:59.730 --> 41:01.810] You can go through and... [41:02.970 --> 41:08.650] For a specific application, you know, hey, for this particular research, we're looking at cancer patients. [41:08.930 --> 41:14.110] You can give them one set of aliases, okay, that's just specific to them. [41:14.330 --> 41:19.190] They can go through, figure out who they're interested in, but they only get a subset of the complete data. [41:20.070 --> 41:21.310] If that makes sense. [41:21.730 --> 41:22.930] Like, they get their own... [41:22.930 --> 41:24.750] They get their own alias pointer. [41:25.050 --> 41:26.230] So, they get all the data. [41:26.410 --> 41:29.270] They can't actually figure out anything outside of... [41:29.270 --> 41:33.650] Like, they can't conglomerate or aggregate that with some other person's data. [41:37.370 --> 41:37.890] Okay. [41:44.950 --> 41:46.970] There's two different ways of looking at that. [41:47.090 --> 41:48.710] Can we talk about it afterwards? [41:48.710 --> 41:49.330] Okay. [41:49.550 --> 41:52.030] Because there was somebody else that had a question as well. [41:52.070 --> 41:55.210] Obviously, if you're using encryption, then the issue becomes key management. [41:56.230 --> 41:56.630] Right. [41:59.590 --> 42:03.650] How are you solving to make sure that you can't identify to the market? [42:03.950 --> 42:05.650] How does that actually work? [42:05.830 --> 42:07.090] It doesn't look like you can do that. [42:07.130 --> 42:07.630] You can't. [42:07.810 --> 42:08.050] Right. [42:08.190 --> 42:11.790] That was one of the risks with hashing, is you're going to have a collision. [42:12.750 --> 42:13.750] You've got a... [42:13.750 --> 42:15.490] You know, what is social security number? [42:16.970 --> 42:17.950] It's not only four digits. [42:17.970 --> 42:18.550] Nine digits. [42:18.650 --> 42:19.230] It's like rainbow tables. [42:19.870 --> 42:20.350] Exactly. [42:20.970 --> 42:21.310] I mean... [42:21.310 --> 42:21.630] Are they using that? [42:21.790 --> 42:23.110] Are they actually using that? [42:23.310 --> 42:23.550] Yes. [42:23.870 --> 42:26.030] And the governments are possibly using that? [42:26.070 --> 42:28.510] They're actually using it in the EU. [42:30.110 --> 42:30.590] And... [42:30.590 --> 42:30.810] Yeah. [42:31.150 --> 42:32.670] So we should probably let them know that happened. [42:34.030 --> 42:34.870] I agree. [42:36.090 --> 42:37.350] I completely agree. [42:37.490 --> 42:39.370] And that's actually a big problem. [42:41.310 --> 42:48.430] The IBM example, they're using it for, like, names and things along those lines, that Nora. [42:48.730 --> 42:54.150] It's supposed to be non-obvious relational abstraction or something along those lines. [42:54.310 --> 42:58.950] It goes through and actually normalizes everything. [42:58.950 --> 43:03.390] So Bob, Robert, and Rob all point to the same person. [43:03.550 --> 43:09.050] They were using it for the casinos because, for some odd reason, people would like to come in there and cheat. [43:10.730 --> 43:11.150] So... [43:11.150 --> 43:17.450] And then when they hashed it, you know, like the NSA guy said, there's no way of going backwards with that. [43:17.930 --> 43:21.350] Well, actually, he didn't say that, but he said that it's easier to do with crypto. [43:24.010 --> 43:24.430] So... [43:25.130 --> 43:25.970] Anything else? [43:26.290 --> 43:27.050] Come on, guys. [43:28.350 --> 43:29.490] It all makes sense. [43:30.130 --> 43:31.150] Your brain hurts. [43:35.190 --> 43:35.670] Okay. [43:37.490 --> 43:38.630] Well, thank you. [43:38.750 --> 43:42.810] If you guys want this presentation, which has a heck of a lot more... [43:43.350 --> 43:43.830] Wow. [43:45.710 --> 43:46.190] Cool. [43:49.460 --> 43:51.100] I don't know what the hell I just pushed. [43:52.680 --> 43:53.180] Yeah. [43:54.640 --> 44:00.960] If you guys want this presentation, you can go to russies.com, and it's smack dab on the front. [44:01.220 --> 44:03.700] Just register for it. [44:04.180 --> 44:06.420] And the whole nine yards are on there. [44:11.420 --> 44:13.800] My web guy promises me it works. [44:16.080 --> 44:17.280] There's a... [44:17.280 --> 44:17.900] There we go. [44:20.700 --> 44:21.520] There you go. [44:21.860 --> 44:26.200] If you go through and click on create an account, it'll give you... [44:37.470 --> 44:39.850] It'll give you a file not found error. [44:41.310 --> 44:42.290] Very secure. [44:42.630 --> 44:42.890] Hey. [44:42.890 --> 44:46.390] It's better than actually logging off by unencrypted HTTP, especially at this time. [44:47.410 --> 44:49.630] Well, anyways, there's a ton of... [44:49.630 --> 44:51.690] There's these presentations. [44:52.390 --> 44:54.870] There's the movies that actually go along at the end. [44:55.030 --> 44:58.950] And then a couple of additional files. [44:58.950 --> 45:04.970] One on the cold boot, how it doesn't affect what we do, which I thought was kind of neat. [45:05.710 --> 45:17.470] Just from a simple standpoint that the world was going to end, you know, February, when all of these keys were being, you know, swiped left and right because somebody stole a laptop that was in hibernate mode. [45:18.090 --> 45:23.870] So, we found out that I did a quick diagnosis and it didn't affect us. [45:24.030 --> 45:25.170] Which was kind of cool. [45:25.490 --> 45:26.070] What's that? [45:26.070 --> 45:26.950] How do you handle the key? [45:29.150 --> 45:29.630] Each... [45:29.630 --> 45:30.230] Each... [45:30.230 --> 45:30.450] Okay. [45:31.910 --> 45:35.390] You end up with every piece of information gets its own key. [45:37.770 --> 45:39.510] So, every key is unique. [45:40.230 --> 45:44.450] You throw out all the weak keys just because we do that. [45:44.890 --> 45:49.990] And so you have all these unique keys you can go through and you don't have to worry about re-keying. [45:50.750 --> 45:52.110] We have system keys. [45:52.330 --> 45:53.130] There's a set of 100. [45:53.350 --> 45:55.270] You can set that as high as you want. [45:56.090 --> 45:57.450] You set it to 1,000. [45:57.450 --> 45:58.590] You rotate those out. [45:58.710 --> 46:00.210] There's a key expiration on them. [46:00.310 --> 46:04.470] They're stored, but they have a limited amount of information that they can actually encrypt. [46:04.670 --> 46:05.590] They get stored. [46:05.710 --> 46:07.070] You go on to the next 100. [46:10.090 --> 46:12.770] When people access the information, they have keys, right? [46:14.470 --> 46:16.370] When they access the information... [46:16.370 --> 46:23.610] People that are using the information to regroup it and figure this out, they have keys that allow them to get certain information out of it, but not all of them, right? [46:25.330 --> 46:27.470] They authenticate themselves to the system. [46:27.910 --> 46:28.390] Yes. [46:28.930 --> 46:31.950] And once they authenticate, that can be certificate based. [46:32.890 --> 46:37.530] Once they authenticate, there's actually ACLs against every single key. [46:37.530 --> 46:39.450] The keys are encrypted. [46:39.750 --> 46:40.690] You don't have the ACL. [46:40.690 --> 46:44.310] You don't get the symmetric key shipped down to your crypto module. [46:44.570 --> 46:46.530] You can't decrypt the data. [46:48.210 --> 46:48.950] Yes, sir? [46:48.950 --> 46:51.150] What about access to limited sets of data? [46:51.450 --> 46:56.430] Do you have any provision for only giving access to a certain subset of the data to a certain key? [46:56.610 --> 46:57.050] Yes. [46:57.410 --> 47:01.670] You can go through and set an ACL group. [47:02.410 --> 47:04.210] And when you do that, you can... [47:04.210 --> 47:06.350] Well, you've got group controls at that point. [47:06.510 --> 47:07.810] But it's not key level. [47:08.030 --> 47:08.390] What's happening? [47:09.710 --> 47:10.150] Well... [47:10.150 --> 47:10.970] Right. [47:11.250 --> 47:20.730] The keys are encrypted, so therefore, you've got to get authentication to get the key to decrypt the pointer to get the...on and on, to actually make it all the way down to the data. [47:21.150 --> 47:21.530] So... [47:22.310 --> 47:23.510] That's if you... [47:23.930 --> 47:24.350] If... [47:26.930 --> 47:30.170] We can talk more about that if you want. [47:30.370 --> 47:31.870] It can get kind of involved. [47:33.290 --> 47:34.030] Yes, sir? [47:34.390 --> 47:44.310] If somebody gets root on the system that holds all the key tables, say at the first web-ups, do they just break everything for everyone everywhere? [47:45.170 --> 47:46.350] They get root. [47:46.570 --> 47:46.990] No. [47:47.170 --> 47:49.470] Because all that's stored there is encrypted keys. [47:50.650 --> 47:53.330] The database only has encrypted keys in it. [47:54.530 --> 48:00.190] There's a key server that's separate, and all it has on it is the ACL... [48:00.190 --> 48:02.710] access to the key database. [48:03.570 --> 48:05.950] So you've got two separate pieces. [48:09.170 --> 48:10.350] You don't have... [48:10.350 --> 48:10.810] Here you go. [48:10.950 --> 48:18.270] An admin does not have decrypt rights, whereas a user does. [48:20.330 --> 48:27.710] There's ways of setting up the provisions and controls so that you can't go through and add privileges, et cetera, et cetera. [48:27.850 --> 48:32.110] So you can't get decrypt rights to actually go through and grab the keys. [48:32.370 --> 48:34.590] The key server just key serves keys. [48:34.590 --> 48:37.730] I mean, the decryption itself uses another key, right? [48:38.410 --> 48:41.030] The decryption itself uses... well, yes. [48:41.450 --> 48:43.950] So that key is stored somewhere, yes? [48:44.290 --> 48:46.630] Yes, on the key database or in the crypto module. [48:48.690 --> 48:52.450] And so to what extent is there one of those for the system? [48:53.070 --> 48:58.830] There are what we call master keys on the key server. [48:59.570 --> 49:00.050] Okay? [49:00.190 --> 49:01.890] And that's how you start the key server up. [49:02.050 --> 49:04.830] You can do it with Lagrange, K of M. [49:05.070 --> 49:13.110] You can do multi-key pass, smart card, multi-smart card startup for the system. [49:13.470 --> 49:20.710] So you've got to... if it reboots, you know, you've got to have multiple people authenticate to it in order to start the actual key service. [49:20.970 --> 49:21.990] Is that what you're asking? [49:24.330 --> 49:26.230] Separate physical hardware and key server? [49:26.650 --> 49:26.910] Yes. [49:27.410 --> 49:32.450] The key server, key database, and the end workstations are all separate servers. [49:32.810 --> 49:35.570] So you've got separation from that standpoint. [49:36.230 --> 49:48.990] And, I mean, even if you put these on a file server, if you put all the files on a file server, the only pieces of information that are stored are that encrypted key pointer, which we call the hidden link, and the encrypted data. [49:52.990 --> 49:53.970] Go for it. [49:56.650 --> 49:57.310] So... [49:59.350 --> 50:01.330] Tony pieces with similar names. [50:03.530 --> 50:13.050] But if you have a user-side database already, because you're a legitimate user for that aspect. [50:13.430 --> 50:13.950] Okay. [50:14.270 --> 50:19.010] And you then have all these encrypted key pointers on them. [50:20.030 --> 50:22.170] Key database has encrypted key pointers. [50:22.290 --> 50:22.650] That's correct. [50:22.850 --> 50:22.970] Okay. [50:24.690 --> 50:25.210] Wait. [50:25.770 --> 50:26.650] Then I said something wrong. [50:29.330 --> 50:31.950] Maybe I'm not getting straight enough to ask this question. [50:32.290 --> 50:32.590] No. [50:32.730 --> 50:32.990] That's cool. [50:34.250 --> 50:35.070] Go for it. [50:36.470 --> 50:37.770] I might have a picture. [50:39.470 --> 50:41.390] Might be easier to work off the picture. [50:43.290 --> 50:46.030] There's one, two, and the end workstations. [50:46.210 --> 50:46.290] Okay. [50:46.430 --> 50:46.790] There's three. [50:49.800 --> 50:51.080] There's three parts. [50:55.380 --> 50:55.940] Okay. [50:56.200 --> 50:58.020] So you've got... [50:58.020 --> 50:59.040] This... [50:59.040 --> 51:00.220] We might want to... [51:01.100 --> 51:03.020] But there's... [51:03.020 --> 51:10.940] The database of actual data, except that bits of it are replaced with the lookup tokens, basically, right? [51:11.260 --> 51:11.660] Right. [51:11.760 --> 51:12.980] Encrypted lookup tokens, right. [51:13.280 --> 51:13.640] Okay. [51:13.640 --> 51:14.860] And also... [51:14.860 --> 51:20.720] And then you have the lookup table, which translates the encrypted tokens to the right goal, right? [51:22.340 --> 51:23.460] Lookup table... [51:24.460 --> 51:25.020] Let's... [51:25.020 --> 51:26.460] Let's you and I sit down. [51:26.620 --> 51:27.760] Because this... [51:27.760 --> 51:28.220] This... [51:28.220 --> 51:29.720] It can take more than five minutes. [51:31.220 --> 51:31.780] Okay. [51:32.820 --> 51:36.140] It's definitely still sounding single point of failure to me, but I... [51:36.140 --> 51:36.860] If... [51:36.860 --> 51:37.380] If... [51:37.380 --> 51:38.040] If you crash... [51:38.040 --> 51:42.660] Well, if you crash the key server, okay, yes, you will have an issue. [51:42.880 --> 51:45.380] However, you can federate and scale. [51:45.760 --> 51:50.320] You can either regionalize the key servers and have trust relationships between them. [51:50.760 --> 51:57.920] And you can put them, like, behind a load balancer and double them up, triple them up, whatever, and just add them... [51:57.920 --> 51:58.380] Yeah. [51:58.480 --> 52:00.960] And that's in terms of being owned, not in terms of being down. [52:01.320 --> 52:01.580] Okay. [52:02.000 --> 52:03.560] Being down is also obviously a risk. [52:03.560 --> 52:04.820] It sounds like... [52:04.820 --> 52:05.220] If... [52:05.220 --> 52:09.940] All of your hospital's data lines get hit with a backhoe, they can't reach their patient database. [52:10.920 --> 52:11.400] That... [52:11.400 --> 52:13.420] That would be one of the reasons that you'd do a trust. [52:13.660 --> 52:14.920] And have a regional... [52:14.920 --> 52:16.100] A regional database. [52:16.440 --> 52:17.820] A regional key server, local. [52:19.560 --> 52:20.520] So the... [52:21.580 --> 52:22.540] Thing that... [52:22.540 --> 52:24.860] Make kids in privacy would be physically in the hospital building? [52:26.340 --> 52:27.340] Could be, yes. [52:29.680 --> 52:30.640] Oh, I'm... [52:30.640 --> 52:31.240] Sorry. [52:31.380 --> 52:31.540] Sorry. [52:31.780 --> 52:31.980] Hold up. [52:32.360 --> 52:32.720] Yes, sir. [52:32.720 --> 52:32.800] There. [52:33.820 --> 52:41.360] I heard most of that conversation, I think, so you might want to repeat some of that group right here for some of your question. [52:41.720 --> 52:43.000] But you already answered this. [52:43.140 --> 52:43.400] I'm sorry. [52:43.920 --> 52:44.360] No problem. [52:45.520 --> 52:46.000] Um... [52:46.000 --> 52:46.380] You have... [52:46.380 --> 52:49.040] You have special access to the speaker, so... [52:49.040 --> 52:49.620] Go ahead. [52:49.740 --> 52:50.520] How does this... [52:50.520 --> 53:03.100] How does something like this help prevent, like, say, a full loop attack or some type of open SSL attack on the database where the original data entry is done? [53:03.440 --> 53:12.640] Like, say, a hospital administrator that's entering patient information, right, and that original data that's given to them, it's just real SSMs, right? [53:12.880 --> 53:12.960] Right. [53:13.140 --> 53:14.380] So that's entered in there. [53:15.300 --> 53:15.780] Um... [53:15.780 --> 53:16.540] And then it's... [53:16.540 --> 53:22.480] It's at some point anonymized and encrypted and transmitted up to a centralized server, right? [53:22.740 --> 53:22.880] The... [53:22.880 --> 53:24.900] You actually... [53:25.210 --> 53:29.400] Remember a couple of seconds ago, we saw the information that's actually sent. [53:29.560 --> 53:32.960] A row, ID number, and a social security number. [53:33.280 --> 53:33.520] Right. [53:33.720 --> 53:46.280] Once that's anonymized, that gets sent back to the end database that you then replace all the social security numbers with the alias. [53:46.360 --> 53:47.160] The original database. [53:47.480 --> 53:48.460] The original database. [53:48.460 --> 53:49.080] Yes, sir. [53:49.160 --> 53:50.800] So that's... [53:50.800 --> 53:51.980] So the... [53:51.980 --> 54:04.660] Supposed prevention against some type of attack like that is that, let's say, you do some type of a full loop exploit and early services being stolen, which certainly does happen, especially in hospitals, right? [54:04.860 --> 54:05.360] No, never. [54:07.240 --> 54:13.740] That the data that you would find from that is just a bunch of anonymized information at that point. [54:13.880 --> 54:16.280] It's not the original data that was entered? [54:16.660 --> 54:17.180] Absolutely. [54:17.180 --> 54:18.300] And what in... [54:18.300 --> 54:19.240] What actually... [54:19.240 --> 54:23.680] You can give that data, you could even put that server in China. [54:23.840 --> 54:26.320] Not that I'd recommend that, but you could put it in China. [54:26.920 --> 54:32.260] And they can mine against the data without any risk of compromise. [54:32.260 --> 54:36.500] Because the SSNs don't exist anywhere within the dataset. [54:36.900 --> 54:40.820] Or whatever PII you want to put in there doesn't exist within the dataset. [54:40.820 --> 54:56.200] So is there also some type of a front-end like a custom API or an application in the database front-end that you could offer or help the customer build to help someone prevent something like say just a simple keystroke logger? [54:57.240 --> 54:58.680] Sealing out safe information. [55:01.100 --> 55:06.640] Keystroke logger is probably going to be a better known problem. [55:06.640 --> 55:10.720] And you use, you know, anti-spyware and things. [55:10.940 --> 55:11.000] Yeah. [55:11.960 --> 55:15.340] I mean, then you're getting into something that we really can't control, fortunately. [55:15.580 --> 55:17.400] Kind of a second part of the question. [55:17.560 --> 55:19.980] Maybe not really a question, more of a clarification. [55:20.440 --> 55:33.880] The whole point of this is to view data mining as a good thing and a necessity that sometimes you need to data mine information, like a hospital might need to mine its own data. [55:34.240 --> 55:35.320] That's absolutely correct. [55:41.580 --> 55:51.480] And one of the applications has been we have a customer, a very large customer, that uses us for their customs control. [55:52.180 --> 56:02.660] So when somebody comes into the country, you obviously don't want, you know, everybody and their brother to figure out that you went into that particular country. [56:03.480 --> 56:07.660] So they anonymize the information, store it securely, and then... [56:07.660 --> 56:10.920] As far as the databases go, there's an encrypt... [56:10.920 --> 56:13.520] Essentially, you're doing an encrypt, decrypt call. [56:13.800 --> 56:18.060] We've got server agents that run against multiple databases. [56:18.660 --> 56:24.420] So, you know, whatever you're using, you just make a call, like an API. [56:25.140 --> 56:26.940] How the hell do I keep doing that? [56:29.840 --> 56:30.820] Ah, I found it. [56:31.040 --> 56:31.480] Side button. [56:32.200 --> 56:32.700] All right. [56:33.800 --> 56:38.280] You and you, we probably need to talk afterwards, if you feel up to it. [56:38.580 --> 56:39.320] Anything else? [56:40.380 --> 56:41.140] I'm here. [56:41.640 --> 56:42.360] Thank you. [56:43.880 --> 56:44.500] Thank you. [56:44.600 --> 56:47.320] Thank you, everybody, for coming and tolerating my rambling. [56:49.000 --> 56:49.480] And... [56:54.120 --> 56:58.740] I hope a few of you have checked out the site and pulled some of this stuff down. [56:59.000 --> 57:06.800] Like I said, you can hear my voice drone on for a few minutes, but it actually makes a little more sense, probably, because I'm not up here rambling. [57:07.560 --> 57:08.040] So... [57:08.940 --> 57:10.660] Do you want to gab for a couple? [57:23.000 --> 57:25.540] I have a question about the battery in the truss. [57:25.720 --> 57:26.140] Sure. [57:27.480 --> 57:28.440] So, if... [57:28.440 --> 57:29.100] In the medical... [57:29.100 --> 57:29.960] Oh, one more thing. [57:30.120 --> 57:32.080] I brought a couple of folders, if anybody wants them. [57:32.620 --> 57:33.100] There.