Secure Processing Of Sensitive Data While In Use

G T Venkateshwar Rao | Managing Director, Posidex Technologies
GTV brings over 30 years of experience in public administration, technology strategy, and data-driven innovation. A former officer of the Indian Revenue Service, he is widely regarded as a pioneer in the use of data for better governance, fraud detection, and business transformation in Government. Took VRS from Government in 2022 and joined Posidex Technologies.
Linkedin Profile
Table Of Contents

Data has three states

It's accepted that data is in three states:

  1. Data at rest: data stored in databases, files or other storage
  2. Data in transit: data moving between systems
  3. Data in use: data being actively processed by an application or database

Encryption at rest & in transit  have become a standard requirement for enterprises. It is part of compliance checklists, is reviewed during audits and gives security teams a clear answer when they are asked how sensitive data is protected, at rest & in transit

But there is another question that needs to be asked: How is the data protected when it is actually being used? 

This is becoming an important question because the actual  value of data is created only when it is processed. And that is also when the data needs to be available to applications and systems.

The limitation of encryption at rest & in transit

Encryption at rest & transit is important. Technologies such as Transparent Data Encryption (TDE), TLS 1.3, https protect data while they are stored or in transit. But it addresses a specific problem. 

But data doesn’t always remain stored. It has to be processed for business. A database needs to process data. An application needs to query it. An analytics system needs to analyze it. A KYC or AML system needs to match customer information.  Queries have to be executed and applications have to receive results. Data has to be made available to apps and systems. 

Consequently, unencrypted plain text data sits exposed in system memory (RAM), query results, temporary tables, cached files, and system logs. People and any process with higher system privileges can freely access this plaintext data

This creates a window of exposure and attackers exploit this exact window.  They wait for running systems to load decrypted data into memory. Since the exposure window remains open till the data is being processed (or used), there is enough time for a breach to occur.

The consequences of a breach are severe. Regulatory frameworks like India's DPDP Act and the EU's GDPR enforce statutory fines reaching up to ₹250 Crore and €20 million, respectively.

This is where PETs become important

Privacy Enhancing Technologies, or PETs, provide a different approach.

Instead of only protecting the storage layer and then exposing the data when processing starts, PETs can allow operations to be performed on the Data while the underlying sensitive information remains encrypted i.e. “Data to Intelligence or Insights” on encrypted data. PETs introduce a new paradigm of processing on encrypted data. 

The objective is not to stop the application from using the data. The objective is to allow the application to get the information it needs without exposing the underlying PII.

For example, consider customer matching.

A financial institution may need to determine whether a new prospect is ETB/NTB (Existing to Bank or New To Bank). The business process needs the answer. 

But does every application involved in that process need to see the customer's complete PII? Not necessarily.

With PETs, sensitive attributes are protected while the required matching or processing takes place. They protect data without compromising its utility.  Furthermore, even if an attacker exfiltrates data, the stolen information remains fully encrypted and useless.

Protecting data throughout its lifecycle

I don't think encryption at rest or transit is becoming less important. It remains a necessary part of a good security architecture. But it should not be the end of the discussion. As enterprises use customer data across more applications, analytics platforms, AI systems and compliance processes, the amount of time data spends being actively processed is increasing.

We need to think about protection across the entire data lifecycle. at rest, in transit and, increasingly & importantly, while data is in use, which is addressed by using PETs.