I'm excited to share this Case Study for Quantum Entropy Injection into HSMs for Post Quantum Cryptographic (PQC) Key Generation that our amazing PQC team and I recently completed. In cybersecurity, entropy is the measure of randomness in a string of bits. In cryptography, entropy is used to produce random numbers, which in turn are used to produce cryptographic keys. As entropy increases, randomness gets better, keys become more difficult to determine, and security improves. Entropy is also important for the generation of random numbers and other critical security parameters such as seeds, salts, and initialization vectors for cryptographic algorithms. Financial institutions must deal with the constant risk of cyber-attacks, underlining the responsibility to maintain and strengthen digital security for customers’ trust and integrity. A foundational step for addressing these issues is generating stronger cryptographic keys with better entropy (as part of a broader Defense in Depth PQC strategy). Using random bits (from quantum sourced entropy) that are proven for improved randomness and unpredictability is pivotal for both today’s classical cryptography and tomorrow’s quantum resistant cryptography. Wells Fargo, Thales, and Quantinuum, working in collaboration, demonstrated the ability to generate strong cryptographic keys within the cryptographic boundary of a Thales Luna HSM, a FIPS 140-2 level 3 cryptographic module with external entropy. The keys were generated using random bits with verified quantum entropy acquired from the Quantinuum Origin trapped ion-based quantum computer and validated using the Bell Test to prove it met the threshold for quantum entropy. This cryptographic solution gives Wells Fargo a proven quantum entropy source to generate ultra-secure keys that can be designed and deployed at scale.
Blockchain For Data Management
Explore top LinkedIn content from expert professionals.
-
-
Last week's White House Executive Order on advanced cryptographic attacks provided more clarity on timelines that have been missing from the post-quantum conversation. 2030 for key establishment. 2031 for digital signatures. The order applies to federal information systems first, but it extends the urgency to critical infrastructure operators, federal contractors, and any organization in regulated industries that follows federal procurement standards. My colleague Anand Oswal wrote about this clearly this week. The point that should land hardest with boards: adding support for post-quantum algorithms is not the same as safely migrating to them. You can have systems that technically support the new standards and still not be ready to use them at the scale and pace the timeline requires. The pattern should sound familiar. This is the same architecture we have been writing about for AI security. You cannot secure what you cannot see. Visibility leads, then assessment, then protection. The Discover, Assess, Protect sequence from yesterday's unified approach post applies just as cleanly to cryptographic readiness. The five actions Anand lays out track to the same operating model: 1️⃣ See cryptographic exposure across all environments. 2️⃣ Prioritize authentication, high-value assets, and long-lived sensitive data. 3️⃣ Modernize trust infrastructure to support evolving standards. 4️⃣ Automate cryptographic change so spreadsheets are not the operating model. 5️⃣ Govern readiness as a continuous discipline rather than a one-time project. The harvest now, decrypt later risk is the part most boards have not fully internalized. The data adversaries are capturing today is the data they plan to decrypt later. Organizations holding sensitive information with a multi-year shelf life have less time than the 2030 and 2031 milestones suggest. The Cryptographic Reset is already underway, and the window to organize a response is still open. The first step is visibility. https://lnkd.in/dTfyudrH
-
Why Blockchain Might Be the Trust Layer AI Desperately Needs. Think of blockchain as the flight recorder for AI. If AI is the engine of the future, blockchain is its black box—and its seatbelt. We don’t need more “responsible AI” panels. We need architecture. Guardrails. Proof. And that’s where blockchain steps in—not as hype, but as infrastructure for ethical, accountable, and trusted AI. Here are five key insights from the new INATBA - International Association for Trusted Blockchain Applications Task Force report: 1. Trust Can’t Be Retrofitted - AI systems are only as good—and as fair—as the data they’re trained on. - Yet bias still permeates: one algorithm used healthcare costs as a proxy, disadvantaging Black patients. - Another penalised CVs with the word “women’s”. - Trust must be baked into AI from day one—and blockchain’s immutable audit trails can make that possible. 2. Blockchains = AI Black Box Breakers - Blockchain doesn’t make AI smarter. It makes it safer. - Decentralised governance, transparent data provenance, time-stamped model updates—these aren’t buzzwords. - They’re the difference between explainable AI and inscrutable automation. 3. DAOs Can Democratise AI - Want AI that works for society, not just the powerful? - DAOs (Decentralised Autonomous Organizations) allow ethicists, communities, and regulators to co-govern AI models—approving data sets, funding audits, and rejecting unethical updates. - Think of it as participatory AI, not extractive AI. 4. Ethics at Scale Requires Code, Not Just Principles - Blockchain smart contracts can enforce ESG benchmarks in real time—triggering alerts or pausing systems if thresholds are breached. - ZK-proofs (zero-knowledge) let you verify an AI model meets ethical standards without exposing proprietary code. - This is ethics-as-a-service, not just ethics-as-a-slogan. 5. Energy Efficiency and AI: Friends or Foes? - Training one large AI model can emit as much carbon as five cars over their lifetimes. - But with blockchain-enabled smart grids, AI can optimise renewable energy flows. - Proof-of-stake + AI coordination = decarbonisation enabler, not threat. So What? - AI is moving faster than policy. Faster than comprehension. - Blockchain gives us the tools to slow it down just enough—to verify, govern, and trust what we’re building. Great work Mariana de la Roche Wills, Mat Yarger, Prof. Dr. Ingrid Vasiliu-Feltes, Dr. Tan Gürpinar
-
Most people think their password manager's server is the fortress. It shouldn't be. In a team environment, the server should be nothing more than a blind postman. When we talk about credential security, the real question is: Where does the math happen? If cryptography runs on the server, you aren't just trusting the math, you’re trusting the vendor’s employees, their infrastructure, and their cloud provider. True security architecture requires a shift: >Key Generation: Happens on the user’s device. >Execution: Cryptography runs entirely client-side. >Visibility: The server only sees encrypted blobs. I’ve been digging into passbolt’s approach. By building on OpenPGP standards and ensuring the server never touches plaintext, they move the security boundary back to the user’s machine. It’s about moving from "Trust us" to "Verify the architecture." Are you prioritizing where your encryption happens, or just that it happens? https://lnkd.in/e9GU-Hz9 #ClientSideEncryption #OpenPGP #SecretManagement #Passbolt #EngineeringFirst
-
#blockchain | #carbonmarkets | #sustainability | #ESG : Integrating Satellite Imagery and Blockchain Technology for Enhanced Monitoring. Integrating blockchain technology to enhance environmental regulations and the carbon market can presents several key advantages: ● Enhanced Transparency: Blockchain's immutable ledger offers stakeholders unprecedented transparency throughout the carbon offset supply chain, reducing the risk of fraud or misinformation. ● Traceability and Accountability: By linking geolocation metadata to individual trees on the blockchain, stakeholders can verify the location and status of carbon offset projects, ensuring accountability and authenticity. ● Efficient Monitoring and Compliance: Blockchain enables efficient monitoring of compliance with environmental regulations and carbon market standards, mitigating the risk of non-compliance. ● Mitigation of Fraud and Double Counting: The immutable nature of blockchain prevents fraudulent activities such as double counting of carbon offsets or misrepresentation of projects, ensuring the integrity of carbon offset transactions. ● Dynamic Carbon Accounting: By linking CO2 absorption data to trees on the blockchain, stakeholders can dynamically adjust carbon accounting based on changes in forest conditions and prevent the issuance of invalid offsets. Combining Technologies for Enhanced Monitoring Satellite imagery for better environmental monitoring and law enforcement has been used for years, such as government monitoring systems that use satellite images to monitor deforestation-related crimes. The inclusion of blockchain technology in these efforts can now bring more accurate, transparent, and tamper-proof data. With satellite imagery providing real-time, high-resolution images of the land, allowing for detailed monitoring of environmental changes, the blockchain can ensure that the data collected from satellite imagery is stored in a decentralized and immutable ledger. This guarantees that the final information processed by satellite images cannot be altered or hidden in the event of an environmental crime. Another example is the ability to detect and report changes taking place in forested areas. Satellite imagery provides a continuous monitoring of vast areas in almost daily frequency to identify and monitor changes in the environment conditions, while #smartcontracts on the blockchain could implement these monitoring systems on the environment, where stakeholders can access deforestation alerts in smart contracts in real time and see any changes in the forest carbon stocks.
-
When trust can’t be compromised, blockchain becomes the default. A Coimbatore-based startup is now piloting blockchain-powered product verification for sectors like medical devices and electronics. The system tracks origin, movement, and handling through each step of the supply chain and logs it all on-chain. In industries where tampering or counterfeiting isn’t just a loss, but a risk to life or safety, the stakes are high. Traditional systems rely heavily on manual checks and siloed data, which often fail under pressure. With blockchain, every step is recorded immutably. -Smart contracts automate verification. -Auditable logs replace assumptions with certainty. -Data is shared across stakeholders without compromising control. These are early pilots but they signal a shift. Blockchain is no longer just infrastructure for crypto transactions. It’s starting to anchor trust in physical systems where accountability has long been hard to enforce. And when that shift happens quietly, through working prototypes, it usually means the tech is finally doing its job. #web3 #blockchain #smartcontracts
-
The tension between maximizing data utility and upholding stringent privacy is a defining challenge. How can we leverage sensitive information for analytics, AI training, or collaborative research without ever exposing the raw data itself? Homomorphic Encryption (HE)—a cryptographic approach that promises to solve this dilemma. Imagine performing computations directly on encrypted data, without any need for decryption. It's like giving someone a locked box, letting them process its contents, and getting a new locked box back, all without them ever seeing what's inside. Where could this technology revolutionize data privacy? ✅ Cloud Computing: Securely outsourcing powerful analytics or privacy-preserving AI/ML model training to untrusted cloud environments, maintaining data confidentiality end-to-end. ✅ Healthcare & Genomics: Facilitating collaborative medical research across institutions on encrypted patient records or genomic data, accelerating breakthroughs without compromising individual privacy. ✅ Financial Services: Enabling fraud detection, risk assessments, or credit scoring by analyzing encrypted financial transactions, ensuring regulatory compliance and protecting sensitive customer portfolios. ✅ Government & Defense: Enabling secure intelligence sharing and processing of classified data in multi-party or untrusted environments. However, the challenges are: 🔴 Performance Overhead: Current HE schemes are computationally intensive. Operations on encrypted data are significantly slower and resource-heavy compared to plaintext operations, making real-time applications a hurdle. 🔴 Complexity: Implementing and securely managing HE systems requires deep cryptographic expertise, posing a barrier for many organizations. The learning curve for developers is steep. 🔴 Data Expansion: Encrypted data often becomes significantly larger than its original plaintext, leading to increased storage and bandwidth requirements. 🔴 Limited Operations (Historically): While strides have been made, not all complex operations are equally efficient or even possible with current HE schemes. It's a highly specialized toolkit. 🔴 Bootstrapping: A key technique required to "refresh" noisy ciphertexts to allow for more complex computations, but it's one of the most computationally expensive steps. Despite these hurdles, the progress in libraries like SEAL, HElib, and TFHE is truly remarkable. It promises a future where data utility and privacy can coexist. What are your thoughts on Homomorphic Encryption's potential impact on cybersecurity and data privacy? #DataSecurity #Encryption #HomomorphicEncryption #SecureData #DataPrivacy #CyberSecurity #SecureProcessing #CloudComputing #TechInnovation #DataProtection
-
We discuss data security in terms of encryption, but we rarely stop to consider the moment when data is most exposed: during computation. This point is where traditional methods show their limits and where confidential computing becomes essential. Encryption at rest and in transit has become standard in cloud infrastructure. It protects databases and communication channels, but once data is loaded into memory for processing, it typically becomes vulnerable. That is the weak link many overlook. Confidential computing addresses this gap. By using hardware-based isolation and encrypted memory, it ensures that even during use, data remains inaccessible to unauthorized access. This approach does not replace existing protections; it completes them. As cloud adoption grows and privacy regulations tighten, safeguarding data in use is no longer optional. It is a necessary evolution in how we think about trust, transparency, and responsibility in digital infrastructures. #CloudSecurity #ConfidentialComputing #DataProtection #PrivacyByDesign #Cybersecurity
-
Why next-generation AI analytics may need a blockchain trust layer? AI analytics is moving from dashboards to decisions. As that happens, trust becomes more important than raw performance. Many organisations already struggle with questions like: Where did this data come from? Which model produced this result? Can we prove this decision was fair, unchanged, and compliant? Industry research increasingly points to trust, provenance, and auditability as the biggest blockers to scaling AI analytics, especially in regulated sectors like public services, finance, and healthcare. A blockchain trust layer can help by: 🔐 Providing immutable records of data lineage and model versions 🧾 Creating tamper-proof audit trails for analytical decisions 🤝 Enabling cross-organisation analytics without sharing raw data 📜 Supporting compliance and explainability by design This is not about running AI on-chain or crypto hype. The compute stays off-chain. Blockchain acts as a trust backbone for governance, accountability, and verification. As AI analytics becomes a system of record for decision-making, trust may be the defining feature of next-generation platforms.
-
Dear IT Auditors, Database Audit and Encryption Review Data is only as safe as the encryption that protects it. When encryption controls fail or are poorly implemented, even strong firewalls and access controls cannot stop data exposure. That’s why auditing database encryption processes is a key part of every IT and cybersecurity audit. 📌 Start with the Encryption Policy Begin by reviewing the organization’s data encryption policy. It should define which data must be encrypted, the standards to follow, and the roles responsible for managing encryption keys. Policies that lack detail often lead to inconsistent implementation. 📌 Encryption at Rest Verify that sensitive data stored in databases is encrypted at rest. Review configurations in tools such as Transparent Data Encryption (TDE) for SQL, Oracle, or cloud-managed databases. Ensure encryption algorithms like AES-256 are used rather than weaker ones. 📌 Encryption in Transit Data moving between applications and databases should be encrypted using secure protocols such as TLS 1.2 or higher. Auditors should test whether unencrypted connections (HTTP, FTP, or old JDBC strings) are still in use. Any plaintext transmission is a data leak waiting to happen. 📌 Key Management Controls Strong encryption is meaningless if the keys are weak or mishandled. Review how encryption keys are generated, stored, rotated, and retired. Confirm that keys are held in a secure vault or Hardware Security Module (HSM). Keys should never be hard-coded into scripts or shared via email. 📌 Access to Keys and Certificates Only a limited number of trusted individuals should access encryption keys. Review access lists for key vaults and certificate repositories. Each access should be logged and periodically reviewed. 📌 Backup Encryption Backups often contain full copies of production data. Verify that backup files and storage devices are also encrypted. If backups are sent to third parties or cloud storage, ensure that the same encryption controls are applied. 📌 Decryption and Recovery Testing Encryption isn’t complete without successful decryption. Review whether periodic recovery tests are performed to confirm that encrypted backups and databases can be restored correctly. Unrecoverable encryption is as dangerous as no encryption. 📌 Audit Evidence Key evidence includes encryption configuration files, key management procedures, access control lists for key stores, and decryption test reports. These show that encryption controls are both effective and maintained. Effective database encryption builds resilience. It ensures that even if an attacker gains access, the data remains unreadable and useless. Strong encryption is both a commitment to trust and a technical safeguard. #DatabaseSecurity #Encryption #CyberSecurityAudit #ITAudit #CyberVerge #CyberYard #DataProtection #RiskManagement #KeyManagement #DataGovernance #GRC #InformationSecurity
Explore categories
- Hospitality & Tourism
- Productivity
- Finance
- Soft Skills & Emotional Intelligence
- Project Management
- Education
- Leadership
- Ecommerce
- User Experience
- Recruitment & HR
- Customer Experience
- Real Estate
- Marketing
- Sales
- Retail & Merchandising
- Science
- Supply Chain Management
- Future Of Work
- Consulting
- Writing
- Economics
- Artificial Intelligence
- Employee Experience
- Healthcare
- Workplace Trends
- Fundraising
- Networking
- Corporate Social Responsibility
- Negotiation
- Communication
- Engineering
- Career
- Business Strategy
- Change Management
- Organizational Culture
- Design
- Innovation
- Event Planning
- Training & Development