If I were Google I would fund the heck out of homomorphic encryption research.
As Google tries to gobble up even more of everyone's data and every waking habit as they try to improve Google Now and other services, the privacy concerns are only going to grow bigger. It will be not just a drain on their public image (just like it is on Facebook's image), but it would also give competitors a lot more opportunities to take jabs at them. Think Scroogled, but 10 fold.
Homomorphic encryption would pretty much fix all of that, and they wouldn't even need to give up their data collection (or not as much).
Unfortunately not. HE has some performance issues (that might be solveable with time) but the primary issue is that Google do actually want to see exactly what you're doing. It's important for basically everything Google does that makes it money.
Furthermore, the privacy concerns are nowhere near great enough. All of the mainstream privacy concerns have come from Google releasing your information to others (Google Buzz, that recent ECHR case etc) and not Google keeping information themselves. Furthermore, since I assume that what you're really talking about here is emails, it would be impossible to practically implement a HE system for emails that would allow for searching (because one could derive meaning from emails by sending them the right queries). It'd be no better than client-side encryption, and no one really wants that.
No, the people for which this is really useful is large non-IT companies like Boeing or healthcare companies etc. They have huge data processing or storage requirements, and frequently have to run around hoops in order to ensure data is not transmitted in a way that would breach commercial agreements or confidentiality requirements.
The problem is that frequently these workloads (especially for companies like Boeing) will involve much data, and HE tends to come with a large size increase and performance drop - so it's often too costly, which is a shame.
Can you expand a bit more on the type of commercial agreements and confidentiality requirements of Boeing? In particular, what kind of data would the agreements pertain to, and who would the other parties be? Would the 'hoops' occur only for internal data transmission, or is it because they need to share it with 3rd-party organisations? I'm a researcher in the area, and I'm familiar with stuff like that from the healthcare domain, where you have e.g. lots of different hospitals that want to share certain data for research purposes, but I'm curious as to the use cases more commercial organisations might have.
It's neither. They make the assumption that their combined cloud partners aren't all in cahoots, and distribute their data such that the probability that a) one can intercept enough chunks and b) one can infer meaning from the chunks is very low.
The cynical part of me wants to say that it's very similar to a standard mapreduce, and the security properties came for free/very little.
I think you are wrong. Google's current business requires that they are able to match your interests to ads. Contrary to popular belief, it has nothing to do with selling you out to advertisers and it doesn't even strictly require Google to know all about you.
If they can efficiently apply FHE to your data and produce an encrypted set of ads that only you can unscramble, they'll make plenty of money.
It's not at all clear that this is feasible, but if I had billions of dollars burning a hole in my pocket, I'd probably fund FHE research.
No, it relies on them being able to do that, but also to be able to improve their products such that they stay relevant. Things like A/B testing require Google to know what the user is doing in order to test their effectiveness - a FHE setup would ruin that.
In any case, I'm not sure how this would stop them from tracking in the first place.
CHY872 is right. Who benefits most from this are governments, spy-agencies, military and a small a solid number of security-aware civilists. This is right as long as nobody enforces FHE to the government, but I doubt that it would occur in the USA at this time from that side. If it happens at all, which I also highly doubt, then it maybe somewhere in Europe.
Comments
If I were Google I would fund the heck out of homomorphic encryption research.
As Google tries to gobble up even more of everyone's data and every waking habit as they try to improve Google Now and other services, the privacy concerns are only going to grow bigger. It will be not just a drain on their public image (just like it is on Facebook's image), but it would also give competitors a lot more opportunities to take jabs at them. Think Scroogled, but 10 fold.
Homomorphic encryption would pretty much fix all of that, and they wouldn't even need to give up their data collection (or not as much).
Unfortunately not. HE has some performance issues (that might be solveable with time) but the primary issue is that Google do actually want to see exactly what you're doing. It's important for basically everything Google does that makes it money. Furthermore, the privacy concerns are nowhere near great enough. All of the mainstream privacy concerns have come from Google releasing your information to others (Google Buzz, that recent ECHR case etc) and not Google keeping information themselves. Furthermore, since I assume that what you're really talking about here is emails, it would be impossible to practically implement a HE system for emails that would allow for searching (because one could derive meaning from emails by sending them the right queries). It'd be no better than client-side encryption, and no one really wants that.
No, the people for which this is really useful is large non-IT companies like Boeing or healthcare companies etc. They have huge data processing or storage requirements, and frequently have to run around hoops in order to ensure data is not transmitted in a way that would breach commercial agreements or confidentiality requirements. The problem is that frequently these workloads (especially for companies like Boeing) will involve much data, and HE tends to come with a large size increase and performance drop - so it's often too costly, which is a shame.
Can you expand a bit more on the type of commercial agreements and confidentiality requirements of Boeing? In particular, what kind of data would the agreements pertain to, and who would the other parties be? Would the 'hoops' occur only for internal data transmission, or is it because they need to share it with 3rd-party organisations? I'm a researcher in the area, and I'm familiar with stuff like that from the healthcare domain, where you have e.g. lots of different hospitals that want to share certain data for research purposes, but I'm curious as to the use cases more commercial organisations might have.
Yup - Ars can explain it better than me! http://arstechnica.com/information-technology/2014/04/how-bo... Clearly, though, this would be a case where homomorphic encryption would not be required - because they've solved the problem without it.
Boeing's technique sounds more like steganography than cryptography.
It's neither. They make the assumption that their combined cloud partners aren't all in cahoots, and distribute their data such that the probability that a) one can intercept enough chunks and b) one can infer meaning from the chunks is very low.
The cynical part of me wants to say that it's very similar to a standard mapreduce, and the security properties came for free/very little.
I think you are wrong. Google's current business requires that they are able to match your interests to ads. Contrary to popular belief, it has nothing to do with selling you out to advertisers and it doesn't even strictly require Google to know all about you.
If they can efficiently apply FHE to your data and produce an encrypted set of ads that only you can unscramble, they'll make plenty of money.
It's not at all clear that this is feasible, but if I had billions of dollars burning a hole in my pocket, I'd probably fund FHE research.
No, it relies on them being able to do that, but also to be able to improve their products such that they stay relevant. Things like A/B testing require Google to know what the user is doing in order to test their effectiveness - a FHE setup would ruin that. In any case, I'm not sure how this would stop them from tracking in the first place.
CHY872 is right. Who benefits most from this are governments, spy-agencies, military and a small a solid number of security-aware civilists. This is right as long as nobody enforces FHE to the government, but I doubt that it would occur in the USA at this time from that side. If it happens at all, which I also highly doubt, then it maybe somewhere in Europe.