Quantum, AI, and Cybersecurity: A New Era of Digital Defense
Quantum technology is gaining traction, especially in cybersecurity. Retired U.S. Army Brigadier General Paul G. Craft shares insights from his experience in the Department of Defense, emphasizing the shift from human to computer-based threats. CEO and Cofounder Lance Smith introduces Cy4Data Labs, highlighting their encryption methods for data protection. The role of AI in cybersecurity is discussed, noting its benefits and risks. The importance of securing sensitive data and financial implications of data security measures are also covered.
Transcript
Hey, everyone. Welcome back here to Tech Trunk tv. You know, if you haven't noticed over the last couple of weeks, this whole quantum thing has piqued my interest.
And so I've been reaching out and talking to a lot of people regarding Quantum. You know, my friend John Willis, who's actually working on a book on Quantum right now, he, he got me started on this about two, three months ago. And it's, it's just fascinating.
You know, I, I admit it's something you gotta expand your mind to get your hands around, but, um, it's real, it's coming. And I, I want us to be out front here at Techstrong. I've invited our next guest on, because they're doing some interesting things around quantum and quantum proofing and quantum cyber threats, post quantum encryptions, all all of these things.
We we're gonna live in the day after Q Day and of, you know, who, we don't know when Q Day is, but when it's here, we'll tell, let you know. Let me introduce you quickly to Lance Smith. Lance is the CEO and co-founder of a company called SCI four Data Labs, cipher Data Labs.
I hope I pronounce that right, Lance. Right on. And also joining Lance and I is General Paul G.
Craft retired, who's on the board of advisors for Cipher Data Labs and is a, a former US Army chief of cyber and, uh, chief of cyber as well. Um, gentlemen, welcome to Techstrong tv. It's great to have you on here.
Thanks Tha thanks for having us. Nice to be here. So guys, I, I always like to give our audience a flavor of who they're talking to.
Of course, I, I gave them your titles, that's nice. But give us the story behind the title. Lance, if it's okay with you, I'm going to defer to the general and let let General Kraft go first, if it's okay.
Absolutely. That'd be fantastic. Go ahead, general.
Alright, well, I appreciate that. So, uh, again, uh, uh, general Paul Kraft, I was, uh, I retired as the Deputy Commanding General for Army Cyber Command. And so my responsibility, uh, in that role was really about cybersecurity, uh, for multiple locations around the world.
Uh, and before that, I was the chief of cyber for the US Army and really ran cybersecurity for the DOD securing White House, the Pentagon, and really our, um, our entire DOD network with, for the Defense Marine Systems Agency, and really the National Security Agency. Um, what I encountered every day was, what we always talk about, Alan, what you talk about, you know, every week, is that that constant threat, that ever changing threat, the concerns that we have, and as we really, we know, we all realize that we're gonna shift into a quantum and then post quantum world, a a as a person who really ran a lot of the cyber operations, even on the offensive side within the DODI knew that if I had enough time, enough energy, enough people, eventually we could asai, you know, asai that target. Uh, but we were using very conventional methods and we knew what we were doing.
And, and I'll tell you, there was a time in my career where I knew I was fighting a person, but based on the speed at which they were attacking the speed at which we could defend. Um, but then it shifted and I realized I was starting to fight computers and I wasn't fighting people anymore because it became a constant, uh, a constant fight, a constant, um, effort that now we couldn't just deal with people against machines. So as we, as we lift and shift into the pros quantum world, and as I, uh, I retired, I knew there was a couple things I wanted to do in my, I'll call my retirement, if you want to call it retirement.
And that was the fine solutions that I know that we need, our nation needs, our, our Department of Defense needs inside this space. 'cause while we have played traditional cybersecurity in the space of basically a castle defense perimeter security, midpoint security, and endpoint security, I knew it was all about the data. We know it's all about the data, and it's that data that we wanted to make sure that we, we can secure.
And so finding companies like Lance's, um, with CY four Data Labs, it's one of those companies that is now reaching that point that I know that we need in order to fight against, um, well today computers. But tomorrow, computers at a speed that people don't even understand. It's not even fathomable as we hit that quantum and then post quantum space, we know that it's coming.
We don't, Alan, you know, we don't know when it is. Um, but I'm excited to, I'll, I'll say transfer over to our CEO, um, Lance Smith to talk, you know, to give his intro and really then really get into a discussion about what CCI Four Data Labs can do. So thank you very much for having us, Alan.
Thank you. General pleasure. And thank you for your service.
I, I'd love to sit together with you, and I'm sure you've got some tales to tell. Lance, how about you? Yeah, tha thanks Alan.
Uh, again, my name is Lance Smith. Uh, I'm the CEO and, and co-founder for Cipher Data Labs. You know, my background is, uh, is an interesting one from the perspective that I grew up in Silicon Valley.
I have the of fortunate luck of being around, you know, some luminaries, uh, you know, some, uh, uh, thought thinkers about what does it take to develop some of these technologies starting out at, uh, Santa Dakota University with a background in, uh, microprocessors, um, with a, with a focus on semiconductor physics. The journey that I have taken, um, has seen me, uh, experience, you know, this, this idea of a personal computer, its architecture and its impact as it is, uh, become a dominant force, you know, within, uh, you know, our computing worlds. Today, I got to see next generation X 86, uh, microprocessor architectures being developed to sit show, to show with these architects.
And it's, uh, taken me down a path where, you know, I've been with companies, um, you know, previously the president and Chief operating officer of Fusion io, where we created, you know, the first most reliable, high performant, um, flash-based, uh, enterprise class drives, you know, for the PC industry. The interesting part was my exposure there was trying to figure out how to take a memory tier and make it usable in the marketplace. And the one place that we found great success was accelerating databases.
Now, I, I tell you this background, because previously worked on, um, uh, security engines, accelerators, uh, network processors spent decades looking at what, what does traffic look like when you know when someone is doing good? And then when the nefarious trying to figure out how to penetrate, uh, an environment and, and to protect it in real time, you know, at, at, at full performance. And then we got faced with, uh, these databases, how to make them go faster.
And customers would ask us, well, how do we go about securing it? Right? And so today's industry, um, has a couple tools and there's, there's two pillars really, that it's missing.
One, which is the idea of protecting data at rest versus, uh, data in flight. But there we had this question about data in use. And so about six or seven years ago, I met up with, uh, one of our other co-founders, uh, Todd Harper, who has some 35 years of developing technologies for the, uh, uh, credit card and smart card industry.
And this guy's seen it all. So we put our heads together and we said, alright, what's going on here with this idea of data breaches? So Paul, Paul makes some interesting points about these attackers.
They look for, you know, this, this easiest path, um, to get to data itself. But we were watching what was happening in the industry five, six years ago. We said, you know, there's something wrong because, um, we, we see this clue that data breach will happen.
And then there's this idea of a record, and this is where it led us to look at databases and say, well, there's a vulnerability there. Okay, well, what about all these threats? Well, hopefully we'll be able to talk, uh, in depth about quantum computers and what that threat looks like.
Uh, ai, it's accelerating these types of attacks, uh, human error, uh, that, that infiltrates, um, uh, unknown vulnerabilities. Those are common. Well, we, we asked ourselves, well, what if we had no security?
Could we still protect the data? So when we put this company together, we had to say, could we protect the data in plain sight? Could we actually just protect the data itself at the data layer?
So then we got to work, we took a look at the various types of cryptography that existed. Um, NIST does a tremendous amount of work to create these algorithms and validate them, but could we deal with the insider attack? What if you lost your credentials?
Again, if there was no perimeter, this castle idea and, and a moat that's around it that Paul was talking about, could we still protect that data? And that's what we came up with, uh, cipher Data Labs. I love it.
What a great story of how, of how that came about. Now, of course, we, you know, I was listening to you speak, Lance, and I'm thinking AI had to have, you know, just accelerated the heck outta this, right? And everything today, you can't walk two steps without tripping over something with ai.
And, and, and in some ways, AI and quantum is, is linked. I don't know if it's a quantum linkage, if we could call it entanglement, if you will, but it, it, it is linked, right? We, we are, but AI in and of itself is changing the game in, in, in data.
You know, how, how we're moving data, how we are, uh, using data, how, and how we're securing data, right? It's, it's, it's putting more pressure in an already very pressured environment. Mm-hmm.
Right? The flip side is a lot of companies are using AI to, to help defend the, the, you know, the mission. So it, it is a two-edged sword, but it certainly is a, a bit of a game changer there.
Um, so we talked about data at rest, we talked about data in transit, and we talked about data in use, right? Kind of the three phases of data, if you will. Um, what else are we, you know, now we're, and, and Grant, you know what, NS got out ahead.
We've got some post quantum algorithms that, that are available, you know, quantum proof algorithms supposedly, that are available out there. What, what are you guys doing at SCI four data to prepare for this post quantum world, if you will? Uh, you know, if, if, if I may sort of open it up and I, I'd like to have Paul jump in on this.
W let's talk about the quantum fusion that in that threat real quick. You know, we, we can talk about, you know, the speed at which these things can potentially run. The idea behind breaking some type of encryption algorithm really was focused, uh, in secure communications.
That's what we're really worried about. You know, when you're communicating between two computers, a person in, you know, a server, can you protect those bits that are in flight, right? And the, this is for the man in the middle attack.
And the threat here is this harvest today in, in break tomorrow. And the algorithms that are used on that, uh, I dunno, backend, like 1994, Peter Sho, MIT, uh, came up with an idea, an algorithm right at that if we had a quantum computer, uh, they took this position where they could take advantage of it and literally break these public, private key based, um, or asymmetrical, um, uh, type of encryption algorithms. And the proof is starting to show up, right?
We have commercially available quantum computers. They're not terribly big. Um, they are fast, and we're starting to break more and more bits, like take RSAs.
You know, one of the examples there have been, uh, you know, starting with like Lockheed, um, you know, some 15 years ago they were breaking in the order of 10 to 12 bits, right? And then, uh, uh, Purdue moved it up, you know, to, uh, like 16 bits. But Shanghai University, now, they took it from 50 bits last year, 10 90 bits this year that they were able to break.
So this path, you know, or this trajectory as to whether quantum computers are real and q a's gonna happen just in the last week or so, stability of the qubit, the number of logical bits that they're able to create, air correction, all these things are pointing to the fact that you could steal and harvest those communications and then break them. So we, you know, if I take us back to this idea of protecting data itself, that it defines, quite frankly, the data, then we work in conjunction with any other security that exists today. Look, RSA, Diffy, Hellman and Elliptic Curve, uh, cryptography are all safe today using, you know, classic computer attacks.
AI getting thrown into the mix is what's making this really difficult, because they can do more sophisticated phishing. Um, they can do it more often. They literally can take the, uh, common vulnerability exploits, which last year there was some 40,000 that were posted.
We're on track this year for about 45,000. Another record, mind you. And they can use that as input into their AI engine, right?
You're saying it's a double-edged sword. These, uh, these criminals, these cyber criminals now can say, Hey, ai, take a look at, you know, all of the common vulnerabilities that a particular customer I want to target. Maybe, you know, the products they're using, maybe using, and then, you know, come up with a, you know, an approach so that I can go, uh, attack their perimeters and get in.
And this is, this is kind of the big problem. If I have a set of credentials that are the gateway into this network, into this perimeter, you get access to everything, right? Can horizontally move an attack?
But what if we took an encryption key and able to encrypt down to a single word or a field of a record? Now, if you have like a hundred fields on a record, you need a hundred encryption keys to break one record. And if I have a million of those, you need a hundred million keys.
That's the basis of this idea. So we took, you know, computer architecture, database architecture, encryption, using the encryption algorithms that are unbreakable, like A-E-S-A-E-S-S 2 56, um, or other ideas where you, uh, you know, we went back to American Ngenuity using something like, um, the concepts of one-time pad where you have a dedicated key, um, that's sufficiently random applied to one piece of data. That's, that's the approach that we're taking.
Yep. So, and, and general, you know, you, you probably dealt with this, the issue then becomes the what's the cost of doing that? Can I afford to do it to all my data and probably not.
So, you know, now I've gotta create data hierarchies of classified top secret, top, top secret. You know what I mean? And that's how much I'm willing, how much money I'm willing to put behind how, you know, it's a risk management issue, which all security comes down to risk management, right?
Um, and, and, and then, but, but the real threat here is, in my mind anyway, look, a guy who's looking to steal your personal identifiable information probably doesn't have quantum computing or even high performance computing in his pocket or their pocket. But these attacks are coming from nation states and these nations. If Shanghai University is publicly saying they're doing, what is it, 50 or 60?
Uh, bid encryption, breaking it, what's the CPL, uh, excuse me, the, the, uh, CCP doing in their labs apps, right? And that's the real danger here, right? Yes.
There is a, there's a crap load of hashed up tar balls of stuff they've stolen over the last, you know, 10, 15 years. And, you know, the good news is as time goes on, that information becomes less valuable and less useful. But make no mistake, it's the nation states.
And in general, I would imagine, you know, that better than anyone, I don't know if we could talk about it, but it's the nation states for all I do, we know if they even have a functioning quantum computer already, Well ought just say, just say, you know, unclass, right? Utterly unclassified is we have to assume, you know, all things, uh, all, all things are possible. And that, you know, you've got a lot of people that are even working together, uh, military, paramilitary, governmental, you know, forces as you mentioned, cyber, cyber criminality, you know, is alive and well.
And, and you can go, uh, you know, on the dark web and, and actually buy compute. You can buy, uh, you know, a vulnerability library and then apply it to AI and then throw, throw that at something and see, basically it's a bunch of keys. And you can try a whole bunch of keys to try to get into a lock.
The the thing that's exciting in, in CIFOR data labs that I've kind of put, you know, as a, you know, as a general on the board, is to help Lance and team, you know, get them to the finish line here, is, um, he, he, I like how they're going down two paths. One is to convince the operational, you know, community about how this key encryption works, where you can look at a database and Lance, and with the technology they have, they can encrypt the row by itself. They can encrypt the, the, the, I'm sorry, the column by itself, the row by itself, and then the field.
And so you've triple encrypted every single thing. Well, it's not triple, it's, it's, it's, it's three times three three to the third. Yeah.
Right? It's not just three times we've Done. Yeah.
And so we've done that operationally to show operationally like how advanced this is, and at the same time, take 'em down that hard junket path path of academics. So there's a lot of, you know, folks in the academic world that understand this. He theoretically have never done it operationally.
And so Lance is also, uh, winning the hearts and minds in the academia world of showing the math, go into the board, showing the math with a bunch of his PhDs on like, no, no, let me show you how this works. And we're, um, we're racing a lot of eyebrows in the academic community, uh, who are saying like, oh, like, uh, we, we actually see how you're able to do this as you drive right toward one time pad, you know, solutions. And so it's one thing to show it operationally.
It's another thing to also get the endorsement, you know, of the academic policy side of things, of showing that it really is what we say that it is, um, that's out there. So they, they've, they're much more advanced than I've seen other companies that are in that same space where, 'cause they're willing to show, I'll say, show the math, show their code and understand what they're doing, show Their work. We used to, what used to teach us, show the in school.
You gotta show your work, Lance. I'm gonna throw the, the issue that I raised earlier though. At what, at what price do you know, do I, at what price do I get this type of security?
Can I, is it a, is it, so I I good friends, if you're familiar with Splunk, yeah, right? The company Splunk's part of Cisco now. Yeah.
When I first saw Splunk, man, I fell in love with it. It had the ability to capture data from every kinda log, file, everything, store, everything. I can look at everything, right?
May be able to not look at it right now, but eventually I'll be able to look at everything. But then people quickly ran into the problem of, if I can't afford to store everything, okay, I gotta figure out what, what is worthy of me storing what is, and so that's the issue I have, or the question I have for you in regard to Cipher Data Labs technology, right? Is this something where I encrypt every darn database I got?
Do I, you know, how do I allocate? And, and it's, it's a dollars and cents question at the end of the day. There's a couple of buckets of costs we should probably talk about.
Um, first and foremost, we designed this to be, uh, completely transparent. Like you don't know this is actually occurring. We should also point out that our focus is on what we'll just deem it or termed as, uh, sensitive data.
The, the data that has the most value is what we're really concerned about, right? So the personal identifiable information, personal health information, numerical values, that, that, uh, where mathematical operations we've performed on it, like social security numbers, yes, they're based on numbers, but technically you never, you know, multiply them by two or divide by 12, um, zip codes, right? These are ones that help identify who people are their first name, their last name, their address, things of that nature.
Those are what we're really focused on. So it technically doesn't need to be every single column, row or field, the ones that have the most monetary value to someone, you know, a, a, a perpetrator that wants to, um, uh, exultate that information so that they can, you know, hold it ransom, right? So to do double extortion, that's what we're really focused on.
You could do, you know, many more things, but that's literally what our number one focus is. But when you do this, it's all in situ two. Now, this is the benefit of how we've approached this.
Now, I said earlier that it was at the data layer. Okay? So it, it's not an OSI model, okay?
It's kind of below that. When we work on the data itself, we make that encrypted value look like data to the databases. Now we focus on databases.
We can focus on many more things, productivity, apps, communications, you know, if we're sending messages to each other, emails, it's all applicable to it. But our number one focus, 'cause the biggest threat for enterprise and for, you know, like our US government, you know, in, in our entities, especially when it comes to, um, defense, uh, you know, our military, um, over on the academic side, our children, right? I mean, like, can you imagine being like eight years old?
I mean, look, all of us were old enough at eight years old. We did not think about whether someone had stolen our IDs. And now I have to worry about my credit history.
It is the craziest thing, you know, to think about. And so, uh, you know, we want to protect those who can protect themselves. So let's find a way to make it as inexpensive as possible.
The end of the day, we're talking about key data. It's cheap, it's small, okay? It's lightweight.
But when we make it in situ two, in other words, encrypting the word, a single word in a field, it now goes back into the same database infrastructure you got. So we're talking about Brownfield deployments. Everything that our customers or our government has invested in, we don't care if it's five years old, 10 years old, 20 years old, 30 years old, 50 years old.
If it's a database, we make the data, even though it's encrypted, still look like data, it's analogous to like a foreign language. Databases don't care if it's English, French, German, Italian, or Spanish. So now we encrypt it, it looks like data to a database.
Uh, and that's all it's required. We just have to ask it the right question. So, you know, if the database is in German, you better ask it in German.
Don't ask it English. And that's how we approach it. So no impact on performance, no impact on your existing infrastructure.
You could use all the security that you've, if you, that you've invested on and afforded to roll out. We don't care what kind of database, sql, no sql, uh, graph document. Um, because it just looks like data at the end of the day and cost perspective, it's 10th of a penny per key.
We made it inexpensive by definition, so that we want people to use as many keys as they want, protect as much data as they want. So they had a consistent cost, you know, from month to month. Excellent.
Gentlemen, I looked at my watch we're way over time. I got, I gotta kinda wrap up here, Lance, for people who want to get more information about Cipher Data Labs, what's the website? com.
Excellent. And pretty much everything we're talking about today, they can go for themselves and see for it, see it there. And, and this is technology that's available now that they can get their hands on and, and start using.
We've been in production with customers for over two years now. Uh, you know, and we've deployed hundreds of millions of keys that are in production, single databases as much as 80 million keys. Uh, it's quick, reliable, it's fast.
Uh, and we've got, uh, you know, good penetration in, uh, you know, credit, credit bureaus, um, insurance companies, uh, you know, from, uh, yeah, SP 500 right to Fortune 500. Excellent. Lance General Craft.
I want to thank you both for coming on Tech Trunk tv. It's been a pleasure having you on. Again, general, thank you for your service.
Good luck as you set on your second career here, set sale on your second career. Lance, good luck with Cipher Data Labs do keep us posted. Okay?
Will Do. Thank you so much. Will Do.
Thank you. All right, we're gonna take a break on Textron tv. We'll be back.
com. Check 'em out. We'll be back with more on Textron.