Reiner Kappenberger on Securing IoT Data

TL;DR
Protect sensitive IoT data as soon as it enters the infrastructure, while preserving its format so authorized systems can continue processing it. HPE’s software integrates with NiFi and other environments to encrypt data at rest, in motion, and in memory, while stateless key management generates keys on demand and avoids dependence on a specific hardware vendor.
Transcript
Hi, I'm Jason Hiner here at RSAC TV. Uh, I'm with TechRepublic and ZDNet, and with me, I've got a special guest today from HPE, Rainer Kappenberger. Rainer, thanks for being here. Thank you, Jason, for having me. Very good. So why don't you, uh, to introduce yourself to the audience, tell us, uh, tell us a little bit about what you do at HPE. Oh, a... Read More
Key Insights
- IoT security is becoming data-centric because connected devices create growing quantities of sensitive information outside the controls of traditional data centers. HPE’s approach protects that information at the point where it is ingested into an organization’s infrastructure.
- The announced software protects data at rest, in motion, and in memory. Applying encryption across all three states helps prevent sensitive information from becoming exposed while stored, transmitted, or actively processed within an IoT and big-data environment.
- Format-preserving encryption retains the original structure of protected data. A 16-digit credit card number remains 16 digits instead of becoming a long, unusable string, allowing existing processing logic to continue operating without revealing the authentic value.
- Protected medical data can remain analytically useful without directly identifying a person. A blood-pressure value can preserve the appearance and logic needed for abnormality checks, while the real reading and associated employee identifier remain unavailable to an attacker.
- Stateless key management generates encryption keys on demand instead of storing them. HPE presents this model as a way to keep keys available across large IoT deployments while avoiding the latency and risks associated with retrieving keys from traditional stored-key systems.
- Telecommunications operators can encrypt information as it arrives from cell towers. Protecting the data before it enters a staging area reduces exposure to live information, while NiFi can support subsequent analysis and decisions made directly at the edge.
- Manufacturers can encrypt information within the country where it is collected before transferring it to a central location. This approach helps them address varying in-country requirements while reducing exposure of workers, customers, and other people represented in the data.
- The software does not require HPE hardware at the edge. It can run with NiFi, big-data environments, other open systems, and even mainframes on existing infrastructure, with a virtual appliance added for key management.
Install to Summarize YouTube Videos and Get Transcripts
Explore YouTube Video Summarizer or Get YouTube Transcript Extractor
Questions & Answers
Q: How can organizations protect sensitive IoT data at the edge?
Organizations can protect sensitive IoT data by encrypting it when it first enters their IT infrastructure. HPE’s software provides a processor that can be dragged and dropped into a NiFi data flow, applying format-preserving encryption during ingestion. This reduces exposure in staging areas while allowing the protected information to continue through analysis and other operational processes.
Q: What is format-preserving encryption for IoT data?
Format-preserving encryption protects a value while retaining its original structure. For example, a 16-digit credit card number remains a 16-digit value rather than becoming a long string that existing applications cannot use. This preserved structure lets organizations continue applying data logic and processing while preventing attackers from seeing or using the authentic sensitive information.
Q: How does HPE protect data at rest, in motion, and in memory?
HPE applies format-preserving encryption within the data flow so sensitive information remains protected while stored, transmitted, and actively used in memory. Because the encrypted result retains the format and logic of the original value, systems can continue operating on it. This makes encryption compatible with ongoing analysis instead of requiring information to remain exposed during processing.
Q: Can encrypted medical IoT data still be analyzed?
Encrypted medical IoT data can remain useful when its format and analytical logic are preserved. A protected blood-pressure reading can still look like a blood-pressure value, allowing a system to check for abnormalities. At the same time, an attacker cannot recover the real reading or connect it to the authentic employee identifier, preventing identification of the individual involved.
Q: How does stateless encryption key management work?
Stateless key management generates encryption keys on demand rather than storing them. According to Kappenberger, this ensures that a key is available whenever and wherever an IoT deployment needs one, even at global scale. The approach is intended to avoid losing stored keys and to reduce the latency and ecosystem risks associated with traditional key-management systems.
Q: How can telecommunications companies secure cell tower data?
A telecommunications company can use NiFi to collect information from cell towers and encrypt it immediately as it reaches the edge. This prevents live data from remaining exposed in a traditional staging area where an attacker might access it. After protection, the company can analyze the information and use NiFi to support decisions directly at the edge.
Q: How can global manufacturers centralize protected IoT data?
A global manufacturer can encrypt IoT information inside the country where it is collected, then transfer the protected data to a central location. HPE’s software can perform that encryption through NiFi before transmission. This reduces exposure of workers, customers, and others represented in the data while helping the manufacturer address different in-country requirements and use centralized analytics.
Q: Does HPE IoT data security require HPE edge hardware?
HPE’s software does not require customers to use HPE routers, networking equipment, or another specific hardware vendor at the edge. It can operate on existing infrastructure that uses NiFi, big-data environments, other open systems, or even mainframes. The additional component described in the interview is a virtual appliance that provides the key-management capability.
Summary & Key Takeaways
-
HPE’s data security approach moves protection closer to IoT data sources. Its software-based processor can be inserted into a NiFi data flow to encrypt sensitive information when it enters the infrastructure, reducing exposure at staging areas and allowing organizations to protect data at rest, in motion, and in memory.
-
Format-preserving encryption keeps the structure and logic of protected values intact. A credit card number can remain a 16-digit value, while medical readings can retain a usable format for abnormality checks. The protected information appears realistic, but attackers cannot identify the underlying person or obtain the authentic values.
-
The software can operate on existing infrastructure without requiring HPE routers or networking equipment. Telecommunications and manufacturing organizations can protect data at the edge or within its country of origin, then analyze or centralize it with less exposure. Stateless key management supports scale by generating encryption keys whenever they are needed.
Read in Other Languages (beta)
Share This Summary 📚
Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator
Explore More Summaries from RSAC Cybersecurity 📚






Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator