May 2024 Summaries
3 posts from Duality
Filter
Month:
Year:
Post Summaries
Back to Blog
Data clean rooms (DCRs) and trusted execution environments (TEEs) are emerging as key components in the realm of data privacy and AI security, though they serve different purposes and offer unique advantages. DCRs are secure, isolated environments that allow for the collaborative analysis of sensitive data, ensuring compliance with privacy laws but relying on a trusted party for data management, which could pose security risks. On the other hand, TEEs provide a hardware-based secure enclave for confidential computing, enabling multiparty data collaboration without the need for a trusted intermediary, thus enhancing security by encrypting data and computations. Duality, a leader in secure data collaboration, has chosen to support TEEs over DCRs due to their ability to mitigate unauthorized access and maintain data integrity, offering a robust solution for secure data sharing. While DCRs are valuable for complying with current privacy regulations, they risk obsolescence without substantial innovation, as more adaptable and secure software-based privacy solutions emerge. In contrast, TEEs are well-aligned with the demands of Responsible AI, offering strong data governance and compliance mechanisms, making them better suited for future regulatory changes and collaborative innovation.
May 05, 2024
1,004 words in the original blog post.
The EU AI Act aims to establish a comprehensive legal framework within the European Union for the development, marketing, and use of AI, emphasizing human-centric and trustworthy AI to ensure high levels of health, safety, and fundamental rights protection while promoting innovation. This framework includes challenging requirements for high-risk AI models, necessitating the use of real client data to obtain market approval, which poses significant challenges due to data security and localization requirements. Duality Technologies offers a solution through its Secure Collaborative AI platform, which aligns with the AI Regulatory Sandbox requirements such as data governance, monitoring mechanisms, and protection of personal data in trusted execution environments. The platform ensures data security and intellectual property protection, enabling AI providers to train models in compliance with regulations while satisfying data owner concerns.
May 05, 2024
941 words in the original blog post.
Zero Trust Data Protection is a security model that assumes no trust for any users or systems, internal or external, until verified, marking a departure from traditional security practices that consider internal networks safe. This model emphasizes continuous verification and strict access controls to mitigate evolving cyber threats such as ransomware and insider breaches, which have demonstrated increased urgency with an 11% rise in ransomware attacks in 2024. Key principles of Zero Trust include never assuming trust, implementing least privilege access, microsegmentation, multi-factor authentication, real-time threat detection, and compliance checks. It adapts dynamically to new threats using AI, machine learning, and cloud-native environments, and has become accessible through Zero Trust as a Service (ZTaaS). Duality Technologies exemplifies this approach by enabling secure collaboration on encrypted data through advanced privacy-enhancing technologies, ensuring robust data protection while facilitating collaboration without direct data access.
May 05, 2024
1,050 words in the original blog post.