Data at rest has long been protected by technology called public key infrastructure (PKI), in which data is encrypted when it's created by a public key and only decrypted by the authorized person holding the private key. But data protection is complicated in cloud environments.