| By Gilad Parann-Nissany | Article Rating: |
|
| February 5, 2013 11:00 AM EST | Reads: |
2,318 |
VMware is without a doubt a major platform for private as well as public cloud deployments. But as in any other cloud-based system, data security, and more specifically cloud encryption and key management are fundamental building blocks.
Cloud key management and encryption requirements
We have found that external users have many of the same security requirements, whether the cloud is public or private: from an external user’s point of view, the differences between public and private clouds are technical details, and the user requires the same guarantees from the provider.
In particular, users expect to own their data. In a business context, a user is often another business. These businesses want to know that they are enjoying the benefits of the provided service, but that the provider cannot read their data.
As a consequence, cloud infrastructure must provide an ability to encrypt sensitive data, and to keep encryption keys under the control of the user. This requirement shows up in public deployments, as a requirement to control keys that encrypt disks. It also shows up in private deployments, as a requirement to control keys that are used by the software solution: each user wants to have separate keys, so that other users and the solution provider cannot read the users data. Such solutions are beginning to emerge, for example split-key encryption and homomorphic key management.
Public cloud deployments
Public providers often want to “chop” a large storage array into chunks that are usable for customers. Virtualization technology is very natural here, but the challenge is to make each “chunk” encrypted by different keys, so that customers remain in control.
A natural solution here has emerged from Porticor: Virtual Appliances are deployed on the same VMware-based infrastructure that the provider has chosen. These appliances know how to consume a LUN or VMFS, and re-expose it as a new LUN or VMFS, this time encrypted using keys that are specific to a customer. (For further details read the white paper here)
The Porticor solution actually leverages the same flexibility to carve up storage and compute – that is available from the VMware cloud infrastructure – and adds encryption and key management as a natural layer.
Private cloud deployments
Private providers often have a specific software solution in mind. Here Porticor’s ability to provide unique “tokens” for users, groups or roles – and an API that integrates with the provider’s identity & access management solution – allows individual and group identities to be maintained at the encryption layer.
Providers can offer full multi-tenancy, yet guarantee that the user’s individual data is encrypted using a key that only the user knows. The provider’s employees literally provide the service yet cannot read the data.
Summary
The flexibility of modern virtualization environments is often presented as a security challenge, but with the right technology, it can actually enhance security and offer users greater control of their data – without the hassle of managing it themselves.
The post Key management and encryption in VMware-based clouds appeared first on Porticor Cloud Security.
Read the original blog entry...
Published February 5, 2013 Reads 2,318
Copyright © 2013 SYS-CON Media, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
More Stories By Gilad Parann-Nissany
Gilad Parann-Nissany, Founder and CEO at Porticor is a pioneer of Cloud Computing. He has built SaaS Clouds for medium and small enterprises at SAP (CTO Small Business); contributing to several SAP products and reaching more than 8 million users. Recently he has created a consumer Cloud at G.ho.st - a cloud operating system that delighted hundreds of thousands of users while providing browser-based and mobile access to data, people and a variety of cloud-based applications. He is now CEO of Porticor, a leader in Virtual Privacy and Cloud Security.
- Cloud Expo New York Speaker Profile: Jill T. Singer – Federal CIO Emeritus
- Cloud Expo New York: API Security, Does My Business Need an OAuth Server?
- Session Topics: 12th Cloud Expo / Cloud Expo New York
- Cloud Expo New York: Aligning Your Cloud Security with the Business
- Cloud Expo NY: Best Practices for Architecting Your Cloud Infrastructure
- The Rise of the Thin Client
- Patterns to Bring Enterprise and Social Identity to the Cloud
- NIST to Sponsor FFRDC Widespread Adoption of Integrated CyberSecurity
- Lunch Keynote at Cloud Expo New York | CIOs Are Transforming the Cloud
- Logicworks to Exhibit at Cloud Expo New York
- Cloud Expo NY: Virtualization, Compliance, and Healthcare in the Cloud
- Is Cloud Safer Than Your Traditional Datacenter?
- Cloud Expo New York Speaker Profile: Jill T. Singer – Federal CIO Emeritus
- Cloud Expo New York: API Security, Does My Business Need an OAuth Server?
- Session Topics: 12th Cloud Expo / Cloud Expo New York
- Cloud Expo New York | Danger Ahead: Why File Sync Is NOT Endpoint Backup
- Cloud Expo New York: Aligning Your Cloud Security with the Business
- Cloud Expo NY: Best Practices for Architecting Your Cloud Infrastructure
- Overview of the OpenStack Cloud
- The Rise of the Thin Client
- Cloud Expo New York: Managing Legal Risks in Cloud Computing
- Patterns to Bring Enterprise and Social Identity to the Cloud
- NIST to Sponsor FFRDC Widespread Adoption of Integrated CyberSecurity
- Lunch Keynote at Cloud Expo New York | CIOs Are Transforming the Cloud
- Effective Page Authorization In JavaServer Faces
- The Top 250 Players in the Cloud Computing Ecosystem
- Cloud Expo New York Call for Papers Now Open
- SOA Focus - Web Services Security in Java EE
- IBM Security Report Predicts Mobile/Satellite Attacks in 2005
- Industry Experts Discuss the State of Cloud Computing
- The Cloud Computing Kettle Heats Right Up
- The Top 100 Bloggers on Cloud Computing
- The Next Chapter in the Virtualization Story Begins
- Java Application Security in the Corporate World
- ColdFusion Security Best Practices
- Cloud Expo 2011 East To Attract 10,000 Delegates and 200 Exhibitors




















