SlideShare uma empresa Scribd logo
1 de 20
Baixar para ler offline
© 2018 Cloud4com, a.s. All rights reserved. www.cloud4com.com
© 2016 Cloud4com, a.s. All rights reserved.
Bezpečnost a šifrování dat umístěných v cloudu
Jiří Vrbický
VIRTUALIZATION FORUM 2018
© 2018 Cloud4com, a.s. All rights reserved. www.cloud4com.com
© 2018 Cloud4com, a.s. All rights reserved. www.cloud4com.com
© 2018 Cloud4com, a.s. All rights reserved. www.cloud4com.com
© 2018 Cloud4com, a.s. All rights reserved. www.cloud4com.com
Trusted Platform – Intel TXT & Attestation
vMotion*
Protected VM
Trusted Untrusted
© 2018 Cloud4com, a.s. All rights reserved. www.cloud4com.com
Cloud4com Virtual Private Data Center (vPDC) concept
SSL VPN
Internet
vPDC
Customer Portal
IT
Administrator
Customer Cloud4com, a.s. Service Provider
Customer
Requests
Infrastructure
Orchestration
vServers
vRouter
VLAN A - Production
VLAN B - Development
NAS
Appliance
Customers
Application Access
Physical Server
© 2018 Cloud4com, a.s. All rights reserved. www.cloud4com.com
© 2018 Cloud4com, a.s. All rights reserved. www.cloud4com.com
Role-based User Access
© 2018 Cloud4com, a.s. All rights reserved. www.cloud4com.com
© 2018 Cloud4com, a.s. All rights reserved. www.cloud4com.com
© 2018 Cloud4com, a.s. All rights reserved. www.cloud4com.com
© 2018 Cloud4com, a.s. All rights reserved. www.cloud4com.com
Gemalto Platform for Data Encryption
• Why Gemalto?
– Trusted vendor with real references
– Provide higher security on shared platform
– Flexible cloud-based model
– Independent Key Management platform with KMIP support
– Provide Key Management Server as Virtual Appliance
– Easy to deploy and manage solution for data encryption
– Product for transparent data encryption in Virtual and Physical Server
– Product for data encryption on File System and NAS
– High-speed network traffic encryption on L2
– Encryption connectors for mainstream DBs, APP development
– Proof-of-Concept / DEMO for Our Customers is Available
© 2018 Cloud4com, a.s. All rights reserved. www.cloud4com.com
Cloud Security with Gemalto
SafeNet KeySecure
Centralized Key Management and Crypto Engine
Physical & Virtual Appliance
Unstructured Data Encryption
Structured Data Encryption
Data in Transit Encryption
NAS & File
Encryption
ProtectFile
Application Data
Encryption (API)
ProtectApp
Transparent
Data Encryption
Data-at-Rest
Virtual & Physical
Server Encryption
ProtectV
Database
Encryption
ProtectDB
Layer 2 Network
Encryption
Network Encryptors
Key Manager
© 2018 Cloud4com, a.s. All rights reserved. www.cloud4com.com
VMware vSphere/ESXi
Encryption of Virtual Servers
Customer Portal
IT
Administrator
Customer Cloud4com, a.s. Service Provider
Remote Management through ProtectV
Manager - https (SSL VPN, IPSec, …)
Customer
Requests
Infrastructure
Orchestration
Security
Department
Export / Backup
Virtual Private Data Center
(vPDC)
Virtual & Physical
Servers
Management
SafeNet ProtectV Clients
SafeNet ProtectV ManagerSafeNet KeySecure
KeySecure
© 2018 Cloud4com, a.s. All rights reserved. www.cloud4com.com
SafeNet KeySecure / Virtual KeySecure
• Centralized Key Management
• Centrally manages symmetric, asymmetric keys and certificates
• Generate, Export, Import, Destroy, Backup/Restore, etc.
• Support KMIP Standard
• Built-in key rotation – versioned keys
• Crypto Engine
• Encryption & Decryption Services
• Configurable for offload or local crypto
© 2018 Cloud4com, a.s. All rights reserved. www.cloud4com.com
SafeNet ProtectV Encryption Status
© 2018 Cloud4com, a.s. All rights reserved. www.cloud4com.com
© 2018 Cloud4com, a.s. All rights reserved. www.cloud4com.com
© 2018 Cloud4com, a.s. All rights reserved. www.cloud4com.com+420 734 649 949 sales@cloud4com.comwww.cloud4com.com

Mais conteúdo relacionado

Mais de MarketingArrowECS_CZ

Mais de MarketingArrowECS_CZ (20)

Novinky ve světě Oracle DB a koncept konvergované databáze
Novinky ve světě Oracle DB a koncept konvergované databázeNovinky ve světě Oracle DB a koncept konvergované databáze
Novinky ve světě Oracle DB a koncept konvergované databáze
 
Základy licencování Oracle software
Základy licencování Oracle softwareZáklady licencování Oracle software
Základy licencování Oracle software
 
Garance 100% dostupnosti dat! Kdo z vás to má?
Garance 100% dostupnosti dat! Kdo z vás to má?Garance 100% dostupnosti dat! Kdo z vás to má?
Garance 100% dostupnosti dat! Kdo z vás to má?
 
Využijte svou Oracle databázi naplno
Využijte svou Oracle databázi naplnoVyužijte svou Oracle databázi naplno
Využijte svou Oracle databázi naplno
 
Oracle Data Protection - 2. část
Oracle Data Protection - 2. částOracle Data Protection - 2. část
Oracle Data Protection - 2. část
 
Oracle Data Protection - 1. část
Oracle Data Protection - 1. částOracle Data Protection - 1. část
Oracle Data Protection - 1. část
 
Benefity Oracle Cloudu (4/4): Storage
Benefity Oracle Cloudu (4/4): StorageBenefity Oracle Cloudu (4/4): Storage
Benefity Oracle Cloudu (4/4): Storage
 
Benefity Oracle Cloudu (3/4): Compute
Benefity Oracle Cloudu (3/4): ComputeBenefity Oracle Cloudu (3/4): Compute
Benefity Oracle Cloudu (3/4): Compute
 
InfiniBox z pohledu zákazníka
InfiniBox z pohledu zákazníkaInfiniBox z pohledu zákazníka
InfiniBox z pohledu zákazníka
 
Exadata z pohledu zákazníka a novinky generace X8M - 2. část
Exadata z pohledu zákazníka a novinky generace X8M - 2. částExadata z pohledu zákazníka a novinky generace X8M - 2. část
Exadata z pohledu zákazníka a novinky generace X8M - 2. část
 
Exadata z pohledu zákazníka a novinky generace X8M - 1. část
Exadata z pohledu zákazníka a novinky generace X8M - 1. částExadata z pohledu zákazníka a novinky generace X8M - 1. část
Exadata z pohledu zákazníka a novinky generace X8M - 1. část
 
Úvod do Oracle Cloud infrastruktury
Úvod do Oracle Cloud infrastrukturyÚvod do Oracle Cloud infrastruktury
Úvod do Oracle Cloud infrastruktury
 
Check Point automatizace a orchestrace
Check Point automatizace a orchestraceCheck Point automatizace a orchestrace
Check Point automatizace a orchestrace
 
vSAN a FileServices
vSAN a FileServicesvSAN a FileServices
vSAN a FileServices
 
Oracle databáze - zkonsolidovat, ochránit a ještě ušetřit! (1. část)
Oracle databáze - zkonsolidovat, ochránit a ještě ušetřit! (1. část)Oracle databáze - zkonsolidovat, ochránit a ještě ušetřit! (1. část)
Oracle databáze - zkonsolidovat, ochránit a ještě ušetřit! (1. část)
 
Oracle databáze - zkonsolidovat, ochránit a ještě ušetřit! (2. část)
Oracle databáze - zkonsolidovat, ochránit a ještě ušetřit! (2. část)Oracle databáze - zkonsolidovat, ochránit a ještě ušetřit! (2. část)
Oracle databáze - zkonsolidovat, ochránit a ještě ušetřit! (2. část)
 
Horizon 8 + Instant Clones
Horizon 8 + Instant ClonesHorizon 8 + Instant Clones
Horizon 8 + Instant Clones
 
Webinář InfiniGuard
Webinář InfiniGuardWebinář InfiniGuard
Webinář InfiniGuard
 
Výhody a benefity nasazení Oracle Database Appliance
Výhody a benefity nasazení Oracle Database ApplianceVýhody a benefity nasazení Oracle Database Appliance
Výhody a benefity nasazení Oracle Database Appliance
 
Webinář InfiniBox
Webinář InfiniBoxWebinář InfiniBox
Webinář InfiniBox
 

Último

+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
Joaquim Jorge
 

Último (20)

A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
HTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation StrategiesHTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation Strategies
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 
Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 

Bezpečnost a šifrování dat umístěných v cloudu

  • 1. © 2018 Cloud4com, a.s. All rights reserved. www.cloud4com.com
  • 2. © 2016 Cloud4com, a.s. All rights reserved. Bezpečnost a šifrování dat umístěných v cloudu Jiří Vrbický VIRTUALIZATION FORUM 2018
  • 3. © 2018 Cloud4com, a.s. All rights reserved. www.cloud4com.com
  • 4. © 2018 Cloud4com, a.s. All rights reserved. www.cloud4com.com
  • 5. © 2018 Cloud4com, a.s. All rights reserved. www.cloud4com.com
  • 6. © 2018 Cloud4com, a.s. All rights reserved. www.cloud4com.com Trusted Platform – Intel TXT & Attestation vMotion* Protected VM Trusted Untrusted
  • 7. © 2018 Cloud4com, a.s. All rights reserved. www.cloud4com.com Cloud4com Virtual Private Data Center (vPDC) concept SSL VPN Internet vPDC Customer Portal IT Administrator Customer Cloud4com, a.s. Service Provider Customer Requests Infrastructure Orchestration vServers vRouter VLAN A - Production VLAN B - Development NAS Appliance Customers Application Access Physical Server
  • 8. © 2018 Cloud4com, a.s. All rights reserved. www.cloud4com.com
  • 9. © 2018 Cloud4com, a.s. All rights reserved. www.cloud4com.com Role-based User Access
  • 10. © 2018 Cloud4com, a.s. All rights reserved. www.cloud4com.com
  • 11. © 2018 Cloud4com, a.s. All rights reserved. www.cloud4com.com
  • 12. © 2018 Cloud4com, a.s. All rights reserved. www.cloud4com.com
  • 13. © 2018 Cloud4com, a.s. All rights reserved. www.cloud4com.com Gemalto Platform for Data Encryption • Why Gemalto? – Trusted vendor with real references – Provide higher security on shared platform – Flexible cloud-based model – Independent Key Management platform with KMIP support – Provide Key Management Server as Virtual Appliance – Easy to deploy and manage solution for data encryption – Product for transparent data encryption in Virtual and Physical Server – Product for data encryption on File System and NAS – High-speed network traffic encryption on L2 – Encryption connectors for mainstream DBs, APP development – Proof-of-Concept / DEMO for Our Customers is Available
  • 14. © 2018 Cloud4com, a.s. All rights reserved. www.cloud4com.com Cloud Security with Gemalto SafeNet KeySecure Centralized Key Management and Crypto Engine Physical & Virtual Appliance Unstructured Data Encryption Structured Data Encryption Data in Transit Encryption NAS & File Encryption ProtectFile Application Data Encryption (API) ProtectApp Transparent Data Encryption Data-at-Rest Virtual & Physical Server Encryption ProtectV Database Encryption ProtectDB Layer 2 Network Encryption Network Encryptors Key Manager
  • 15. © 2018 Cloud4com, a.s. All rights reserved. www.cloud4com.com VMware vSphere/ESXi Encryption of Virtual Servers Customer Portal IT Administrator Customer Cloud4com, a.s. Service Provider Remote Management through ProtectV Manager - https (SSL VPN, IPSec, …) Customer Requests Infrastructure Orchestration Security Department Export / Backup Virtual Private Data Center (vPDC) Virtual & Physical Servers Management SafeNet ProtectV Clients SafeNet ProtectV ManagerSafeNet KeySecure KeySecure
  • 16. © 2018 Cloud4com, a.s. All rights reserved. www.cloud4com.com SafeNet KeySecure / Virtual KeySecure • Centralized Key Management • Centrally manages symmetric, asymmetric keys and certificates • Generate, Export, Import, Destroy, Backup/Restore, etc. • Support KMIP Standard • Built-in key rotation – versioned keys • Crypto Engine • Encryption & Decryption Services • Configurable for offload or local crypto
  • 17. © 2018 Cloud4com, a.s. All rights reserved. www.cloud4com.com SafeNet ProtectV Encryption Status
  • 18. © 2018 Cloud4com, a.s. All rights reserved. www.cloud4com.com
  • 19. © 2018 Cloud4com, a.s. All rights reserved. www.cloud4com.com
  • 20. © 2018 Cloud4com, a.s. All rights reserved. www.cloud4com.com+420 734 649 949 sales@cloud4com.comwww.cloud4com.com