filmov
tv
At-rest Encryption in OpenStack Swift

Показать описание
John Dickinson
Recently, the OpenStack Swift project released a feature that implements server-side encryption. The feature is designed to protect user data from being exposed if drives were to leave the cluster, something that can happen intentionally through an RMA process or unintentionally from mistakes or malicious intent. If drives leave the cluster, we want to be sure that the users' data is protected and impossible to recover. Swift's at-rest encryption feature encrypts user data and metadata with AES using a unique key for every object stored.
In this talk, we will cover the details of how the server-side encryption works, including the on-disk format, and we'll dig into the key-management used. Also, we'll discuss the ways in which this feature can be improved to support more advanced functionality and more robust key management.
Recently, the OpenStack Swift project released a feature that implements server-side encryption. The feature is designed to protect user data from being exposed if drives were to leave the cluster, something that can happen intentionally through an RMA process or unintentionally from mistakes or malicious intent. If drives leave the cluster, we want to be sure that the users' data is protected and impossible to recover. Swift's at-rest encryption feature encrypts user data and metadata with AES using a unique key for every object stored.
In this talk, we will cover the details of how the server-side encryption works, including the on-disk format, and we'll dig into the key-management used. Also, we'll discuss the ways in which this feature can be improved to support more advanced functionality and more robust key management.
At-rest Encryption in OpenStack Swift
Swift Object Encryption
New in Swift: Object Encryption
CyberTip 4 Encryption at Rest
Securing OpenStack Clouds with Cinder Volume Encryption - for Real This Time!
Finally FDE - OpenStack Full Disk Encryption and Missing Pieces
Simpler Encrypted Volume Management with Tang
How to Encrypt and Decrypt with swift 3 app
Cloud Keep: OpenStack Key Management as a Service
How to Integrate OpenStack Swift to Your 'Legacy' System
Securing API authentication on OpenStack cloud
Encryption for OpenStack Cinder Block Storage with Bloombase StoreSafe Intelligent Storage Firewall
Barbican 1.0: Open Source Key Management for OpenStack
OpenStack Swift by Christian Schwede, Red Hat
Storage Made Easy - Data Governance on OpenStack
Encrypt your Volumes with Barbican
Are Your Secrets Secure?
Amp up OpenStack Swift
2015 OpenStack Vancouver - Andrew Gaul – Introduction to S3Proxy and SwiftProxy
Secure Data Analysis with OpenStack and Asperathos
How to deliver High Performance OpenStack Cloud: Christoph Dwertmann, Vault Systems
Common Use Cases and Options for Barbican in Your OpenStack Deployment
Extend Swift by Developing Your Own Middlewares
Extending Barbican - Managing Secrets and Events Your Way
Комментарии