Cloud Computing Patterns, Mechanisms > Cloud Service and Storage Security Patterns > In-Transit Cloud Data Encryption
In-Transit Cloud Data Encryption (Cope, Erl)
How can data be securely transmitted to, from, and within a cloud environment?
data:image/s3,"s3://crabby-images/7913b/7913b92b0041edb0f90eb53cc5a0106ec0ed8e8f" alt="In-Transit Cloud Data Encryption In-Transit Cloud Data Encryption"
Problem
Data copied to and from a cloud environment transits networks and servers beyond the control of the organization and can be intercepted by malicious intermediaries.
Solution
A solution is implemented with capabilities that secure and protect data while it transfers between sender and receiver and also ensure that data will not be accepted by the receiver if the original data sent is modified.
Application
An encryption mechanism is implemented to encrypt data between sender and receiver for confidentiality, and a digital signature mechanism is implemented to provide integrity for the data.
Compound Patterns
Burst In, Burst Out to Private Cloud, Burst Out to Public Cloud, Cloud Authentication, Cloud Balancing, Elastic Environment, Infrastructure-as-a-Service (IaaS), Isolated Trust Boundary, Multitenant Environment, Platform-as-a-Service (PaaS), Private Cloud, Public Cloud, Resilient Environment, Resource Workload Management, Secure Burst Out to Private Cloud/Public Cloud, Software-as-a-Service (SaaS)
data:image/s3,"s3://crabby-images/a310b/a310b0fd792326757d5ac1d4db8d5164fb9fcc1b" alt="In-Transit Cloud Data Encryption: An attacker attempts to intercept data uploading into a cloud environment, however, the data is encrypted and signed before it is sent. In-Transit Cloud Data Encryption: An attacker attempts to intercept data uploading into a cloud environment, however, the data is encrypted and signed before it is sent."
An attacker attempts to intercept data uploading into a cloud environment, however, the data is encrypted and signed before it is sent.
data:image/s3,"s3://crabby-images/97b59/97b5909eb24cfb1928ce4e5b370125d03eb87148" alt="In-Transit Cloud Data Encryption: An attacker intercepts encrypted data before it is received by the cloud provider, and the receiver discards the packet as a result of maintaining data integrity and confidentiality. In-Transit Cloud Data Encryption: An attacker intercepts encrypted data before it is received by the cloud provider, and the receiver discards the packet as a result of maintaining data integrity and confidentiality."
An attacker intercepts encrypted data before it is received by the cloud provider, and the receiver discards the packet as a result of maintaining data integrity and confidentiality.
This mechanism is covered in CCP Module 7: Fundamental Cloud Security and
in Module 8: Advanced Cloud Security.
For more information regarding the Cloud Certified Professional (CCP) curriculum, visit www.arcitura.com/ccp.
The architectural model upon which this design pattern is based is further covered in:
Cloud Computing Design Patterns by Thomas Erl, Robert Cope, Amin Naserpour
(ISBN: 9780133858563, Hardcover, ~ 528 pages)
For more information about this book, visit www.arcitura.com/books.