bloombase transparent vmdk encryption solution for vmware esx, red hat kvm, citrix xenserver and...

23
Bloombase Data At- Rest Security for Virtual Data Centers Bloombase Technologies

Upload: bloombase-inc

Post on 28-Jul-2015

402 views

Category:

Documents


4 download

DESCRIPTION

Bloombase data at-rest solution for virtual data centers VMware ESX, Red Hat KVM, Citrix XenServer, Oracle Virtualbox

TRANSCRIPT

Page 1: Bloombase Transparent VMDK Encryption Solution for VMware ESX, Red Hat KVM, Citrix XenServer and Oracle Virtualbox Virtual Data Centers

Bloombase Data At-Rest Security for Virtual Data Centers

Bloombase Technologies

Page 2: Bloombase Transparent VMDK Encryption Solution for VMware ESX, Red Hat KVM, Citrix XenServer and Oracle Virtualbox Virtual Data Centers

Overview

Page 3: Bloombase Transparent VMDK Encryption Solution for VMware ESX, Red Hat KVM, Citrix XenServer and Oracle Virtualbox Virtual Data Centers

Bloombase Data At-Rest Security

Traditional data center

storage encryption

Transparent encryption

and unencryption

Storage proxy

On-the-fly wire-speed

storage communications

payload cryptography

Page 4: Bloombase Transparent VMDK Encryption Solution for VMware ESX, Red Hat KVM, Citrix XenServer and Oracle Virtualbox Virtual Data Centers

Virtual Data Center Encryption

Virtual data center

needs encryption as

much as for physical

Server and encryption

server as virtual

machines

Storage communications

hypervised

Page 5: Bloombase Transparent VMDK Encryption Solution for VMware ESX, Red Hat KVM, Citrix XenServer and Oracle Virtualbox Virtual Data Centers

Bloombase Virtual Appliance

Bloombase Spitfire

StoreSafe can be

deployed as virtual

appliance on virtual data

center

Storage communications

hypervised

Page 6: Bloombase Transparent VMDK Encryption Solution for VMware ESX, Red Hat KVM, Citrix XenServer and Oracle Virtualbox Virtual Data Centers

Virtual Appliance Hypervisor Support

VMware ESX/ESXi

Oracle VirtualBox

Citrix XenServer

Red Hat KVM

IBM PowerVM

Page 7: Bloombase Transparent VMDK Encryption Solution for VMware ESX, Red Hat KVM, Citrix XenServer and Oracle Virtualbox Virtual Data Centers

Technology In Depth

Page 8: Bloombase Transparent VMDK Encryption Solution for VMware ESX, Red Hat KVM, Citrix XenServer and Oracle Virtualbox Virtual Data Centers

Product Overview

Server and storage transparent

Automated encryption

Turnkey and immediate

regulatory compliance

Scale-up and scale-out

Cost-effective

High availability ready for

mission critical applications

Page 9: Bloombase Transparent VMDK Encryption Solution for VMware ESX, Red Hat KVM, Citrix XenServer and Oracle Virtualbox Virtual Data Centers

Transparent Automated Encryption and Unencryption

Fully automated data

encryption and

unencryption for

authorized clients

On-premise: SAN, NAS,

DAS, Tape, VTL

Cloud: RESTful

Page 10: Bloombase Transparent VMDK Encryption Solution for VMware ESX, Red Hat KVM, Citrix XenServer and Oracle Virtualbox Virtual Data Centers

Multiple Storage Protocol Support

Block storage based, file

based, object based

FCP, FCoE, iSCSI

NFS, CIFS

HTTP, WEBDAV

RESTful cloud

Page 11: Bloombase Transparent VMDK Encryption Solution for VMware ESX, Red Hat KVM, Citrix XenServer and Oracle Virtualbox Virtual Data Centers

Client and User Authentication

User-based

authentication: LDAP,

MSAD, Kerberos,

CHAP

Host-based

authentication:

network address,

LUN mask

Page 12: Bloombase Transparent VMDK Encryption Solution for VMware ESX, Red Hat KVM, Citrix XenServer and Oracle Virtualbox Virtual Data Centers

Industry Proven Security

Industry standard cipher

algorithm support

Regional and special

cipher support

IEEE 1619 compliant

OASIS KMIP support

NIST FIPS 140-2 validated

Page 13: Bloombase Transparent VMDK Encryption Solution for VMware ESX, Red Hat KVM, Citrix XenServer and Oracle Virtualbox Virtual Data Centers

Key Management

Stored separately from

encrypted information

Key vault protected by

AES-256 strong

encryption

Supports 3rd party

PKCS#11 HSMs and

KMIP-compliant key

managers

Page 14: Bloombase Transparent VMDK Encryption Solution for VMware ESX, Red Hat KVM, Citrix XenServer and Oracle Virtualbox Virtual Data Centers

Management

Web-based and CLI

management consoles

Role-based administration

Separation of duties (SoD)

Syslog and Audit trail

SNMP

Recovery quorum

Operator smart tokens

Page 15: Bloombase Transparent VMDK Encryption Solution for VMware ESX, Red Hat KVM, Citrix XenServer and Oracle Virtualbox Virtual Data Centers

Use Cases

Page 16: Bloombase Transparent VMDK Encryption Solution for VMware ESX, Red Hat KVM, Citrix XenServer and Oracle Virtualbox Virtual Data Centers

Tenant File Encryption

Virtual data center

tenants access

Bloombase encrypted

network file resources

over Ethernet

Page 17: Bloombase Transparent VMDK Encryption Solution for VMware ESX, Red Hat KVM, Citrix XenServer and Oracle Virtualbox Virtual Data Centers

Tenant File Encryption

Bloombase Spitfire

StoreSafe provides file

encryption to tenants

as virtual appliance

Page 18: Bloombase Transparent VMDK Encryption Solution for VMware ESX, Red Hat KVM, Citrix XenServer and Oracle Virtualbox Virtual Data Centers

Tenant Volume Encryption

Virtual data center

tenants access

Bloombase encrypted

iSCSI block-based

volumes over Ethernet

Page 19: Bloombase Transparent VMDK Encryption Solution for VMware ESX, Red Hat KVM, Citrix XenServer and Oracle Virtualbox Virtual Data Centers

Tenant Volume Encryption

Bloombase Spitfire

StoreSafe provides block

based encryption to

tenants as virtual

appliance

Page 20: Bloombase Transparent VMDK Encryption Solution for VMware ESX, Red Hat KVM, Citrix XenServer and Oracle Virtualbox Virtual Data Centers

Datastore File Encryption

Hypervisor direct attaches

Bloombase secured file servers

AS-IF virtual plain file resources

VMDKs on NFS storage remain

as normal files but encrypted

Page 21: Bloombase Transparent VMDK Encryption Solution for VMware ESX, Red Hat KVM, Citrix XenServer and Oracle Virtualbox Virtual Data Centers

Datastore Volume Encryption

Hypervisor direct attaches

Bloombase secured volumes

AS-IF virtual plain volumes

Encryption on block-storage

level, objects stored in VMFS

are encrypted as a result

Page 22: Bloombase Transparent VMDK Encryption Solution for VMware ESX, Red Hat KVM, Citrix XenServer and Oracle Virtualbox Virtual Data Centers

Questions? Comments?

Page 23: Bloombase Transparent VMDK Encryption Solution for VMware ESX, Red Hat KVM, Citrix XenServer and Oracle Virtualbox Virtual Data Centers