|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
組織は、PII を保護し、コンプライアンスを確保するという課題に直面しています。 Skyflow Data Privacy Vault は、機密データを分離して保護し、ダウンストリーム ストレージ用のトークンに変換して、コンプライアンスの範囲を縮小します。 Cloud Storage Security は、アップロードされたファイルを自動的にスキャンしてウイルスやマルウェアを検出し、潜在的な脅威を軽減することでこれを補完します。このパートナーシップにより、ファイル管理が簡素化され、データのセキュリティが確保され、コンプライアンスの負担が軽減されます。

Securely Managing Personally Identifiable Information (PII) with Skyflow and Cloud Storage Security on AWS
Skyflow と AWS のクラウド ストレージ セキュリティを使用して個人を特定できる情報 (PII) を安全に管理
Introduction
導入
Organizations entrusted with the management of personally identifiable information (PII) face significant challenges in maintaining the security and compliance of this sensitive data. Despite best efforts, PII often resides in a fragmented fashion across diverse repositories, including databases, data warehouses, log files, and backups, making comprehensive security and compliance measures difficult to implement.
個人識別情報 (PII) の管理を任されている組織は、この機密データのセキュリティとコンプライアンスを維持するという重大な課題に直面しています。最善の努力にもかかわらず、PII はデータベース、データ ウェアハウス、ログ ファイル、バックアップなどのさまざまなリポジトリに断片的に存在することが多く、包括的なセキュリティおよびコンプライアンス対策の実装が困難になります。
Furthermore, file management introduces additional complexities, necessitating stringent security measures, robust access controls, and compliance-aligned storage practices. The risk of data breaches and malware threats escalates when organizations receive files from external sources, such as customers. To mitigate these risks, organizations must meticulously scan external files for viruses and malware prior to processing.
さらに、ファイル管理ではさらに複雑さが増し、厳格なセキュリティ対策、堅牢なアクセス制御、コンプライアンスに準拠したストレージ慣行が必要になります。組織が顧客などの外部ソースからファイルを受け取ると、データ侵害やマルウェアの脅威のリスクが高まります。これらのリスクを軽減するには、組織は外部ファイルを処理する前にウイルスやマルウェアを注意深くスキャンする必要があります。
Addressing Challenges with Skyflow and Cloud Storage Security
Skyflow とクラウド ストレージ セキュリティで課題に対処する
To minimize risk and alleviate the burdens associated with existing upstream and downstream systems, organizations leverage Skyflow, available within AWS Marketplace. Skyflow Data Privacy Vault delivers comprehensive security, compliance, and data residency for Amazon Web Services (AWS) workloads.
リスクを最小限に抑え、既存の上流および下流システムに伴う負担を軽減するために、組織は AWS Marketplace 内で利用可能な Skyflow を活用します。 Skyflow Data Privacy Vault は、アマゾン ウェブ サービス (AWS) ワークロードに包括的なセキュリティ、コンプライアンス、およびデータ常駐を提供します。
In conjunction with Skyflow, Cloud Storage Security (CSS) plays a crucial role in further safeguarding infrastructure and alleviating the complexities associated with sensitive file management. CSS, an AWS Specialization Partner with the Security Competency, automates the scanning of uploaded files for malicious code and malware.
Skyflow と連携すると、クラウド ストレージ セキュリティ (CSS) は、インフラストラクチャをさらに保護し、機密ファイル管理に関連する複雑さを軽減する上で重要な役割を果たします。セキュリティコンピテンシーを持つ AWS スペシャライゼーションパートナーである CSS は、アップロードされたファイルの悪意のあるコードやマルウェアのスキャンを自動化します。
Securing PII with Skyflow Data Privacy Vault
Skyflow Data Privacy Vault による PII の保護
Skyflow, a software-as-a-service (SaaS) offering, supports both multi-tenant and single-tenant deployment models. Its Data Privacy Vault isolates, protects, and governs access to sensitive customer data, transforming it into opaque tokens that serve as references to the original data. These non-sensitive tokens can be securely stored in any application storage system or utilized in data warehouses.
Skyflow は、SaaS (Software-as-a-Service) 製品であり、マルチテナント展開モデルとシングルテナント展開モデルの両方をサポートしています。その Data Privacy Vault は、機密性の高い顧客データへのアクセスを分離、保護、管理し、元のデータへの参照として機能する不透明なトークンに変換します。これらの機密性のないトークンは、アプリケーション ストレージ システムに安全に保存したり、データ ウェアハウスで利用したりできます。
A Skyflow vault enables the confinement of sensitive data within a specific geographic location and tightly controls access to this data. Other systems interact only with the non-sensitive tokenized data, effectively removing them from the scope of compliance. The tokenization process preserves formatting when necessary and maintains consistency for analytics and machine learning (ML) workflows.
Skyflow コンテナーを使用すると、機密データを特定の地理的位置内に閉じ込めることができ、このデータへのアクセスを厳密に制御できます。他のシステムは、非機密のトークン化データのみを操作し、それらのデータをコンプライアンスの範囲から事実上削除します。トークン化プロセスでは、必要に応じて書式設定が保持され、分析と機械学習 (ML) のワークフローの一貫性が維持されます。
Skyflow Data Privacy Vault serves as the core infrastructure for PII, providing compute, storage, and network resources as a service. Its architectural simplicity is achieved through an API call, and Skyflow employs polymorphic encryption to secure PII and preserve its usability. This enables the execution of operations on fully encrypted data.
Skyflow Data Privacy Vault は、PII のコア インフラストラクチャとして機能し、コンピューティング、ストレージ、ネットワーク リソースをサービスとして提供します。そのアーキテクチャのシンプルさは API 呼び出しによって実現され、Skyflow はポリモーフィック暗号化を採用して PII を保護し、使いやすさを維持します。これにより、完全に暗号化されたデータに対する操作の実行が可能になります。
Organizations can seamlessly build PII-specific workloads on a Skyflow vault for tasks such as data sharing, analytics, and encrypted operations. This capability empowers businesses to identify records with specific attributes, such as area code, without decrypting the data or calculate customer income averages, all without exposing PII to unauthorized parties.
組織は、データ共有、分析、暗号化された操作などのタスクのために、PII 固有のワークロードを Skyflow コンテナー上にシームレスに構築できます。この機能により、企業はデータを復号化することなく市外局番などの特定の属性を持つレコードを識別したり、顧客の平均収入を計算したりすることができ、PII を無許可の当事者に公開することはありません。
Working with a Skyflow Vault
Skyflow Vault の操作
While a data privacy vault differs from a traditional database, Skyflow Data Privacy Vault emulates certain database properties. Notably, a Skyflow vault supports a customizable schema consisting of tables, columns, and rows.
Data Privacy Vault は従来のデータベースとは異なりますが、Skyflow Data Privacy Vault は特定のデータベース プロパティをエミュレートします。特に、Skyflow コンテナーは、テーブル、列、行で構成されるカスタマイズ可能なスキーマをサポートしています。
Skyflow's vault is specifically designed to manage the entire lifecycle of sensitive data, comprehensively understanding the structure and applications of PII. For instance, a Skyflow vault recognizes a social security number as a distinct data type, not merely a string. This deep understanding allows the vault to natively support use cases such as revealing only the last four digits of a social security number based on defined roles and policies or securely sharing the complete social security number with third-party vendors for identity verification purposes.
Skyflow の保管庫は、PII の構造と用途を包括的に理解しながら、機密データのライフサイクル全体を管理するように特別に設計されています。たとえば、Skyflow ボールトは、社会保障番号を単なる文字列ではなく、別個のデータ型として認識します。この深い理解により、Vault は、定義された役割とポリシーに基づいて社会保障番号の下 4 桁のみを公開したり、本人確認の目的で完全な社会保障番号をサードパーティ ベンダーと安全に共有したりするユースケースをネイティブにサポートできます。
Beyond transforming sensitive data into non-sensitive forms, the vault strictly controls access to sensitive data through a zero-trust model. This model ensures that no user account or process can access data without explicit authorization via access control policies. These policies are meticulously constructed from the ground up, granting access to specific columns and rows of PII. This granular control enables organizations to meticulously define who can access what data, when, where, for how long, and in what format.
機密データを非機密形式に変換するだけでなく、ボールトはゼロトラスト モデルを通じて機密データへのアクセスを厳密に制御します。このモデルにより、アクセス制御ポリシーによる明示的な承認がなければ、ユーザー アカウントやプロセスがデータにアクセスできないことが保証されます。これらのポリシーは最初から細心の注意を払って構築されており、PII の特定の列と行へのアクセスが許可されます。このきめ細かな制御により、組織は誰が、いつ、どこで、どのくらいの期間、どのような形式でどのデータにアクセスできるかを細心の注意を払って定義できます。
For data storage, management, and retrieval, Skyflow offers both APIs and software development kits (SDKs). Skyflow supports both frontend and backend SDKs, providing flexibility based on integration requirements.
データの保存、管理、取得のために、Skyflow は API とソフトウェア開発キット (SDK) の両方を提供します。 Skyflow はフロントエンド SDK とバックエンド SDK の両方をサポートし、統合要件に基づいた柔軟性を提供します。
Managing Secure File Storage with Skyflow and CSS
Skyflow と CSS を使用した安全なファイル ストレージの管理
To demonstrate the secure storage and handling of files through Skyflow, we will examine how this solution effectively removes exposure to sensitive documents for both frontend and backend applications.
Skyflow を介したファイルの安全な保管と処理を実証するために、このソリューションがフロントエンド アプリケーションとバックエンド アプリケーションの両方で機密文書への露出を効果的に排除する方法を検証します。
In addition to Skyflow Vault, the solution leverages Amazon API Gateway as the backend API entry point for passing non-sensitive data downstream, AWS Lambda to receive and securely store non-sensitive data in Amazon DynamoDB, AWS Secrets Manager for secure storage and management of the Skyflow vault service account key, Amazon DynamoDB to save the skyflow_id shared by the vault after secure file storage, and Cloud Storage Security to automatically ensure that files are free from viruses and other potential threats.
Skyflow Vault に加えて、このソリューションは、非機密データを下流に渡すためのバックエンド API エントリ ポイントとして Amazon API Gateway、非機密データを受信して Amazon DynamoDB に安全に保存する AWS Lambda、安全な保存と管理のための AWS Secrets Manager を活用します。 Skyflow ボルト サービス アカウント キー、安全なファイル ストレージの後にボルトによって共有される skyflow_id を保存する Amazon DynamoDB、およびファイルがウイルスやその他の潜在的な脅威から解放されていることを自動的に保証する Cloud Storage セキュリティ。
The accompanying architecture diagram illustrates the file upload flow involving Skyflow, the aforementioned AWS services, and CSS.
添付のアーキテクチャ図は、Skyflow、前述の AWS サービス、および CSS を含むファイル アップロード フローを示しています。
Access Control Mechanisms
アクセス制御メカニズム
To govern access to the customer's vault, Skyflow employs policies that permit programmatic writes into the vault table for client records.
顧客のボールトへのアクセスを管理するために、Skyflow はクライアント レコードのボールト テーブルへのプログラムによる書き込みを許可するポリシーを採用しています。
To ensure read and update access is restricted to the single record owned by the currently logged-in user, Skyflow customers can leverage authentication services like Auth0. The customer application can then identify the user based on the Auth0 token.
読み取りおよび更新アクセスが現在ログインしているユーザーが所有する単一レコードに制限されるようにするために、Skyflow の顧客は Auth0 などの認証サービスを利用できます。その後、顧客アプリケーションは Auth0 トークンに基づいてユーザーを識別できます。
Skyflow's vault respects the user's identity and restricts access accordingly. To fulfill this requirement, customers utilize Skyflow's context-aware authorization.
Skyflow のボールトはユーザーの ID を尊重し、それに応じてアクセスを制限します。この要件を満たすために、顧客は Skyflow のコンテキスト認識型認証を利用します。
Context-Aware Authorization
コンテキスト認識型認可
Programmatic access to Skyflow APIs is controlled through a service account established within the Skyflow account. The roles assigned to the service account and the policies associated with those roles determine the level of access to a vault. The creation of Skyflow roles, policies, and service accounts can be managed programmatically via Skyflow's management APIs or through Skyflow Studio, Skyflow's web-based vault administration portal.
Skyflow API へのプログラムによるアクセスは、Skyflow アカウント内で確立されたサービス アカウントを通じて制御されます。サービス アカウントに割り当てられたロールと、それらのロールに関連付けられたポリシーによって、コンテナーへのアクセス レベルが決まります。 Skyflow のロール、ポリシー、サービス アカウントの作成は、Skyflow の管理 API または Skyflow の Web ベースの Vault 管理ポータルである Skyflow Studio を介してプログラムで管理できます。
Context-aware authorization empowers the backend to insert an additional claim for end-user context into the JWT token during insertion. This claim can be any string that uniquely identifies the end user, such as the token provided by Auth0 upon successful client login.
コンテキスト認識型承認により、バックエンドは、挿入中にエンドユーザー コンテキストの追加クレームを JWT トークンに挿入できるようになります。このクレームには、クライアントのログイン成功時に Auth0 によって提供されるトークンなど、エンド ユーザーを一意に識別する任意の文字列を指定できます。
After the additional claim is incorporated, the vault verifies the request and returns a bearer token containing the context identifier. The context-aware authorization flow diagram illustrates authentication with contextual information for the Skyflow customer and data retrieval.
追加のクレームが組み込まれた後、ボールトはリクエストを検証し、コンテキスト識別子を含むベアラー トークンを返します。コンテキスト認識型の認証フロー図は、Skyflow 顧客のコンテキスト情報を使用した認証とデータ取得を示しています。
Leveraging the returned bearer token with the context restriction, the frontend customer application can retrieve the PII and files owned by only the currently logged-in user.
コンテキスト制限付きで返されたベアラー トークンを利用することで、フロントエンドの顧客アプリケーションは、現在ログインしているユーザーのみが所有する PII とファイルを取得できます。
Furthermore, the time-to-live (TTL) of the bearer token can be controlled to ensure its validity only for the duration required to retrieve the record for the client.
さらに、ベアラー トークンの有効期間 (TTL) を制御して、クライアントのレコードを取得するのに必要な期間のみ有効性を確保できます。
Securing PII and Files from the Application Frontend
アプリケーション フロントエンドからの PII とファイルの保護
When collecting and managing sensitive data, such as files containing PII, it is prudent to exclude the entire application infrastructure from the security and compliance scope, including the frontend.
PII を含むファイルなどの機密データを収集および管理する場合、フロントエンドを含むアプリケーション インフラストラクチャ全体をセキュリティおよびコンプライアンスの範囲から除外することが賢明です。
Skyflow Elements offers a secure platform for collecting and revealing sensitive data, including files. It provides numerous advantages, including complete programmatic isolation from frontend applications, end-to-end encryption, tokenization, and customizable data collection forms.
Skyflow Elements は、ファイルなどの機密データを収集および公開するための安全なプラットフォームを提供します。これには、フロントエンド アプリケーションからのプログラムによる完全な分離、エンドツーエンドの暗号化、トークン化、カスタマイズ可能なデータ収集フォームなど、数多くの利点があります。
When users interact with Skyflow Elements, various components orchestrate to collect and reveal sensitive data. The process unfolds as follows:
ユーザーが Skyflow Elements を操作すると、さまざまなコンポーネントが連携して機密データを収集し、公開します。プロセスは次のように展開されます。
- When a user enters sensitive data into collect elements, the client-side SDK transmits the data to the vault and receives tokens representing the data.
- When the data needs to be revealed to a user, the client-side SDK sends the tokens to the vault, receives the data, and displays the data in reveal elements.
Following file upload, Skyflow automatically scans the file for viruses through the integrated CSS within the vault. The status of a scan can be retrieved using the Get Status Scan API.
ユーザーが機密データを収集要素に入力すると、クライアント側 SDK はデータをボールトに送信し、データを表すトークンを受け取ります。データをユーザーに公開する必要がある場合、クライアント側 SDK はトークンをボールトに送信します。 、データを受信し、そのデータをリビール要素に表示します。ファイルのアップロード後、Skyflow はボールト内の統合 CSS を通じてファイルのウイルスを自動的にスキャンします。スキャンのステータスは、Get Status Scan API を使用して取得できます。
If the file is virus-free, a SCAN_CLEAN status is returned, and the file becomes available for retrieval or in-page display. In the event of a virus detection, a SCAN_INFECTED status is returned, and the file is moved into quarantine.
ファイルにウイルスが存在しない場合は、SCAN_CLEAN ステータスが返され、ファイルの取得またはページ内表示が可能になります。ウイルスが検出された場合、SCAN_INFECTED ステータスが返され、ファイルは隔離に移動されます。
To reveal an uploaded file, it is embedded into the web frontend as an iframe, ensuring that the file never resides on the customer's servers.
アップロードされたファイルを明らかにするために、そのファイルは Web フロントエンドに iframe として埋め込まれ、ファイルが顧客のサーバーに常駐しないようにします。
Skyflow empowers organizations to delegate the security, privacy, and compliance responsibilities associated with sensitive file and PII handling, allowing them to focus on their core business objectives.
Skyflow を使用すると、組織は機密ファイルと PII の処理に関連するセキュリティ、プライバシー、コンプライアンスの責任を委任できるようになり、中核的なビジネス目標に集中できるようになります。
Conclusion
結論
In this comprehensive overview, we have explored the challenges organizations face in managing sensitive customer data. We have examined how to secure personally identifiable information (PII) using Skyflow Data Privacy Vault and further enhance protection against malware using Cloud Storage Security (CSS) on AWS.
この包括的な概要では、機密性の高い顧客データの管理において組織が直面する課題を検討してきました。 Skyflow Data Privacy Vault を使用して個人を特定できる情報 (PII) を保護し、AWS 上の Cloud Storage Security (CSS) を使用してマルウェアに対する保護をさらに強化する方法を検討しました。
We have also demonstrated how Skyflow Data Privacy Vault can securely collect, manage, and utilize sensitive data. Skyflow seamlessly integrates with CSS to provide automatic virus and malware detection and protection for files.
また、Skyflow Data Privacy Vault が機密データを安全に収集、管理、利用する方法を実証しました。 Skyflow は CSS とシームレスに統合し、ウイルスとマルウェアの自動検出とファイルの保護を提供します。
Organizations寻求更多信息,请联系 Skyflow 或在 AWS Marketplace 中试用 Skyflow。关于 Cloud Storage Security 的更多信息,请访问 AWS Marketplace 中的 CSS。
詳細をお探しの組織は、Skyflow にお問い合わせいただくか、AWS Marketplace で Skyflow をお試しください。クラウドストレージセキュリティの詳細については、AWS Marketplace の CSS をご覧ください。
免責事項:info@kdj.com
提供される情報は取引に関するアドバイスではありません。 kdj.com は、この記事で提供される情報に基づいて行われた投資に対して一切の責任を負いません。暗号通貨は変動性が高いため、十分な調査を行った上で慎重に投資することを強くお勧めします。
このウェブサイトで使用されているコンテンツが著作権を侵害していると思われる場合は、直ちに当社 (info@kdj.com) までご連絡ください。速やかに削除させていただきます。

































