|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
조직은 PII를 보호하고 규정 준수를 보장하는 데 어려움을 겪고 있습니다. Skyflow Data Privacy Vault는 민감한 데이터를 격리 및 보호하고 이를 다운스트림 스토리지용 토큰으로 변환하여 규정 준수 범위를 줄입니다. Cloud Storage Security는 업로드된 파일에 바이러스 및 악성 코드가 있는지 자동으로 검사하여 잠재적인 위협을 완화함으로써 이를 보완합니다. 이 파트너십은 파일 관리를 단순화하고 데이터 보안을 보장하며 규정 준수 부담을 덜어줍니다.

Securely Managing Personally Identifiable Information (PII) with Skyflow and Cloud Storage Security on AWS
AWS의 Skyflow 및 클라우드 스토리지 보안을 통해 개인 식별 정보(PII)를 안전하게 관리
Introduction
소개
Organizations entrusted with the management of personally identifiable information (PII) face significant challenges in maintaining the security and compliance of this sensitive data. Despite best efforts, PII often resides in a fragmented fashion across diverse repositories, including databases, data warehouses, log files, and backups, making comprehensive security and compliance measures difficult to implement.
개인 식별 정보(PII) 관리를 맡은 조직은 이 민감한 데이터의 보안과 규정 준수를 유지하는 데 있어 상당한 어려움에 직면해 있습니다. 최선의 노력에도 불구하고 PII는 데이터베이스, 데이터 웨어하우스, 로그 파일, 백업을 비롯한 다양한 저장소에 분산된 방식으로 상주하는 경우가 많아 포괄적인 보안 및 규정 준수 조치를 구현하기가 어렵습니다.
Furthermore, file management introduces additional complexities, necessitating stringent security measures, robust access controls, and compliance-aligned storage practices. The risk of data breaches and malware threats escalates when organizations receive files from external sources, such as customers. To mitigate these risks, organizations must meticulously scan external files for viruses and malware prior to processing.
또한 파일 관리로 인해 추가적인 복잡성이 발생하므로 엄격한 보안 조치, 강력한 액세스 제어 및 규정 준수 스토리지 방식이 필요합니다. 조직이 고객과 같은 외부 소스로부터 파일을 받으면 데이터 침해 및 맬웨어 위협의 위험이 더욱 커집니다. 이러한 위험을 완화하기 위해 조직은 처리하기 전에 외부 파일에서 바이러스 및 맬웨어를 꼼꼼하게 검사해야 합니다.
Addressing Challenges with Skyflow and Cloud Storage Security
Skyflow 및 클라우드 스토리지 보안 문제 해결
To minimize risk and alleviate the burdens associated with existing upstream and downstream systems, organizations leverage Skyflow, available within AWS Marketplace. Skyflow Data Privacy Vault delivers comprehensive security, compliance, and data residency for Amazon Web Services (AWS) workloads.
위험을 최소화하고 기존 업스트림 및 다운스트림 시스템과 관련된 부담을 완화하기 위해 조직은 AWS Marketplace에서 사용할 수 있는 Skyflow를 활용합니다. Skyflow Data Privacy Vault는 Amazon Web Services(AWS) 워크로드에 대한 포괄적인 보안, 규정 준수 및 데이터 상주를 제공합니다.
In conjunction with Skyflow, Cloud Storage Security (CSS) plays a crucial role in further safeguarding infrastructure and alleviating the complexities associated with sensitive file management. CSS, an AWS Specialization Partner with the Security Competency, automates the scanning of uploaded files for malicious code and malware.
Skyflow와 함께 CSS(Cloud Storage Security)는 인프라를 더욱 보호하고 민감한 파일 관리와 관련된 복잡성을 완화하는 데 중요한 역할을 합니다. 보안 컴피턴시를 보유한 AWS 전문화 파트너인 CSS는 업로드된 파일에서 악성 코드 및 맬웨어 검사를 자동화합니다.
Securing PII with Skyflow Data Privacy Vault
Skyflow 데이터 개인 정보 보호 볼트로 PII 보호
Skyflow, a software-as-a-service (SaaS) offering, supports both multi-tenant and single-tenant deployment models. Its Data Privacy Vault isolates, protects, and governs access to sensitive customer data, transforming it into opaque tokens that serve as references to the original data. These non-sensitive tokens can be securely stored in any application storage system or utilized in data warehouses.
SaaS(Software-as-a-Service) 제품인 Skyflow는 다중 테넌트 및 단일 테넌트 배포 모델을 모두 지원합니다. Data Privacy Vault는 민감한 고객 데이터에 대한 액세스를 격리, 보호 및 관리하여 이를 원본 데이터에 대한 참조 역할을 하는 불투명 토큰으로 변환합니다. 이러한 민감하지 않은 토큰은 모든 애플리케이션 스토리지 시스템에 안전하게 저장되거나 데이터 웨어하우스에서 활용될 수 있습니다.
A Skyflow vault enables the confinement of sensitive data within a specific geographic location and tightly controls access to this data. Other systems interact only with the non-sensitive tokenized data, effectively removing them from the scope of compliance. The tokenization process preserves formatting when necessary and maintains consistency for analytics and machine learning (ML) workflows.
Skyflow 저장소를 사용하면 민감한 데이터를 특정 지리적 위치 내에 격리하고 이 데이터에 대한 액세스를 엄격하게 제어할 수 있습니다. 다른 시스템은 민감하지 않은 토큰화된 데이터와만 상호 작용하여 규정 준수 범위에서 효과적으로 제거합니다. 토큰화 프로세스는 필요한 경우 형식을 유지하고 분석 및 기계 학습(ML) 워크플로의 일관성을 유지합니다.
Skyflow Data Privacy Vault serves as the core infrastructure for PII, providing compute, storage, and network resources as a service. Its architectural simplicity is achieved through an API call, and Skyflow employs polymorphic encryption to secure PII and preserve its usability. This enables the execution of operations on fully encrypted data.
Skyflow Data Privacy Vault는 PII의 핵심 인프라 역할을 하며 컴퓨팅, 스토리지 및 네트워크 리소스를 서비스로 제공합니다. 아키텍처 단순성은 API 호출을 통해 달성되며 Skyflow는 다형성 암호화를 사용하여 PII를 보호하고 유용성을 보존합니다. 이를 통해 완전히 암호화된 데이터에 대한 작업을 실행할 수 있습니다.
Organizations can seamlessly build PII-specific workloads on a Skyflow vault for tasks such as data sharing, analytics, and encrypted operations. This capability empowers businesses to identify records with specific attributes, such as area code, without decrypting the data or calculate customer income averages, all without exposing PII to unauthorized parties.
조직은 데이터 공유, 분석, 암호화된 작업과 같은 작업을 위해 Skyflow 저장소에 PII 관련 워크로드를 원활하게 구축할 수 있습니다. 이 기능을 통해 기업은 데이터를 해독하거나 고객 소득 평균을 계산하지 않고도 지역 번호와 같은 특정 속성이 있는 기록을 식별할 수 있으며, PII를 승인되지 않은 당사자에게 노출하지 않고도 가능합니다.
Working with a Skyflow Vault
Skyflow Vault 작업
While a data privacy vault differs from a traditional database, Skyflow Data Privacy Vault emulates certain database properties. Notably, a Skyflow vault supports a customizable schema consisting of tables, columns, and rows.
데이터 개인 정보 보호 볼트는 기존 데이터베이스와 다르지만 Skyflow Data Privacy Vault는 특정 데이터베이스 속성을 에뮬레이션합니다. 특히 Skyflow 볼트는 테이블, 열 및 행으로 구성된 사용자 정의 가능한 스키마를 지원합니다.
Skyflow's vault is specifically designed to manage the entire lifecycle of sensitive data, comprehensively understanding the structure and applications of PII. For instance, a Skyflow vault recognizes a social security number as a distinct data type, not merely a string. This deep understanding allows the vault to natively support use cases such as revealing only the last four digits of a social security number based on defined roles and policies or securely sharing the complete social security number with third-party vendors for identity verification purposes.
Skyflow의 저장소는 민감한 데이터의 전체 수명주기를 관리하고 PII의 구조와 적용을 포괄적으로 이해하도록 특별히 설계되었습니다. 예를 들어 Skyflow 저장소는 주민등록번호를 단순한 문자열이 아닌 고유한 데이터 유형으로 인식합니다. 이러한 깊은 이해를 통해 Vault는 정의된 역할 및 정책에 따라 주민등록번호의 마지막 4자리만 공개하거나 신원 확인 목적으로 전체 주민등록번호를 제3자 공급업체와 안전하게 공유하는 등의 사용 사례를 기본적으로 지원할 수 있습니다.
Beyond transforming sensitive data into non-sensitive forms, the vault strictly controls access to sensitive data through a zero-trust model. This model ensures that no user account or process can access data without explicit authorization via access control policies. These policies are meticulously constructed from the ground up, granting access to specific columns and rows of PII. This granular control enables organizations to meticulously define who can access what data, when, where, for how long, and in what format.
볼트는 민감한 데이터를 민감하지 않은 형식으로 변환하는 것 외에도 제로 트러스트 모델을 통해 민감한 데이터에 대한 액세스를 엄격하게 제어합니다. 이 모델은 액세스 제어 정책을 통해 명시적인 승인 없이는 사용자 계정이나 프로세스가 데이터에 액세스할 수 없도록 보장합니다. 이러한 정책은 처음부터 세심하게 구성되어 PII의 특정 열과 행에 대한 액세스 권한을 부여합니다. 이러한 세부적인 제어를 통해 조직은 누가 어떤 데이터에 언제, 어디서, 얼마나 오랫동안, 어떤 형식으로 액세스할 수 있는지 세심하게 정의할 수 있습니다.
For data storage, management, and retrieval, Skyflow offers both APIs and software development kits (SDKs). Skyflow supports both frontend and backend SDKs, providing flexibility based on integration requirements.
데이터 저장, 관리 및 검색을 위해 Skyflow는 API와 소프트웨어 개발 키트(SDK)를 모두 제공합니다. Skyflow는 프런트엔드 및 백엔드 SDK를 모두 지원하여 통합 요구 사항에 따라 유연성을 제공합니다.
Managing Secure File Storage with Skyflow and CSS
Skyflow 및 CSS를 사용하여 안전한 파일 저장소 관리
To demonstrate the secure storage and handling of files through Skyflow, we will examine how this solution effectively removes exposure to sensitive documents for both frontend and backend applications.
Skyflow를 통한 파일의 안전한 저장 및 처리를 시연하기 위해 이 솔루션이 프런트엔드 및 백엔드 애플리케이션 모두에서 민감한 문서에 대한 노출을 효과적으로 제거하는 방법을 살펴보겠습니다.
In addition to Skyflow Vault, the solution leverages Amazon API Gateway as the backend API entry point for passing non-sensitive data downstream, AWS Lambda to receive and securely store non-sensitive data in Amazon DynamoDB, AWS Secrets Manager for secure storage and management of the Skyflow vault service account key, Amazon DynamoDB to save the skyflow_id shared by the vault after secure file storage, and Cloud Storage Security to automatically ensure that files are free from viruses and other potential threats.
Skyflow Vault 외에도 이 솔루션은 민감하지 않은 데이터를 다운스트림으로 전달하기 위한 백엔드 API 진입점으로 Amazon API Gateway를 활용하고, AWS Lambda를 활용하여 민감하지 않은 데이터를 Amazon DynamoDB에 수신하고 안전하게 저장하며, AWS Secrets Manager를 통해 Skyflow 저장소 서비스 계정 키, 안전한 파일 저장 후 저장소에서 공유하는 skyflow_id를 저장하는 Amazon DynamoDB, 파일에 바이러스 및 기타 잠재적인 위협이 없는지 자동으로 확인하는 Cloud Storage Security가 있습니다.
The accompanying architecture diagram illustrates the file upload flow involving Skyflow, the aforementioned AWS services, and CSS.
함께 제공되는 아키텍처 다이어그램은 앞서 언급한 AWS 서비스 및 CSS인 Skyflow와 관련된 파일 업로드 흐름을 보여줍니다.
Access Control Mechanisms
액세스 제어 메커니즘
To govern access to the customer's vault, Skyflow employs policies that permit programmatic writes into the vault table for client records.
고객의 저장소에 대한 액세스를 관리하기 위해 Skyflow는 클라이언트 레코드의 저장소 테이블에 프로그래밍 방식으로 쓰기를 허용하는 정책을 사용합니다.
To ensure read and update access is restricted to the single record owned by the currently logged-in user, Skyflow customers can leverage authentication services like Auth0. The customer application can then identify the user based on the Auth0 token.
읽기 및 업데이트 액세스가 현재 로그인한 사용자가 소유한 단일 레코드로 제한되도록 하기 위해 Skyflow 고객은 Auth0과 같은 인증 서비스를 활용할 수 있습니다. 그러면 고객 애플리케이션은 Auth0 토큰을 기반으로 사용자를 식별할 수 있습니다.
Skyflow's vault respects the user's identity and restricts access accordingly. To fulfill this requirement, customers utilize Skyflow's context-aware authorization.
Skyflow의 저장소는 사용자의 신원을 존중하고 이에 따라 액세스를 제한합니다. 이 요구 사항을 충족하기 위해 고객은 Skyflow의 상황 인식 인증을 활용합니다.
Context-Aware Authorization
컨텍스트 인식 인증
Programmatic access to Skyflow APIs is controlled through a service account established within the Skyflow account. The roles assigned to the service account and the policies associated with those roles determine the level of access to a vault. The creation of Skyflow roles, policies, and service accounts can be managed programmatically via Skyflow's management APIs or through Skyflow Studio, Skyflow's web-based vault administration portal.
Skyflow API에 대한 프로그래밍 방식의 액세스는 Skyflow 계정 내에 설정된 서비스 계정을 통해 제어됩니다. 서비스 계정에 할당된 역할과 해당 역할과 연결된 정책에 따라 Vault에 대한 액세스 수준이 결정됩니다. Skyflow 역할, 정책 및 서비스 계정 생성은 Skyflow의 관리 API 또는 Skyflow의 웹 기반 저장소 관리 포털인 Skyflow Studio를 통해 프로그래밍 방식으로 관리할 수 있습니다.
Context-aware authorization empowers the backend to insert an additional claim for end-user context into the JWT token during insertion. This claim can be any string that uniquely identifies the end user, such as the token provided by Auth0 upon successful client login.
컨텍스트 인식 승인은 백엔드가 삽입 중에 JWT 토큰에 최종 사용자 컨텍스트에 대한 추가 청구를 삽입할 수 있는 권한을 부여합니다. 이 클레임은 성공적인 클라이언트 로그인 시 Auth0에서 제공하는 토큰과 같이 최종 사용자를 고유하게 식별하는 문자열일 수 있습니다.
After the additional claim is incorporated, the vault verifies the request and returns a bearer token containing the context identifier. The context-aware authorization flow diagram illustrates authentication with contextual information for the Skyflow customer and data retrieval.
추가 클레임이 통합된 후 자격 증명 모음은 요청을 확인하고 컨텍스트 식별자가 포함된 전달자 토큰을 반환합니다. 상황 인식 인증 흐름 다이어그램은 Skyflow 고객 및 데이터 검색에 대한 상황별 정보를 사용한 인증을 보여줍니다.
Leveraging the returned bearer token with the context restriction, the frontend customer application can retrieve the PII and files owned by only the currently logged-in user.
프런트엔드 고객 애플리케이션은 반환된 전달자 토큰을 컨텍스트 제한과 함께 활용하여 현재 로그인한 사용자만 소유한 PII 및 파일을 검색할 수 있습니다.
Furthermore, the time-to-live (TTL) of the bearer token can be controlled to ensure its validity only for the duration required to retrieve the record for the client.
또한 전달자 토큰의 TTL(Time-To-Live)을 제어하여 클라이언트의 레코드를 검색하는 데 필요한 기간 동안만 유효성을 보장할 수 있습니다.
Securing PII and Files from the Application Frontend
애플리케이션 프런트엔드에서 PII 및 파일 보호
When collecting and managing sensitive data, such as files containing PII, it is prudent to exclude the entire application infrastructure from the security and compliance scope, including the frontend.
PII가 포함된 파일과 같은 민감한 데이터를 수집하고 관리할 때는 프런트엔드를 포함하여 보안 및 규정 준수 범위에서 전체 애플리케이션 인프라를 제외하는 것이 좋습니다.
Skyflow Elements offers a secure platform for collecting and revealing sensitive data, including files. It provides numerous advantages, including complete programmatic isolation from frontend applications, end-to-end encryption, tokenization, and customizable data collection forms.
Skyflow Elements는 파일을 포함한 민감한 데이터를 수집하고 공개하기 위한 안전한 플랫폼을 제공합니다. 이는 프런트엔드 애플리케이션으로부터의 완전한 프로그래밍 방식 격리, 종단 간 암호화, 토큰화 및 사용자 정의 가능한 데이터 수집 양식을 포함하여 수많은 이점을 제공합니다.
When users interact with Skyflow Elements, various components orchestrate to collect and reveal sensitive data. The process unfolds as follows:
사용자가 Skyflow Elements와 상호 작용하면 다양한 구성 요소가 조정되어 중요한 데이터를 수집하고 공개합니다. 프로세스는 다음과 같이 전개됩니다.
- When a user enters sensitive data into collect elements, the client-side SDK transmits the data to the vault and receives tokens representing the data.
- When the data needs to be revealed to a user, the client-side SDK sends the tokens to the vault, receives the data, and displays the data in reveal elements.
Following file upload, Skyflow automatically scans the file for viruses through the integrated CSS within the vault. The status of a scan can be retrieved using the Get Status Scan API.
사용자가 수집 요소에 민감한 데이터를 입력하면 클라이언트 측 SDK는 데이터를 저장소로 전송하고 데이터를 나타내는 토큰을 받습니다. 데이터를 사용자에게 공개해야 하는 경우 클라이언트 측 SDK는 토큰을 저장소로 보냅니다. , 데이터를 수신하고 공개 요소에 데이터를 표시합니다. 파일 업로드 후 Skyflow는 Vault 내의 통합 CSS를 통해 파일에 바이러스가 있는지 자동으로 검사합니다. Get Status Scan API를 사용하여 스캔 상태를 검색할 수 있습니다.
If the file is virus-free, a SCAN_CLEAN status is returned, and the file becomes available for retrieval or in-page display. In the event of a virus detection, a SCAN_INFECTED status is returned, and the file is moved into quarantine.
파일에 바이러스가 없으면 SCAN_CLEAN 상태가 반환되고 파일을 검색하거나 페이지 내 표시에 사용할 수 있게 됩니다. 바이러스가 탐지되면 SCAN_INFECTED 상태가 반환되고 파일은 격리 저장소로 이동됩니다.
To reveal an uploaded file, it is embedded into the web frontend as an iframe, ensuring that the file never resides on the customer's servers.
업로드된 파일을 표시하기 위해 파일이 iframe으로 웹 프런트엔드에 내장되어 파일이 고객의 서버에 상주하지 않도록 합니다.
Skyflow empowers organizations to delegate the security, privacy, and compliance responsibilities associated with sensitive file and PII handling, allowing them to focus on their core business objectives.
Skyflow를 통해 조직은 민감한 파일 및 PII 처리와 관련된 보안, 개인 정보 보호 및 규정 준수 책임을 위임하여 핵심 비즈니스 목표에 집중할 수 있습니다.
Conclusion
결론
In this comprehensive overview, we have explored the challenges organizations face in managing sensitive customer data. We have examined how to secure personally identifiable information (PII) using Skyflow Data Privacy Vault and further enhance protection against malware using Cloud Storage Security (CSS) on AWS.
이 포괄적인 개요에서 우리는 조직이 민감한 고객 데이터를 관리할 때 직면하는 과제를 살펴보았습니다. 우리는 Skyflow Data Privacy Vault를 사용하여 개인 식별 정보(PII)를 보호하고 AWS의 클라우드 스토리지 보안(CSS)을 사용하여 맬웨어로부터의 보호를 더욱 강화하는 방법을 조사했습니다.
We have also demonstrated how Skyflow Data Privacy Vault can securely collect, manage, and utilize sensitive data. Skyflow seamlessly integrates with CSS to provide automatic virus and malware detection and protection for files.
또한 Skyflow Data Privacy Vault가 민감한 데이터를 안전하게 수집, 관리 및 활용할 수 있는 방법도 시연했습니다. Skyflow는 CSS와 원활하게 통합되어 자동 바이러스 및 맬웨어 감지 및 파일 보호 기능을 제공합니다.
Organizations寻求更多信息,请联系 Skyflow 或在 AWS Marketplace 中试用 Skyflow。关于 Cloud Storage Security 的更多信息,请访问 AWS Marketplace 中的 CSS。
더 많은 정보를 원하는 조직은 Skyflow에 문의하거나 AWS Marketplace에서 Skyflow를 사용해 보십시오. 클라우드 스토리지 보안에 대한 자세한 내용을 보려면 AWS Marketplace의 CSS를 방문하세요.
부인 성명:info@kdj.com
제공된 정보는 거래 조언이 아닙니다. kdj.com은 이 기사에 제공된 정보를 기반으로 이루어진 투자에 대해 어떠한 책임도 지지 않습니다. 암호화폐는 변동성이 매우 높으므로 철저한 조사 후 신중하게 투자하는 것이 좋습니다!
본 웹사이트에 사용된 내용이 귀하의 저작권을 침해한다고 판단되는 경우, 즉시 당사(info@kdj.com)로 연락주시면 즉시 삭제하도록 하겠습니다.

































