市值: $2.2043T 0.58%
成交额(24h): $56.8553B 3.76%
  • 市值: $2.2043T 0.58%
  • 成交额(24h): $56.8553B 3.76%
  • 恐惧与贪婪指数:
  • 市值: $2.2043T 0.58%
加密货币
话题
百科
资讯
加密话题
视频
热门新闻
加密货币
话题
百科
资讯
加密话题
视频
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

加密货币新闻

使用 Skyflow 和 AWS 上增强的文件安全性安全地管理 PII

2024/04/18 04:23

组织在保护 PII 和确保合规性方面面临挑战。 Skyflow Data Privacy Vault 隔离并保护敏感数据,将其转换为下游存储的令牌,从而缩小合规范围。云存储安全通过自动扫描上传的文件是否有病毒和恶意软件来补充这一点,从而减轻潜在的威胁。这种合作关系简化了文件管理、确保数据安全并减轻了合规负担。

使用 Skyflow 和 AWS 上增强的文件安全性安全地管理 PII

Securely Managing Personally Identifiable Information (PII) with Skyflow and Cloud Storage Security on AWS

使用 AWS 上的 Skyflow 和云存储安全性安全管理个人身份信息 (PII)

Introduction

介绍

Organizations entrusted with the management of personally identifiable information (PII) face significant challenges in maintaining the security and compliance of this sensitive data. Despite best efforts, PII often resides in a fragmented fashion across diverse repositories, including databases, data warehouses, log files, and backups, making comprehensive security and compliance measures difficult to implement.

负责管理个人身份信息 (PII) 的组织在维护这些敏感数据的安全性和合规性方面面临着重大挑战。尽管尽了最大努力,PII 通常以分散的方式驻留在不同的存储库中,包括数据库、数据仓库、日志文件和备份,使得全面的安全和合规性措施难以实施。

Furthermore, file management introduces additional complexities, necessitating stringent security measures, robust access controls, and compliance-aligned storage practices. The risk of data breaches and malware threats escalates when organizations receive files from external sources, such as customers. To mitigate these risks, organizations must meticulously scan external files for viruses and malware prior to processing.

此外,文件管理带来了额外的复杂性,需要严格的安全措施、强大的访问控制和合规性存储实践。当组织从外部来源(例如客户)接收文件时,数据泄露和恶意软件威胁的风险就会升级。为了减轻这些风险,组织必须在处理之前仔细扫描外部文件是否有病毒和恶意软件。

Addressing Challenges with Skyflow and Cloud Storage Security

利用 Skyflow 和云存储安全应对挑战

To minimize risk and alleviate the burdens associated with existing upstream and downstream systems, organizations leverage Skyflow, available within AWS Marketplace. Skyflow Data Privacy Vault delivers comprehensive security, compliance, and data residency for Amazon Web Services (AWS) workloads.

为了最大限度地降低风险并减轻与现有上游和下游系统相关的负担,组织利用 AWS Marketplace 中提供的 Skyflow。 Skyflow Data Privacy Vault 为 Amazon Web Services (AWS) 工作负载提供全面的安全性、合规性和数据驻留。

In conjunction with Skyflow, Cloud Storage Security (CSS) plays a crucial role in further safeguarding infrastructure and alleviating the complexities associated with sensitive file management. CSS, an AWS Specialization Partner with the Security Competency, automates the scanning of uploaded files for malicious code and malware.

与 Skyflow 相结合,云存储安全 (CSS) 在进一步保护基础设施和减轻与敏感文件管理相关的复杂性方面发挥着至关重要的作用。 CSS 是具有安全能力的 AWS 专业化合作伙伴,可自动扫描上传的文件中是否存在恶意代码和恶意软件。

Securing PII with Skyflow Data Privacy Vault

使用 Skyflow Data Privacy Vault 保护 PII

Skyflow, a software-as-a-service (SaaS) offering, supports both multi-tenant and single-tenant deployment models. Its Data Privacy Vault isolates, protects, and governs access to sensitive customer data, transforming it into opaque tokens that serve as references to the original data. These non-sensitive tokens can be securely stored in any application storage system or utilized in data warehouses.

Skyflow 是一种软件即服务 (SaaS) 产品,支持多租户和单租户部署模型。其数据隐私保险库隔离、保护和管理对敏感客户数据的访问,将其转换为不透明的令牌,用作原始数据的引用。这些非敏感令牌可以安全地存储在任何应用程序存储系统中或在数据仓库中使用。

A Skyflow vault enables the confinement of sensitive data within a specific geographic location and tightly controls access to this data. Other systems interact only with the non-sensitive tokenized data, effectively removing them from the scope of compliance. The tokenization process preserves formatting when necessary and maintains consistency for analytics and machine learning (ML) workflows.

Skyflow 保管库可以将敏感数据限制在特定地理位置内,并严格控制对此数据的访问。其他系统仅与非敏感标记化数据交互,从而有效地将它们从合规范围中删除。标记化过程会在必要时保留格式,并保持分析和机器学习 (ML) 工作流程的一致性。

Skyflow Data Privacy Vault serves as the core infrastructure for PII, providing compute, storage, and network resources as a service. Its architectural simplicity is achieved through an API call, and Skyflow employs polymorphic encryption to secure PII and preserve its usability. This enables the execution of operations on fully encrypted data.

Skyflow Data Privacy Vault 充当 PII 的核心基础设施,以服务形式提供计算、存储和网络资源。其架构简单性是通过 API 调用实现的,Skyflow 采用多态加密来保护 PII 并保持其可用性。这使得能够对完全加密的数据执行操作。

Organizations can seamlessly build PII-specific workloads on a Skyflow vault for tasks such as data sharing, analytics, and encrypted operations. This capability empowers businesses to identify records with specific attributes, such as area code, without decrypting the data or calculate customer income averages, all without exposing PII to unauthorized parties.

组织可以在 Skyflow 保管库上无缝构建特定于 PII 的工作负载,以执行数据共享、分析和加密操作等任务。此功能使企业能够识别具有特定属性(例如区号)的记录,而无需解密数据或计算客户平均收入,并且不会将 PII 暴露给未经授权的各方。

Working with a Skyflow Vault

使用 Skyflow Vault

While a data privacy vault differs from a traditional database, Skyflow Data Privacy Vault emulates certain database properties. Notably, a Skyflow vault supports a customizable schema consisting of tables, columns, and rows.

虽然数据隐私保管库与传统数据库不同,但 Skyflow Data Privacy Vault 模拟某些数据库属性。值得注意的是,SkyflowVault 支持由表、列和行组成的可自定义架构。

Skyflow's vault is specifically designed to manage the entire lifecycle of sensitive data, comprehensively understanding the structure and applications of PII. For instance, a Skyflow vault recognizes a social security number as a distinct data type, not merely a string. This deep understanding allows the vault to natively support use cases such as revealing only the last four digits of a social security number based on defined roles and policies or securely sharing the complete social security number with third-party vendors for identity verification purposes.

Skyflow 的保管库专门用于管理敏感数据的整个生命周期,全面了解 PII 的结构和应用。例如,Skyflow 金库将社会安全号码识别为独特的数据类型,而不仅仅是字符串。这种深入的理解使保险库能够原生支持用例,例如根据定义的角色和策略仅显示社会安全号码的最后四位数字,或者与第三方供应商安全地共享完整的社会安全号码以进行身份​​验证。

Beyond transforming sensitive data into non-sensitive forms, the vault strictly controls access to sensitive data through a zero-trust model. This model ensures that no user account or process can access data without explicit authorization via access control policies. These policies are meticulously constructed from the ground up, granting access to specific columns and rows of PII. This granular control enables organizations to meticulously define who can access what data, when, where, for how long, and in what format.

除了将敏感数据转换为非敏感形式外,保险库还通过零信任模型严格控制对敏感数据的访问。该模型确保没有通过访问控制策略明确授权的情况下,任何用户帐户或进程都无法访问数据。这些策略是从头开始精心构建的,允许访问 PII 的特定列和行。这种精细的控制使组织能够细致地定义谁可以访问哪些数据、何时、何地、多长时间以及以何种格式。

For data storage, management, and retrieval, Skyflow offers both APIs and software development kits (SDKs). Skyflow supports both frontend and backend SDKs, providing flexibility based on integration requirements.

对于数据存储、管理和检索,Skyflow 提供 API 和软件开发套件 (SDK)。 Skyflow 支持前端和后端 SDK,根据集成要求提供灵活性。

Managing Secure File Storage with Skyflow and CSS

使用 Skyflow 和 CSS 管理安全文件存储

To demonstrate the secure storage and handling of files through Skyflow, we will examine how this solution effectively removes exposure to sensitive documents for both frontend and backend applications.

为了演示通过 Skyflow 安全存储和处理文件,我们将研究该解决方案如何有效地消除前端和后端应用程序对敏感文档的暴露。

In addition to Skyflow Vault, the solution leverages Amazon API Gateway as the backend API entry point for passing non-sensitive data downstream, AWS Lambda to receive and securely store non-sensitive data in Amazon DynamoDB, AWS Secrets Manager for secure storage and management of the Skyflow vault service account key, Amazon DynamoDB to save the skyflow_id shared by the vault after secure file storage, and Cloud Storage Security to automatically ensure that files are free from viruses and other potential threats.

除了 Skyflow Vault 之外,该解决方案还利用 Amazon API Gateway 作为后端 API 入口点来向下游传递非敏感数据、AWS Lambda 来接收非敏感数据并将其安全地存储在 Amazon DynamoDB 中、AWS Secrets Manager 来安全存储和管理非敏感数据。 Skyflow 保管库服务帐户密钥、Amazon DynamoDB(用于在安全文件存储后保存保管库共享的 skyflow_id)以及 Cloud Storage Security(自动确保文件免受病毒和其他潜在威胁)。

The accompanying architecture diagram illustrates the file upload flow involving Skyflow, the aforementioned AWS services, and CSS.

随附的架构图说明了涉及 Skyflow、上述 AWS 服务和 CSS 的文件上传流程。

Access Control Mechanisms

访问控制机制

To govern access to the customer's vault, Skyflow employs policies that permit programmatic writes into the vault table for client records.

为了管理对客户保管库的访问,Skyflow 采用允许以编程方式写入客户记录保管库表的策略。

To ensure read and update access is restricted to the single record owned by the currently logged-in user, Skyflow customers can leverage authentication services like Auth0. The customer application can then identify the user based on the Auth0 token.

为了确保读取和更新访问权限仅限于当前登录用户拥有的单个记录,Skyflow 客户可以利用 Auth0 等身份验证服务。然后,客户应用程序可以根据 Auth0 令牌识别用户。

Skyflow's vault respects the user's identity and restricts access accordingly. To fulfill this requirement, customers utilize Skyflow's context-aware authorization.

Skyflow 的保管库尊重用户的身份并相应地限制访问。为了满足此要求,客户利用 Skyflow 的上下文感知授权。

Context-Aware Authorization

上下文感知授权

Programmatic access to Skyflow APIs is controlled through a service account established within the Skyflow account. The roles assigned to the service account and the policies associated with those roles determine the level of access to a vault. The creation of Skyflow roles, policies, and service accounts can be managed programmatically via Skyflow's management APIs or through Skyflow Studio, Skyflow's web-based vault administration portal.

对 Skyflow API 的编程访问通过 Skyflow 帐户内建立的服务帐户进行控制。分配给服务帐户的角色以及与这些角色关联的策略决定对保管库的访问级别。 Skyflow 角色、策略和服务帐户的创建可以通过 Skyflow 的管理 API 或通过 Skyflow Studio(Skyflow 基于 Web 的保管库管理门户)以编程方式进行管理。

Context-aware authorization empowers the backend to insert an additional claim for end-user context into the JWT token during insertion. This claim can be any string that uniquely identifies the end user, such as the token provided by Auth0 upon successful client login.

上下文感知授权使后端能够在插入期间将最终用户上下文的附加声明插入到 JWT 令牌中。此声明可以是唯一标识最终用户的任何字符串,例如客户端成功登录时 Auth0 提供的令牌。

After the additional claim is incorporated, the vault verifies the request and returns a bearer token containing the context identifier. The context-aware authorization flow diagram illustrates authentication with contextual information for the Skyflow customer and data retrieval.

合并附加声明后,保管库验证该请求并返回包含上下文标识符的承载令牌。上下文感知授权流程图说明了使用 Skyflow 客户的上下文信息进行身份验证和数据检索。

Leveraging the returned bearer token with the context restriction, the frontend customer application can retrieve the PII and files owned by only the currently logged-in user.

利用返回的不记名令牌和上下文限制,前端客户应用程序可以检索仅当前登录用户拥有的 PII 和文件。

Furthermore, the time-to-live (TTL) of the bearer token can be controlled to ensure its validity only for the duration required to retrieve the record for the client.

此外,可以控制不记名令牌的生存时间 (TTL),以确保其仅在为客户端检索记录所需的持续时间内有效。

Securing PII and Files from the Application Frontend

保护应用程序前端的 PII 和文件

When collecting and managing sensitive data, such as files containing PII, it is prudent to exclude the entire application infrastructure from the security and compliance scope, including the frontend.

收集和管理敏感数据(例如包含 PII 的文件)时,明智的做法是将整个应用程序基础架构(包括前端)排除在安全和合规范围之外。

Skyflow Elements offers a secure platform for collecting and revealing sensitive data, including files. It provides numerous advantages, including complete programmatic isolation from frontend applications, end-to-end encryption, tokenization, and customizable data collection forms.

Skyflow Elements 提供了一个用于收集和泄露敏感数据(包括文件)的安全平台。它提供了许多优势,包括与前端应用程序的完全编程隔离、端到端加密、标记化和可定制的数据收集表单。

When users interact with Skyflow Elements, various components orchestrate to collect and reveal sensitive data. The process unfolds as follows:

当用户与 Skyflow Elements 交互时,各种组件会协调收集和泄露敏感数据。该过程展开如下:

  1. When a user enters sensitive data into collect elements, the client-side SDK transmits the data to the vault and receives tokens representing the data.
  2. When the data needs to be revealed to a user, the client-side SDK sends the tokens to the vault, receives the data, and displays the data in reveal elements.

Following file upload, Skyflow automatically scans the file for viruses through the integrated CSS within the vault. The status of a scan can be retrieved using the Get Status Scan API.

当用户将敏感数据输入到收集元素时,客户端 SDK 会将数据传输到保管库并接收代表该数据的令牌。当需要向用户透露数据时,客户端 SDK 会将令牌发送到保管库,接收数据,并在reve元素中显示数据。文件上传后,Skyflow会通过Vault内的集成CSS自动扫描文件是否存在病毒。可以使用获取状态扫描 API 检索扫描的状态。

If the file is virus-free, a SCAN_CLEAN status is returned, and the file becomes available for retrieval or in-page display. In the event of a virus detection, a SCAN_INFECTED status is returned, and the file is moved into quarantine.

如果文件没有病毒,则会返回 SCAN_CLEAN 状态,并且该文件可供检索或页内显示。如果检测到病毒,则会返回 SCAN_INFECTED 状态,并将文件移至隔离区。

To reveal an uploaded file, it is embedded into the web frontend as an iframe, ensuring that the file never resides on the customer's servers.

为了显示上传的文件,它将作为 iframe 嵌入到 Web 前端,确保该文件永远不会驻留在客户的服务器上。

Skyflow empowers organizations to delegate the security, privacy, and compliance responsibilities associated with sensitive file and PII handling, allowing them to focus on their core business objectives.

Skyflow 使组织能够委派与敏感文件和 PII 处理相关的安全、隐私和合规责任,从而使他们能够专注于核心业务目标。

Conclusion

结论

In this comprehensive overview, we have explored the challenges organizations face in managing sensitive customer data. We have examined how to secure personally identifiable information (PII) using Skyflow Data Privacy Vault and further enhance protection against malware using Cloud Storage Security (CSS) on AWS.

在这篇全面的概述中,我们探讨了组织在管理敏感客户数据时面临的挑战。我们研究了如何使用 Skyflow Data Privacy Vault 保护个人身份信息 (PII),并使用 AWS 上的 Cloud Storage Security (CSS) 进一步增强对恶意软件的防护。

We have also demonstrated how Skyflow Data Privacy Vault can securely collect, manage, and utilize sensitive data. Skyflow seamlessly integrates with CSS to provide automatic virus and malware detection and protection for files.

我们还演示了 Skyflow Data Privacy Vault 如何安全地收集、管理和利用敏感数据。 Skyflow 与 CSS 无缝集成,为文件提供自动病毒和恶意软件检测和保护。

Organizations寻求更多信息,请联系 Skyflow 或在 AWS Marketplace 中试用 Skyflow。关于 Cloud Storage Security 的更多信息,请访问 AWS Marketplace 中的 CSS。

Organizations寻求更多信息,请联系 Skyflow 或在 AWS Marketplace 中试用 Skyflow。关于 Cloud Storage Security 的更多信息,请访问 AWS Marketplace 中的 CSS。

免责声明:info@kdj.com

所提供的信息并非交易建议。根据本文提供的信息进行的任何投资,kdj.com不承担任何责任。加密货币具有高波动性,强烈建议您深入研究后,谨慎投资!

如您认为本网站上使用的内容侵犯了您的版权,请立即联系我们(info@kdj.com),我们将及时删除。

2026年08月10日 发表的其他文章