Click to Play

Consumer Generated Content ...
Consumer generated media is present everywhere we turn. It's a natural part of our society and a growing part of business practices, especially in advertising..

Recent Articles

Managing Your Reputation Through Google Profiles
Google has launched a new way to search for individuals called Google Profiles.Setting up a Google Profiles account takes only a couple of minutes. The screen shot below shows a snapshot of the new Profile listing...

Using Social Computing Within The Corporate World
Continuing further with interesting video links that describe how large businesses are making use of social software, both inside and outside of the firewall, to help improve the way knowledge workers collaborate...

Are You Up To Date On Web Analytics Technology?
Last week CMS Watch announced they have launched a new web analytics training course called: "Fundamentals of Web Analytics Technology." The 4 module course is taught by CMS Watch founder, Tony Byrne and...

Competition Heats Amoung CRM Software Giants
Here are several excerpts from an interesting article by Bob Evans about the competition between the CRM software (and cloud computing) industry giants, (salesforce.com, Oracle, SAP and Microsoft), Global CIO: Salesforce CEO Marc Benioff Has Declared War - Are...

Accurate Reports And Monitoring For Social Media
I am crossing posting this from AppGap as I am now using the free version of this tool and find it quite helpful. The new Web offers great transparency if you are able to find what is being said on a topic in the...

Making Agile Software Truly Agile
Earlier I posted Focusing on decisions to improve the software end product and I decided that this week's posts would be a series of follow-ups on how decision management can and should impact software...


05.11.09

Making Your Cloud Server Architecture Secure

By Mike Kavis

There are a lot of discussions going on about security and compliance in the cloud. The concerns are valid, but the belief that they can't be resolved are not. When you buy a cluster of servers and install them in your data center, are they secure? Of course not. There are many things one must do from the perspective of hardware, operating systems, process and policy, network, data center, and software in order to secure those servers and the applications or services running on them.

This is true whether you are in the cloud or not. The cloud does add additional security requirements but all of them are solvable if you can identify them and architect for them.

With that said, I would like to share a couple of approaches that my team has designed. I will make it generic enough not to give away any of our secret sauce. As I mentioned in the past, we are building a 100% off-premise solution for processing real time transactions in the cloud. We are using a hybrid cloud approach made up of a public cloud and a virtual private cloud (VPC) for dealing with sensitive data and compliance requirements. There are two models that we like, each with their pros and cons.

The first model is the Public Master Model where the public cloud is the entry point to our platform (see diagram below).



From Cloud Computing
The second model is VPC Master Model where the virtual private cloud is the entry point to our platform (see diagram below).

Ektron CMS400.NET Now With PageBuilder:
Instant Demo



From Cloud Computing

Now let me discuss each model one at a time.

Public Master

The concept of the Public Master Model is to maximize the use of the cheaper computing platform which is the public cloud.  The public cloud is substantially cheaper than any private cloud solution because of the shared resource model (meaning that you are sharing resources with other companies).  Another factor is that Amazon excels in public cloud solutions which makes it an easier pill to swallow for your potential customers and partners, especially the ones that fear the cloud.

Any data that enters the cloud (per our requirements) will be encrypted and each partner/customer that we interface with must pass us their unique security key with every message.  We validate their key against our private key pair in our security layer.  All data is then replicated from the master database to slave databases in multiple data centers in the public cloud.  Also, all data is replicated to the master and slave copies in multiple locations in the VPC through the intercloud connection.  The intercloud is the equivalent of a virtual private network between clouds where only certain elastic IPs are allowed to carry out communications.  Once again encryption and secure protocols are used for each transmission.

Continue reading this article.


About the Author:
Mike Kavis is a veteran Chief Architect with over 23 years of IT experience including distributed computing, SOA, BPM, data warehouse, business intelligence, and enterprise architecture. Read Mike's blog at Enterprise Initiatives.
About CIOproNews

The latest news and information for the CIO professional





CIOproNews is brought to you by:

SecurityConfig.com NetworkingFiles.com
NetworkNewz.com WebProASP.com
PerlProNews.com SQLProNews.com
SysAdminNews DevWebPro.com
LinuxProNews.com WirelessProNews.com
CProgrammingTrends.com ITCertificationNews.com





-- CIOproNews is an iEntry, Inc. publication --
iEntry, Inc. 2549 Richmond Rd. Lexington KY, 40509
2009 iEntry, Inc. All Rights Reserved Privacy Policy Legal

archives | advertising info | news headlines | free newsletters | comments/feedback | submit article


CIOproNews News Archives About Us Feedback CIOproNews Home Page About Article Archive News Downloads WebProWorld Forums Jayde iEntry Advertise Contact