Brokered Cloud Storage Access
Brokered Cloud Storage Access
Cloud Broker is an entity that manages the use, performance and delivery
of cloud services, and relationships between cloud providers and cloud
consumers.
All the data stored in the cloud. It can be located in the cloud service
provider’s system used to transfer data from sent and received. The cloud
computing has no physical system that serves this purpose. To protect the
cloud storage is the way to isolate data from client direct access. They are
two services are created. One service for a broker with full access to
storage but no access to the client, and another service for a proxy with
no access to storage but access to both the client and broker. These
important two services are in the direct data path between the client and
data stored in the cloud. Under this system, when a client makes a request
for data, here’s what happens:
The proxy completes the response by sending the data requested to the
client.
Even if the proxy service is compromised, that service does not have
access to the trusted key that is necessary to access the cloud storage. In
the multi-key solution, not eliminated all internal service endpoints, but
proxy service run at a reduced trust level is eliminated. The creation of
storage zones with associated encryption keys can further protect cloud
storage from unauthorized access.
Because data stored in the cloud is usually stored from multiple tenants
the each vendor has its own unique method for segregating one
customer’s data from another. It’s important to understand how the
specific service provider maintains data segregation. Cloud storage
provider provides privileged access to storage. Most cloud service
providers store data in an encrypted form to protect the data used in
security mechanism. Hence, data cannot be accessed by the unauthorized
user.