Kinakuta -‐ 22jul2010
Index
• Current Trends • Cloud Risks • Our Solu3on Proposal – Value Proposi3on • How we Solve the Currents Issues • Our Solu3on vs. Competence • Our Strengths vs. Our Compe3tors
Current Trends • Organiza3ons are growing aware of the benefits of cloud compu3ng.
Among the main business incen3ves are: o Reduced costs, o Faster deployment 3mes,
o Increased efficiency, and
o Flexibility
• Recent independent research indicates that organiza3ons worldwide spent 4% of their IT budgets (16B) in cloud services in the year 2008 and that number will go up to 9% (42B) by 2012
• BoXom line: cloud services (IaaS, PaaS and SaaS) make economic sense for organiza3ons it’s only maXer of 3me for it’s widespread adop3on.
Cloud Risks – The Pain • Albeit the obvious benefits, organiza>ons are s>ll reluctant to move
completely to the cloud, specially regarding highly sensi3ve applica3ons such as private data handling and storage.
Current Security Issues Consequences
Compliance regula3ons (geolocaliza3on of records)
Companies are prevented from moving data freely
Failed recovery from cloud providers Poten3al impact on business process availability
Inappropriate or illegal ac3vi3es on the cloud Lack of trust on service providers; poten3al breach
Proper data segrega3on among cloud tenants Poten3al unauthorized access to sensi3ve data
Long-‐term viability of the cloud providers Poten3al impact on business process availability
Physical security of the data processing assets Poten3al confiden3ality breach
Unsupervised privileged access to sensi3ve data Poten3al confiden3ality breach
The Cumulus Secure Cloud Service at-‐a-‐glance
Cloud Service Providers (CSP)
• SaaS • IaaS
High Security
CUMULUS Broker
Service that provides security layers and intermedia3on
between End Customers and Cloud Compu3ng Service Providers (so_ware and
infrastructure)
Customers Key Benefits: • Mul3-‐tenancy
• Pay-‐as-‐you-‐go • Resilience
• No setup
• Service integra3on • Security / control
• Flexibility
Value Proposi>on -‐ Features
• Enable and improve the privacy and security on the following cloud services: • SaaS • IaaS Privacy
• Empower to the customer in order to control their own data on the cloud: • While the informa3on is in transfer • While the informa3on is in storage • While the informa3on is in process
Customer Control
• Enables customer to use cloud services without worrying about the geographic loca3on of the CSP and without breaking any privacy law
Compliance
A service that provides security layers and intermedia4on between end customers and cloud compu4ng service providers (so9ware and infrastructure)
Value Proposi>on -‐ Enablers
Advanced encryp>on techniques.
Allows some opera3ons on encrypted data that prevents that anyone knows the content except for the end
customer
SpliTng and context hiding service.
Hides sensi3ve informa3on to cloud providers that is not essen3al for doing its job
Anonymous use of cloud services.
Allows cloud customers to use cloud services without revealing their iden3ty
How We Solve the Currents Issues Current Issues about Security Our Solu>on
Compliance regula3ons (geolocaliza3on of records)
End–to–End advanced encryp3on of sensi3ve data and data splieng
Failed recovery from cloud providers High availability scheme for data storage in the cloud
Inappropriate or illegal ac3vi3es on the cloud
Audit logs + access roles + perimeter security for data opera3ons
Proper data segrega3on among cloud tenants
End-‐to-‐End advanced encryp3on+ access roles for data opera3ons
Long-‐term viability of the cloud providers
Flexible migra3on to alterna3ve providers of core services (storage and processing)
Physical security of the data processing assets
Hardware security modules for sensi3ve opera3ons
Unsupervised privileged access to sensi3ve data
Audit logs for data opera3ons
Architecture
GUI interface Data interface
XaaS interface
SaaS PaaS IaaS
Storage Billing Cloud Broker core components
ID mgmt. Access ctrl. Data security Business Int.
Cloud enabler
Tradi3onal /custom applica3ons
Workflow Interact. Plakorm Central mgmt.
Audit
Mobile & PC Users
Development stage
Brainstorm • Conceive
product
Definition • Analyze
market requirements
• Define product requierments
Construction • Design product • Develop product • Test product
Market launch • Launch product
Sales & support • Sustain product • Improvement
Next Steps towards market
• Conduct a thorough and independent market survey to determine the best market approach strategy (Es3mated cost: 50K~80K USD)
• Secure financing for prototype building and marke3ng (Es3mated required funding: 200K~800K USD)
• Go live!