Forum Discussion

Duncan_Proffitt's avatar
Duncan_Proffitt
Icon for Altostratus rankAltostratus
Feb 20, 2018

Fileshare on cloud with a rotating private key .. what a mouthful!

So, one of the security architects around me was pulling his hair out (what little of it there was to start with) as he is presented with this scenario

 

User A creates a file using a well-known office product. It contains highly sensitive information and he wants it secured and encrypted. But it must be stored on a disk, in a cloud facility. (Shared/Dedicated options available) SSL to be used, but the user must control the private key.

 

He asks me, can the F5 do this?

 

The questions to be answered 1) How is access control measured? (Who can decyrpt this?) 2) Where is the private key stored (the customer must have control of it) 3) There will be a million and a half keys and will have to be rotated without the file being decrypted first.

 

Is this something we can do?

 

1 Reply

  • taunan_89710's avatar
    taunan_89710
    Historic F5 Account

    Duncan,

     

    The BIGIP can be used for encrypted transport via TLS and we can even encrypt fields in the DOM of a web app using Fraud Protection Services. However storage encryption is not a current feature in F5's stable of products. We can certainly be customized to be involved for transport and network access but management of the actual file and it's keys would be best handled by another device.