Brokered Access in Cloud Storage
Brokered Access in Cloud Storage
com 25-Sep-2025 Pg 1 of 9
Security Boundaries
A particular service model defines the boundary between the
responsibilities of service provider and customer. Cloud
Security Alliance (CSA) stack model defines the boundaries
between each service model and shows how different
functional units relate to each other. The following diagram
shows the CSA stack model:
[Link]
Brokered Cloud Storage Access Mechanism * This document is prepared partially from LLM models Pg 1 of 9
Brokered Cloud Storage Access Mechanism compiled src7cse@[Link] 25-Sep-2025 Pg 2 of 9
Although each service model has security mechanism, the security needs also
depend upon where these services are located, in private, public, hybrid or
community cloud.
Brokered Cloud Storage Access Mechanism * This document is prepared partially from LLM models Pg 2 of 9
Brokered Cloud Storage Access Mechanism compiled src7cse@[Link] 25-Sep-2025 Pg 3 of 9
[Link]
Brokered Cloud Storage Access Mechanism * This document is prepared partially from LLM models Pg 3 of 9
Brokered Cloud Storage Access Mechanism compiled src7cse@[Link] 25-Sep-2025 Pg 4 of 9
Brokered Cloud Storage Access Mechanism * This document is prepared partially from LLM models Pg 4 of 9
Brokered Cloud Storage Access Mechanism compiled src7cse@[Link] 25-Sep-2025 Pg 5 of 9
○ Large enterprises often use multiple cloud providers for redundancy and
data backup. A brokered access mechanism simplifies managing these
disparate systems.
2. Data Compliance and Security
○ Industries such as finance and healthcare can use brokered access to enforce
stringent security and compliance requirements across multiple cloud
platforms.
3. Disaster Recovery and Backup
○ The broker can distribute data across several cloud providers, enhancing
data redundancy and ensuring that recovery is possible even if one provider
goes offline.
4. Hybrid Cloud Environments
○ Companies using a mix of private and public clouds can use brokers to
bridge the gap and create a seamless hybrid cloud experience.
Brokered Cloud Storage Access Mechanism * This document is prepared partially from LLM models Pg 5 of 9
Brokered Cloud Storage Access Mechanism compiled src7cse@[Link] 25-Sep-2025 Pg 6 of 9
Complexity Users must manage multiple APIs and Simplifies access by providing a
authentication systems. unified API and authentication.
Cost Efficiency Users need to manually manage Brokers can automate cost
cost-optimizing strategies. optimization across providers.
Scalability Scaling across multiple providers can Facilitates easy scaling across
be challenging. different cloud environments.
Vendor Lock-In More risk of being locked into a single Reduces lock-in by facilitating
cloud provider multi-cloud use
Brokered Cloud Storage Access Mechanism * This document is prepared partially from LLM models Pg 6 of 9
Brokered Cloud Storage Access Mechanism compiled src7cse@[Link] 25-Sep-2025 Pg 7 of 9
3. OpenStack Swift and Ceph are open-source cloud storage projects that can be
accessed via brokered mechanisms to manage object and block storage with a
focus on scalability and security.
Brokered Cloud Storage Access Mechanism in Cloud Computing
In cloud computing, a brokered cloud storage access mechanism is a system that mediates
between users and multiple cloud storage providers. It simplifies the process of accessing,
managing, and securing data across different cloud platforms by abstracting the
complexities of interacting with individual cloud providers. By doing this, it provides a
more unified, efficient, and secure approach to cloud storage access.
Key Functions of a Brokered Cloud Storage Access Mechanism
1. Unified Access:
○ A broker offers a unified API that abstracts the underlying complexities of
different cloud storage providers like AWS S3, Google Cloud Storage, or
Azure Blob Storage.
○ Users interact with a single interface rather than dealing with multiple cloud
storage APIs, allowing easier integration and interaction.
2. Authentication and Authorization:
○ The broker manages authentication and authorization processes, often using
systems like OAuth or API keys.
○ It can enforce role-based access control (RBAC), ensuring that only
authorized users can access specific data.
3. Data Encryption and Security:
○ Data is encrypted both at rest and in transit, with the broker often managing
the encryption keys.
○ The broker can enforce security policies and provide additional features
like monitoring, logging, and auditing to ensure compliance with security
standards.
4. Cross-Cloud Compatibility:
○ The broker facilitates access to multiple cloud providers, making it easier
for businesses to use a multi-cloud strategy.
○ It allows users to store and retrieve data from various cloud environments
seamlessly, without needing to worry about the specifics of each provider’s
storage system.
5. Performance Optimization:
○ The broker may optimize data storage by distributing it across different
cloud environments based on cost, performance, or latency requirements.
Brokered Cloud Storage Access Mechanism * This document is prepared partially from LLM models Pg 7 of 9
Brokered Cloud Storage Access Mechanism compiled src7cse@[Link] 25-Sep-2025 Pg 8 of 9
○ It can also implement caching mechanisms and ensure that data is retrieved
from the fastest or most cost-efficient storage.
6. Cost Efficiency:
○ By monitoring data access patterns, the broker can move infrequently
accessed data to lower-cost storage tiers or to different cloud providers that
offer better pricing.
○ It helps users avoid cloud vendor lock-in by distributing storage across
multiple providers.
Benefits of a Brokered Cloud Storage Mechanism
● Simplified Multi-Cloud Management: Users can manage data stored across
different cloud platforms through a single interface.
● Enhanced Security: Centralized management of authentication, encryption, and
access control improves data security.
● Cost Optimization: Brokers can automate the process of moving data between
different storage tiers and providers to optimize costs.
● Scalability: The broker can dynamically scale across different cloud providers to
accommodate growing data needs without manual intervention.
Use Cases of Brokered Cloud Storage Access
1. Hybrid Cloud Environments:
○ In hybrid cloud setups (a combination of private and public clouds), a
broker ensures seamless access to data across different environments,
enabling companies to store sensitive data on private clouds while using
public clouds for other applications.
2. Enterprise Data Management:
○ Large organizations with vast amounts of data often use multiple cloud
providers. A broker simplifies the management of data across these
different platforms.
3. Data Compliance and Governance:
○ For businesses operating in highly regulated industries (like healthcare or
finance), brokers help enforce compliance with data security and
governance policies by centralizing control and audit functions.
Brokered Cloud Storage Access Mechanism * This document is prepared partially from LLM models Pg 8 of 9
Brokered Cloud Storage Access Mechanism compiled src7cse@[Link] 25-Sep-2025 Pg 9 of 9
Brokered Cloud Storage Access Mechanism * This document is prepared partially from LLM models Pg 9 of 9
How to deal with storage location and tenancy compiled src7cse@[Link] 25-Sept-2025 Pg 2 of 7
[Link]
Here's a concise overview of dealing with storage location and tenancy for securing
data in cloud computing, along with an example case:
Storage location and multi-tenancy are crucial aspects of data security in cloud
computing. Cloud providers often store data across multiple geographic locations for
redundancy and performance. However, this can raise compliance and privacy
concerns. To address this:
1. Data residency: Ensure data is stored in locations that comply with relevant
regulations.
2. Data sovereignty: Be aware of laws governing data access in different
jurisdictions.
3. Encryption: Use strong encryption for data at rest and in transit.
4. Access controls: Implement robust identity and access management.
5. Tenant isolation: Ensure proper logical separation between different tenants'
data.
Example case: A multinational financial services company needs to store customer data
in the cloud while complying with various regional regulations. They work with a cloud
provider that offers:
How to deal with storage… This document is prepared partially from LLM models Pg 2 of 7
uteyde j guol
svices have dutind
eleud rao fo touch
) A anagement
set up
( e sterage lfini
tnplate fer servi
pature o [Link]
Tuis
wsers Manggnent)
cuatome relan
Ineraein(sLA
2) Tentabout managing leul agreml
Steglis sLA(semiu at
up
eting dieno ndentano tues4
and enureo
ve guarantes tc
can ac
Staga4Senia Optzation
Snvolus tunng servie,
inca wser
performao Bal
perermana
twears n
fedl batk
exampll The company, te
spedo ore o irereas
1hg
Main the ce
fainerisue as
Operotion
Stoge 5 monierng hen conducig
>]nvdws adagasig
thy appeor
ond
maintaunene. Aopota nomed
iena ne andore b
Oonaured that fheir wAae Corre cty
(scuss
cloud storaqg seriie -pr
ie d u e reciue autnatd
ver Customar
inveice
nolongrineedothe serie
ed & y
wnen iien °complet
pronder
’
tne sevia olievt
taak
renaid
eientts data
cantactual
e h t
agremet one
staglmale
and ay
(dantity Managnen
jahdod that aye
Pidertity verHcahm oe
fologin
CAe fo enen
to,
Ye enteing Crdetal
how tt worS
presuted to sevie tu
acers to
ckA oth openD provider
The seve
Asertin Morkup ag
hat exdhangesauthentiat
4nasstandord
uTn [Link]
povbr
oboto
ASA ML to SOrvice
acces muttple
one and
seaitve fo
enareanat Omauthomd
neryptn
npYVata/ secUvO hrom
ven
data
nab to
accer hackg eun
eoe)
Pegal
tunt in cloudforg
aea jn ctoud
pVatE
behueo
sore enyidtion
Sale and
apS data acceA
cloud Advantages d clouo Storag
ad ata
roliakaity
aahene,
Ram
Teduca acesd
is uke ong
is neesoato
nd read data.
wth cere
managad
aidbereg
should iereal,
bayenchcala
lccyde
y Delined uy
in becured rage
acen
-basd
wth ou EnuYe. y
led Backup.
Autom
Preuat
aye beCheacidbutal
d
cuofent
and allsws
wndle puysota mare
martnoce
curity breacha
ndutrty Se ytau
kalps to
’illegal acthvit adendttng
sogice provider
iterent Cloud
ing rmats
seaitve fo
enareanat Omauthomd
neryptn
npYVata/ secUvO hrom
ven
data
nab to
accer hackg eun
eoe)
Pegal
tunt in cloudforg
aea jn ctoud
pVatE
behueo
sore enyidtion
Sale and
apS data acceA
cloud Advantages d clouo Storag
ad ata
roliakaity
aahene,
Ram
Teduca acesd
is uke ong
is neesoato
nd read data.
wth cere
managad
aidbereg
should iereal,
bayenchcala
lccyde
y Delined uy
in becured rage
acen
-basd
wth ou EnuYe. y
led Backup.
Autom
Preuat
aye beCheacidbutal
d
cuofent
and allsws
wndle puysota mare
martnoce
curity breacha
ndutrty Se ytau
kalps to
’illegal acthvit adendttng
sogice provider
iterent Cloud
ing rmats
inveice
nolongrineedothe serie
ed & y
wnen iien °complet
pronder
’
tne sevia olievt
taak
renaid
eientts data
cantactual
e h t
agremet one
staglmale
and ay
(dantity Managnen
jahdod that aye
Pidertity verHcahm oe
fologin
CAe fo enen
to,
Ye enteing Crdetal
how tt worS
presuted to sevie tu
acers to
ckA oth openD provider
The seve
Asertin Morkup ag
hat exdhangesauthentiat
4nasstandord
uTn [Link]
povbr
oboto
ASA ML to SOrvice
acces muttple
one and
FIGURE 12.6
The home page of the DataPortabiliy Project, an industry working group that promoles op
Remix.
Guo DataPortability Connect. Control. Share.
Project
Follow
Get Informed Particlpt
About Implement eDralortabry oed
Subsoce to our
mlormaoon chamei t
UnAs ro a tne resoTEet
Ma erer chekes abuut Dan upen ss roors
Oeree ef the ea sotar. Cheoe g a n
uann ohe ntards nerd ra mplenent dara gazation paeered by
partatiy techncNagies in
dma a ne people be ou
ranizatsorn Ivched Dur soTr
Haor Camparton Cho
fueiness Care Lst of Qpes IOns
ionk or ne Loge
stry ef the Prjea
Highlights
wee hai
[Link]
How to deal with storage location and tenancy compiled src7cse@[Link] 25-Sept-2025 Pg 1 of 7
How to deal with storage location and tenancy for securing data in Cloud
Computing?
(This document is prepared partially from LLM models)
[Link]
How to deal with storage… This document is prepared partially from LLM models Pg 1 of 7
How to deal with storage location and tenancy compiled src7cse@[Link] 25-Sept-2025 Pg 2 of 7
[Link]
Here's a concise overview of dealing with storage location and tenancy for securing
data in cloud computing, along with an example case:
Storage location and multi-tenancy are crucial aspects of data security in cloud
computing. Cloud providers often store data across multiple geographic locations for
redundancy and performance. However, this can raise compliance and privacy
concerns. To address this:
1. Data residency: Ensure data is stored in locations that comply with relevant
regulations.
2. Data sovereignty: Be aware of laws governing data access in different
jurisdictions.
3. Encryption: Use strong encryption for data at rest and in transit.
4. Access controls: Implement robust identity and access management.
5. Tenant isolation: Ensure proper logical separation between different tenants'
data.
Example case: A multinational financial services company needs to store customer data
in the cloud while complying with various regional regulations. They work with a cloud
provider that offers:
How to deal with storage… This document is prepared partially from LLM models Pg 2 of 7
How to deal with storage location and tenancy compiled src7cse@[Link] 25-Sept-2025 Pg 3 of 7
The company implements a hybrid cloud solution, keeping sensitive data on-premises
and using the cloud for less sensitive workloads. They use data classification and
tagging to ensure data is stored in appropriate locations and apply encryption and
access controls consistently across their infrastructure.
[Link]
When migrating data to the cloud, ensuring its security is paramount. Two crucial factors
to consider are storage location and tenancy.
Storage location refers to the geographical region where your data is stored. This can
influence factors like data latency, regulatory compliance, and potential risks. For
instance, if your business operates primarily in Europe, storing data in a European data
center ensures compliance with GDPR regulations. However, storing data in a region
with a different legal framework might expose it to potential risks.
Tenancy refers to the level of isolation between your data and other tenants on the
same cloud platform. In a multi-tenant environment, multiple organizations share the
same infrastructure. 1 While this can be cost-effective, it raises concerns about data
isolation. 2 Cloud providers typically employ various techniques like logical isolation,
encryption, and access controls to mitigate these risks. 3 In contrast, a single-tenant
environment provides dedicated resources for your data, offering a higher level of
security but at a potentially higher cost.
How to deal with storage… This document is prepared partially from LLM models Pg 3 of 7
How to deal with storage location and tenancy compiled src7cse@[Link] 25-Sept-2025 Pg 4 of 7
Example: A healthcare organization might choose to store patient data in a data center located within the country to
comply with local healthcare regulations. To mitigate risks associated with multi-tenancy, they could opt for a private
cloud or a dedicated server within a public cloud.
Security Planning
Before deploying a particular resource to cloud, one should need to analyze
several aspects of the resource such as:
Select resource that needs to move to the cloud and analyze its sensitivity
to risk.
Consider cloud service models such as IaaS, PaaS, and SaaS. These
models require customer to be responsible for security at different levels
of service.
Consider the cloud type to be used such as public, private, community
or hybrid.
Understand the cloud service provider's system about data storage and its
transfer into and out of the cloud.
The risk in cloud deployment mainly depends upon the service models and cloud
types.
How to deal with storage… This document is prepared partially from LLM models Pg 4 of 7
How to deal with storage location and tenancy compiled src7cse@[Link] 25-Sept-2025 Pg 5 of 7
Security Boundaries
[Link]
How to deal with storage… This document is prepared partially from LLM models Pg 5 of 7
How to deal with storage location and tenancy compiled src7cse@[Link] 25-Sept-2025 Pg 6 of 7
Although each service model has security mechanism, the security needs also
depend upon where these services are located, in private, public, hybrid or
community cloud.
Access Control
Auditing
Authentication
Authorization
All of the service models should incorporate security mechanism operating in all
above-mentioned areas.
How to deal with storage… This document is prepared partially from LLM models Pg 6 of 7
How to deal with storage location and tenancy compiled src7cse@[Link] 25-Sept-2025 Pg 7 of 7
The client data request goes to the external service interface of proxy.
The proxy forwards the request to the broker.
The broker requests the data from cloud storage system.
The cloud storage system returns the data to the broker.
The broker returns the data to proxy.
Finally the proxy sends the data to the client.
[Link]
Encryption
Encryption helps to protect data from being compromised. It protects data that
is being transferred as well as data stored in the cloud. Although encryption
helps to protect data from any unauthorized access, it does not prevent data
loss.
How to deal with storage… This document is prepared partially from LLM models Pg 7 of 7