MySQL Secured by SG
The MySQL Secured by SG is a ready-to-deploy, CIS Benchmark compliant Shielded MySQL instance for Google Cloud Platform that is setting new standards when it comes data security. This self protecting MySQL server VM uses advanced security techniques such as Secure Boot, vTPM, UEFI firmware, integrity monitoring at the virtualization layer and transparent encryption, extended access controls, tamper-resistant logs at the data layer in order to protect MySQL data against unauthorized access.
Server General solutions are trusted by some of the leading organizations based in the United States, Europe, and Japan to protect their data and to meet stringent data security requirements imposed by
How Does it Work?
Select Instance TypeChange machine configuration
Install InstanceInstall your instance
Run ScriptLicense your instance Configure administrators Define a security policy Encrypt MySQL data Control access
Manage Your InstanceChange temporary passphrases
Start/Stop the security policy Rotate data encryption keys
LogsServer General administrative logs are stored locally and at three other servers
That’s ItYour MySQL is fully protected now.
The core components of MySQL Secured By SG are a data encryption engine, a key management engine, an access control engine, and a reporting engine. Each component performs a critical function in securing sensitive information and collectively they provide active countermeasures against various types of attack vectors.
A high-performance Data Encryption Engine is employed to provide strong encryption for all writes, and decryption for all reads. The application server data is encrypted at the file-system layer using the AES algorithm. This in- kernel data encryption is quick, transparent and you control the data encryption keys while we help you manage them.
Data encryption protects against theft of media, data images – even if intruders are able to obtain physical or electronic copies of data. The stolen data would be unusable without the decryption keys. Any probing of files would only yield blocks of ciphertext.
The Key Management Engine allows our customers to control their own encryption keys at all times. The encryption keys are stored in one or more key lockers deployed within the Server General global key management infrastructure. The encryption keys are themselves wrapped in another layer of encryption using a master key (a passphrase) that is only known to the data owner. This way only cipher blobs are stored in key lockers preventing other parties from deciphering them. The key management system allows customers to generate strong keys, rotate them on-demand, revoke any key at any time and store them in a secure location. Our security staff ensures their availability.
The Access Control Engine provides industrial strength identification and authentication mechanism that results in reduction of the ‘trust domain’. Only authorized Server General administrators are able to access administrative functions: this one measure reduces the risk posed by rogue systems administrators (or any other entity that has progressed beyond perimeter security). The access control engine allows only authorized users to access the protected data sets.
The Logging Engine logs every administrative operation related to Server General. The logs are stored at four different locations - on the host server and remotely within our cloud infrastructure. These logs provide crucial information during a security audit. In case of a regular server, an external or a malicious internal user may gain unauthorized access to the sensitive data – then perform acts to conceal the breach by removing or editing audit logs. However, this is not possible with Server General, as logs are stored outside the administrative domain of the compromised entity.