Austin
April 25-29, 2016

Event Details

Please note: All times listed below are in Central Time Zone


I’m Having an OpenStack Party, and It’s BYOK!

OpenStack has allowed businesses to improve their efficiency by offloading work into the cloud. Some of that work and data is sensitive, and it would be catastrophic to the business if leaked to competitors. This sensitivity lead OpenStack to implement several encryption features, but encryption begs the question of who is managing the encryption keys? This talk will examine key management and bring your own key (BYOK) in OpenStack. It will briefly describe a couple of encryption features to highlight which services use encryption keys, and then go into a discussion of key management. We will discuss the trust relationships between the different parties, the motivations for bring your own key, and the benefits and drawbacks of BYOK.


What can I expect to learn?

Attendees should expect to learn about some of the currently implemented encryption features in OpenStack as well as the current key management scheme. The attendees will learn about the consequences of this model, and we will examine some of the motivations for allowing BYOK key management. We will also cover how BYOK can work in OpenStack and what needs to change to make that happen.

Tuesday, April 26, 11:15am-11:55am (4:15pm - 4:55pm UTC)
Difficulty Level: Intermediate
JHU/APL
Nathan Reller is the supervisor for the Cloud Security section at Johns Hopkins University Applied Physics Laboratory (JHU/APL) and is a senior developer. Nathan is a member of the Barbican core team and has contributed to several critical security features including Cinder volume encryption, ephemeral disk encryption, and Glance image signing. Nathan also helps lead the OpenKMIP project... FULL PROFILE