近年來雲端運算的發展已經是科技產業的一個趨勢,政府與企業亦規劃了許多開發計畫。雲端運算運用在企業資訊架構中,能夠大幅縮減硬體設備的採購成本與維護時間,並可將其重心放置於提升企業核心競爭力。然而當企業專注於雲端運算的佈署時,潛在的安全問題亦隨之浮現。不同的雲端服務皆有許多不同的安全性問題存在,而資料的安全性便是每一個雲端服務層會出現的議題。 對於一般的個人電腦來說,當使用者進行文件的刪除時,實際上並沒有真正的刪除該文件,而只是將檔案系統中的文件路徑刪除,該文件仍然存在於實體硬碟中,我們稱此為資料殘留(Data remanence)。將此資料殘餘的問題轉移至雲端運算當中,便可能產生雲端上資料的安全性問題。本計畫主要為探討雲端運算中資料儲存與刪除之安全,透過第三方信任中心 (TTP ,Trusted Third Party)設立之監控中心,對於雲端客戶運行於雲端服務提供商(CSP ,Cloud Service Provider)的整體資料生命週期來實施監控機制,並針對殘餘資料的部分進行資料消除(Data sanitization)。
In recent years, as cloud computing becomes popular, it has been attracted more and more attention by governments and enterprises. In the perspective of information technology, cloud computing not only gives a chance to divest infrastructure management of enterprises, but also enhances their core competencies. However, when enterprises focus on the development of cloud computing, the potential security issues emerge gradually. Cloud services will have a variety of security issues, and the subject of data security emerges in every type of service. The emerging cloud computing technology needs the assurance of data security, otherwise most of customers/organizations do not dare to adopt it. As well known, only after the security requirements of cloud computing could be managed and guaranteed, the prospects of the cloud services are brightening. Our research proposes an infrastructure to solve one of the security problems, i.e. data sanitization. Data sanitization is the method to solve the problem of data remanence. Most people do not know when they delete the file, the file still exists in hard disk. We call this problem is data remanence. It will enormously complicate the issue of data remanence in cloud. We propose a novel infrastructure in cloud computing environment which assures the data sanitization after the customers decide to delete them. The data that customer stores on the Cloud Service Provider (CSP) can be monitored by Trusted Third Party (TTP), and TTP implements the monitoring mechanism to control the data lifecycle. We focus on the problem of data remanence to simulate the mechanism of data sanitization in cloud, and we analyze the mechanism performance and security.