SlideShare a Scribd company logo
Secure Multi-tenancy on Private Cloud Environment (Oracle SuperCluster)
How	to	Implement	
Comprehensive	
Security	in	a	Mul8tenant	
Cloud	Environment	
Glenn	Brune=e	
Director	-	Cybersecurity	
		
Ramesh	Nagappan	
Cybersecurity	Architect	
		
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|	 3	
Safe	Harbor	Statement	
The	following	is	intended	to	outline	our	general	product	direc8on.	It	is	intended	for	
informa8on	purposes	only,	and	may	not	be	incorporated	into	any	contract.	It	is	not	a	
commitment	to	deliver	any	material,	code,	or	func8onality,	and	should	not	be	relied	upon	
in	making	purchasing	decisions.	The	development,	release,	and	8ming	of	any	features	or	
func8onality	described	for	Oracle’s	products	remains	at	the	sole	discre8on	of	Oracle.
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|	 4	
Agenda	
1	
2	
3	
Oracle	SuperCluster	Cybersecurity	Building	Blocks	
Secure	Service	Architectures	on	Oracle	SuperCluster	
Secure	Mul8tenant	Clouds	on	Oracle	SuperCluster
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|	
Oracle	SuperCluster	Cybersecurity	
Building	Blocks	
5	
Crea8ve	Commons	Image	Courtesy:	Holger	Zscheye	@	Flickr
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|	 6	
§  ZS3	Mixed-use	Storage	
•  160	TB	(raw)	storage	for	Virtual	Machine	and	system	data	
§  QDR	InfiniBand	Unified	Ultra-fast	Network	
•  40GB/s	QDR	InfiniBand	IO	backplane	
§  M7	Servers	for	Databases	&	ApplicaHons	
•  1	or	2	M7	Chassis	per	system	(Elas8c	Configura8ons)	
•  2	Physical	Domains	per	M7	chassis,	1	-	4	processors	ea.	
•  Up	to	8TB	RAM	per	rack	
§  Exadata	Storage	Servers	for	Oracle	Database	
§  From	3	to	11	per	configura8on	(Flex.	Config.)	
§  High	Capacity	(96TB	raw	disk	ea.)	
§  Extreme	Flash	(12.8TB	raw	flash	ea.)	
SuperCluster	M7:	Hardware	Architecture	
SuperCluster	M7	
8/15/17
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|	 7	
Oracle SuperCluster Common Components
COMPUTE	
	
	
	
STORAGE	
	
	
	
NETWORK	
	
	
	
DATABASE
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|	 8	
Oracle SuperCluster Cybersecurity Focus Areas
Secure	
Isola8on	
Access	
Control	
Data	
Protec8on	
Monitoring	
and	Audi8ng	
COMPUTE	
	
	
	
STORAGE	
	
	
	
NETWORK	
	
	
	
DATABASE
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|	 9	
Secure Isolation For Any Requirement
SPARC M7
Database Domain #1
Physical Domain #1
OracleDatabase12c
Pluggable
Database
Pluggable
Database
Pluggable
Database
Pluggable
Database
Application DomainRoot Domain
Database IO Domain
Database Domain #2
Physical Domain #2
Application IO Domain
Oracle WebLogic
Server
Oracle WebLogic
Server
Oracle
Database 12c
Schema
Schema
Oracle
Fusion
Middleware
Solaris Zone #1
Oracle
Database 12c
Solaris Zone #2
Oracle
Database 12c
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|	 10	
Operating System
Operating System
Physical
Server
Zone A
Client
Access
Network
Client
A-1
Zone C
VLAN
C
Database C-1
Client
C-1 IPsec / TLS
Zone B
Database A-1
IPMPA-1
VLAN A-1-0
VLAN A-1-1
Database B-1
Adding
Cryptographic
Isolation
Layer 2
VNIC and VLAN
Isolation
IPMPB-1
VNIC B-1-0
VNIC B-1-1
net1
net0
Client
B-1
VLAN
A
Network
B
Secure Network Isolation – Ethernet
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|	 11	
Secure Network Isolation – InfiniBand
ASM Disk Groups
ASM Disk Group
A-1
ASM Disk Group
A-2
Oracle Exadata
Storage Servers
ZFS Data Sets
ZFS Data Set
C-1
ZFS Data Set
D-1
Sun ZFS Storage Appliance
InfiniBand
Network
Partition: 0xFFFF
Protocol: RDSv3
Partition: 0x8503
Protocol: NFS / IPoIB
Oracle VM Server for SPARC
Database Domain
Oracle Solaris 11 Zone
(Zone A)
Oracle Database
12c Release 1
Instance A-1
Oracle Database
12c Release 1
Instance A-2
Application Domain
Zone C
Oracle WebLogic
Server 12c
Instance C-1
Zone D
Oracle WebLogic
Server 12c
Instance D-1
Partition:
0x0503
Partition:
0x0503
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|	 12	
End to End Access Control
Compute	
Strong	
Authen8ca8on	
Role-based	
Access	Control	
Privileged	User	
Access	Control	
Storage	
ASM	Security	
NFS	Access	
Controls	
iSCSI	Access	
Controls	
Network	
Boundary	
Hardening	
Network	
Par88oning	
Packet	Filtering	
Database	
Strong	
Authen8ca8on	
Role-based	
Access	Control	
Privileged	User	
Access	Control
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|	 13	
End to End Data Protection
Database Domain
SPARC M7 Cryptography,
Application Data Integrity
Zone A
Oracle Database
A-1
Client
Access
Network
TLS
InfiniBand
Network
Partition
Intel AES-NI Hardware
Assisted Cryptography
Client
A-1
Oracle PKCS#11 Wallet
(Oracle Solaris PKCS#11 Softtoken)
SSL
Certificate
A-1
Oracle Solaris
Cryptographic Framework
ASM Disk Groups
Disk Group A-1
Oracle
Exadata
Storage
Servers
Encrypted
Tablespaces
ZFS Data Sets
Data Sets A-1
Encrypted
Backups
Export Files
Sun ZFS
Storage
Appliance
RDSv3
NFSv4
TDE
Master Key
A-1
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|	
Secure	Service	Architectures	on	
Oracle	SuperCluster	
14	
Crea8ve	Commons	Image	Courtesy:	Guillermo	@	Flickr
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|	 15	
Single Service Workload
Oracle	SuperCluster	Example	
Sample	Secure	ConfiguraHon	Steps	
•  Implement	Security	Hardening	
•  Apply	Security	Updates	
•  Enhance	Opera8ng	System	Security	
–  An8-Malware	Protec8ons	
–  Authen8ca8on	and	Access	Policies	
–  System	Security	Audi8ng	Policy	
–  Configura8on	Compliance	Scanning	
•  Enhance	Database	Security	
–  Enable	Encrypted	Communica8ons	
–  Configure	Transparent	Data	Encryp8on	
–  Configure	Database	Vault	
–  Database	Security	Audi8ng	Policy	
•  Enhance	Management	Security	
–  Change	Default	Passwords	
–  Replace	Self-Signed	Cer8ficates	
InfiniBand
Network
Oracle
Exadata
Storage
Servers
Oracle Solaris 11
Oracle Solaris 11
SPARC
M7
Server
SPARC
M7
Server
ASMASMClient
Access
Network
TLS
TLS
Oracle
Database 12c
Release 1
Oracle
Database 12c
Release 1
RAC
Cluster
Disk Group A
Disk Group B
Tablespace
Tablespace
Tablespace
Tablespace
Tablespace
Tablespace
ASM Cluster
RDSv3
RDSv3
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|	 16	
Single Service Tier Consolidation
Oracle	SuperCluster	Example	-	Database	
Sample	Secure	ConfiguraHon	Steps	
•  Implement	Single	Service	
Workload	Recommenda8ons	
•  Enhance	Opera8ng	System	Security	
–  Implement	Database-specific	Users/Roles	
–  Implement	POSIX	Isola8on	of	Instances	
–  Implement	Non-Global	Zones	(op8onal)	
–  Implement	Resource	Controls	
•  Enhance	Storage	Security	
–  Implement	Exadata	Storage	Security	
–  Implement	Resource	Controls	
InfiniBand
Network
Oracle
Exadata
Storage
Servers
Oracle Solaris 11
Oracle Solaris 11
SPARC
M7
Server
SPARC
M7
Server
ASMASMClient
Access
Network
TLS
TLS
Tablespace
Tablespace
Tablespace
Tablespace
Tablespace
ASM Cluster
Oracle Database
12c Release 1
Oracle Database
12c Release 1
TLS
Tablespace
Tablespace
RDSv3
RDSv3
RDSv3
DiskGroupDiskGroupDiskGroup
Oracle Database
12c Release 1
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|	 17	
Multiple Service Tier Consolidation
AddiHonal	Security	Controls	and	Technologies	
COMPUTE	
	
	
	
	
	
	
	
	
	
Hypervisor	Media8on	
	
Solaris	Non-Global	Zones	
	
Immutable	Global	and	
Non-Global	Zones	
		
Solaris	RBAC	and	Fine-
Grained	Privileges	
STORAGE	
	
	
	
	
	
	
	
	
	
Encrypted	ZFS	Data	Sets	
and	Volumes	
		
iSCSI	and	ASM	
Authen8ca8on	
		
iSCSI	,	NFS	and	ASM	
Access	Controls	
NETWORK	
	
	
	
	
	
	
	
	
	
Full	and	Limited	
Membership	
InfiniBand	Par88ons	
			
Solaris	IP	Filter	and	
IPsec/IKE
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|	 18	
Multiple Service Tier Consolidation
Oracle	SuperCluster	Example	#1	
Web
Tier
Network
IPoIB/SDP
InfiniBand
Network
Partition
Exadata
Tier
Network
RDSv3
InfiniBand
Network
Partition
Client
Access
Network
TLS
10GbE
Network
Database
Tier
Network
IPoIB/SDP
InfiniBand
Network
Partition
Oracle Traffic Director
Cluster
OTD Zone 1
Oracle Traffic
Director 11g
OTD Zone 2
Oracle Traffic
Director 11g
Oracle WebLogic
Server Cluster
WLS Zone 1
Oracle WebLogic
Server 12c
Oracle WebLogic
Server 12c
WLS Zone 2
Oracle WebLogic
Server 12c
Oracle WebLogic
Server 12c
Oracle Database
Cluster
DB Zone 1
Oracle Database 12c
Release 1
DB Zone 2
Oracle Database 12c
Release 1
Physical Server 1
Application Domain 1 Application Domain 2 Database Domain 1
Physical Server 2
Application Domain 1 Application Domain 2 Database Domain 1
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|	 19	
Multiple Service Tier Consolidation
Oracle	SuperCluster	Example	#2	
InfiniBand
Network
Partition
#1
SPARC M7 Hardware Assisted Cryptography and
Application Data Integrity
Client
Access
Network
Database Domain
Oracle Solaris
Cryptographic Framework
Zone C
Oracle Database
12c Release 1
Oracle PKCS#11 Wallet
(Oracle Solaris PKCS#11 Softtoken)
SSL
Certificate
TDE
Master Key
Intel AES-NI Hardware
Assisted Cryptography
ASM Disk Groups
Oracle
Exadata
Storage
ServersENCRYPTED
Tablespaces
ZFS Volumes/Data Sets
ENCRYPTED
Sun ZFS
Storage
Appliance
Binaries
Configurations
BackupsApplication Domain
Zone B
Oracle WebLogic
Server 12c
Oracle Solaris
Cryptographic Framework
Zone A
Oracle Traffic
Director 11g
TLS InfiniBand
Network
Partition
#2
RDSv3
InfiniBand
Network
Partition
#3
iSCSI,
NFS
TLS
TLS
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|	 20	
Secure	Mul8tenant	Clouds	on	
Oracle	SuperCluster	
Crea8ve	Commons	Image	Courtesy:	kassandrabay	@	Flickr
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|	 21	
Application DomainApplication Domain
SPARC M7 Server
Database DomainDatabase Domain
SPARC M7 Server
Client Access Network (10 GbE)
RAC
(DB1)
Oracle Database
12c Release 1
Immutable Zone 1
Oracle Database
12c Release 1
Immutable Zone 2
Exadata
Storage
Servers
ZFS
Storage
Appliance
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|	 22	
Application DomainApplication Domain
SPARC M7 Server
Database DomainDatabase Domain
SPARC M7 Server
Client Access Network (10 GbE)
RAC
(DB1)
Oracle Database
12c Release 1
Immutable Zone 1
Oracle Database
12c Release 1
Immutable Zone 2
Exadata
Storage
Servers
ZFS
Storage
Appliance
Tenant
Specific
VLANs
Tenant
Specific
VLANs
Tenant
Specific
VLANs
Tenant
Specific
VLANs
Tenant
Specific IB
Partitions
Tenant
Specific IB
Partitions
Tenant
Specific IB
Partitions
•  Physical and Logical Compute Isolation – Individual tenants and their
respective service tiers can be isolated using a combination of physical and logical
methods including physical domains, logical domains, I/O domains, and Solaris
zones.
•  Logical Network Isolation – Tenants are assigned dedicated logical network
interfaces to segment their traffic from others on the same physical platform as
well as traffic flowing between architectural service tiers. Methods to achieve
isolation include Ethernet VLANs and InfiniBand partitions.
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|	 23	
Application DomainApplication Domain
SPARC M7 Server
Database DomainDatabase Domain
SPARC M7 Server
Client Access Network (10 GbE)
Solaris Immutable
Non-Global Zones
Oracle Database
12c Release 1
Immutable Zone 1
Oracle Database
12c Release 1
Immutable Zone 2
Exadata
Storage
Servers
ZFS
Storage
Appliance
•  Tamperproof Execution Environment – Defends against accidental and
malicious tampering of sensitive operating system and tenant-specific
binaries, configuration files, etc.
•  Role-based Access Control – Tenant administrators are assigned restricted
rights profiles that strictly limit access to security sensitive functions.
Solaris Immutable Global Zone Solaris Immutable Global Zone
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|	 24	
Application DomainApplication Domain
SPARC M7 Server
Database DomainDatabase Domain
SPARC M7 Server
Oracle Database
12c Release 1
Immutable Zone 1
Oracle Database
12c Release 1
Immutable Zone 2
Exadata
Storage
Servers
ZFS
Storage
Appliance
•  Comprehensive Packet Filtering – Network access to tenant
environments is strictly controlled using a default deny firewall
policy managed by the service provider.
•  Complete End to End Network Encryption – Data in transit is
always protected using a combination of Secure Shell, HTTPS
(SSL/TLS) and IPsec. IPsec is used to protect all internal traffic
flowing between non-global zones.
IPsec
IP Filter
IPsec
IP Filter
IPsec
Secure Shell (SSH) HTTPS
IP Filter IP FilterIP FilterIP Filter
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|	 25	
Application DomainApplication Domain
SPARC M7 Server
Database DomainDatabase Domain
SPARC M7 Server
Client Access Network (10 GbE)
Exadata
Storage
Servers
ZFS
Storage
Appliance
•  Restricted Tenant Access to Storage – Administrative access
to Exadata Storage Servers and the ZFS Storage Appliance is
prohibited from within tenant non-global zones.
•  Security Hardened Storage Appliances – Exadata Storage
Servers and the ZFS Storage Appliance leverage a security
hardened configuration to reduce the attack surface and
prohibit unauthorized access.
Solaris Immutable
Non-Global Zones
Oracle Database
12c Release 1
Immutable Zone 1
Oracle Database
12c Release 1
Immutable Zone 2
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|	 26	
Application DomainApplication Domain
SPARC M7 Server
Database DomainDatabase Domain
SPARC M7 Server
Client Access Network (10 GbE)
Solaris Immutable
Non-Global Zones11g
R2
database
Immutable Zone 1
oracle
11g
R2
database
Immutable Zone 2
oracle
Exadata
Storage
Servers
ZFS
Storage
Appliance
•  Comprehensive Data Protection – Data at rest protection, enabled
by Oracle Transparent Data Encryption, secures access to tenant
data, using unique, tenant-managed keys.
•  Restricted Access to Exadata Storage – Mutual authentication is
used to assign database storage resources to specific tenant
environments, clusters, or individual databases.
Encrypted
Tablespaces
Encrypted
Tablespaces
Encrypted
Tablespaces
Transparent Data Encryption and ASM Database Scoped Security
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|	 27	
Application DomainApplication Domain
SPARC T5-8 Server
Database DomainDatabase Domain
SPARC M7 Server
Client Access Network (10 GbE)
Solaris Immutable
Non-Global Zones
Oracle Database
12c Release 1
Immutable Zone 1
Oracle Database
12c Release 1
Immutable Zone 2
Exadata
Storage
Servers
ZFS
Storage
Appliance
Encrypted
Tablespaces
Encrypted
Tablespaces
Encrypted
Tablespaces
Transparent Data Encryption and ASM Database Scoped Security
ZFS Pool (Zone 1)
rpool /u01 /common
ZFS Pool (Zone 2)
rpool /u01 /common
•  Comprehensive Data Protection – Solaris non-global zones, installed
applications and files are protected at rest using hardware-accelerated
ZFS encryption with tenant-specific keys.
•  Restricted Access to ZFS Storage – Storage resources are logically
isolated, leverage mutual authentication and are assigned directly to
tenant non-global zones.
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|	 28	
SPARC T5-8 ServerSPARC T5-8 Server
Application DomainApplication Domain Database DomainDatabase Domain
Client Access Network (10 GbE)
Exadata
Storage
Servers
ZFS
Storage
Appliance
11g
R2
database
Immutable Zone 2
oracle
Fusion
MIDDLEWARE
Immutable Zone 4b
oracle
Fusion
MIDDLEWARE
Immutable Zone 4a
oracle
rpool
/u01 /common
ZFS Pool (Zone 1a)
rpool
/u01 /common
ZFS Pool (Zone 1b)
rpool
/u01 /common
ZFS Pool (Zone 3)
rpool
/u01 /common
ZFS Pool (Zone 4b)
rpool
/u01 /common
ZFS Pool (Zone 4a)
rpool
/u01 /common
ZFS Pool (Zone 2)
RAC
(DB1) 11g
R2
database
Immutable Zone 1b
oracle
11g
R2
database
Immutable Zone 1a
oracle
11g
R2
database
Immutable Zone 3
oracle
(Zone 2)
DB4
(Zone 1)
DB1
(Zone 1)
DB2
(Zone 1)
DB3
(Zone 3)
DB4
(Zone 3)
DB5
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|	 29	
Application DomainApplication Domain
SPARC T5-8 Server
Database DomainDatabase Domain
SPARC M7 Server
Client Access Network (10 GbE)
Solaris Immutable
Non-Global Zones
Oracle Database
12c Release 1
Immutable Zone 1
Oracle Database
12c Release 1
Immutable Zone 2
Exadata
Storage
Servers
ZFS
Storage
Appliance
Encrypted
Tablespaces
Encrypted
Tablespaces
Encrypted
Tablespaces
Transparent Data Encryption and ASM Database Scoped Security
ZFS Pool (Zone 1)
rpool /u01 /common
ZFS Pool (Zone 2)
rpool /u01 /common
•  Centralized Auditing – Tenant-specific non-global zones are uniformly
audited using a centralized policy defined and managed by the service
provider. All audit trail data is stored in the Solaris global zone in an
encrypted ZFS dataset and is not accessible by individual tenants.
•  Role-based Access Control – Access to provider or tenant-specific
audit trail data is controlled using a highly restricted Solaris role.
/audit_pool
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|	 30	
SPARC M7 ServerSPARC M7 Server
Application DomainApplication Domain Database DomainDatabase Domain
Client Access Network (10 GbE)
Exadata
Storage
Servers
ZFS
Storage
Appliance
Oracle Database
12c Release 1
Immutable Zone 2
Oracle Fusion
Middleware
Immutable Zone 4b
Oracle Fusion
Middleware
Immutable Zone 4a
rpool
/u01 /common
ZFS Pool (Zone 1a)
rpool
/u01 /common
ZFS Pool (Zone 1b)
rpool
/u01 /common
ZFS Pool (Zone 3)
rpool
/u01 /common
ZFS Pool (Zone 4b)
rpool
/u01 /common
ZFS Pool (Zone 4a)
rpool
/u01 /common
ZFS Pool (Zone 2)
RAC
(DB1)
Oracle Database
12c Release 1
Immutable Zone 3
(Zone 2)
DB4
(Zone 1)
DB1
(Zone 1)
DB2
(Zone 1)
DB3
(Zone 3)
DB4
(Zone 3)
DB5
Oracle Database
12c Release 1
Immutable Zone 1a
Oracle Database
12c Release 1
Immutable Zone 1b
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|	 31	
Multiple Tenant Consolidation
Oracle	SuperCluster	Example	–	Tenant	Viewpoint	
Sample	Secure	ConfiguraHon	Steps	
•  Implement	Mul8ple	Service	
Workload	Recommenda8ons	
•  Enhance	Opera8ng	System	Security	
–  Restrict	Tenant	Access	to	Solaris	Zones	
–  Implement	Tenant	Administrator	Role	
–  Implement	Immutable	Non-Global	Zone	
–  Implement	Immutable	Global	Zone	
–  Implement	Immutable	Firewall	Policy	
–  Implement	Immutable	Audi8ng	Policy	
•  Enhance	Network	Security	
–  Implement	IPsec/IKE	for	RAC	Interconnect	
with	Tenant	Specific	Keys	
–  Implement	IP	Filter	on	Applica8on	Zones	
–  Restrict	Tenant	Access	to	SuperCluster	
Management	Network	and	Services	
Client
Access
Network
Oracle Database Cluster (RAC)
Tenant Specific
Immutable Zone
Oracle Database
Tenant Specific
Immutable Zone
Oracle Database
RDSv3
IPoIB
SDP
IPoIB
SDP
TLS
SSH
Oracle WebLogic Cluster
Tenant Specific
Immutable Zone
Oracle WebLogic
Tenant Specific
Immutable Zone
Oracle WebLogic
Tenant
Specific
VLANs
Tenant
Specific
InfiniBand
Network
Partition
Tenant-Specific
Internal
Communications
Oracle Exadata Storage Servers
RDSv3
Oracle Exadata Storage and RAC
Specific Communications
Tenant Specific Disk Group(s)
Exadata Storage Partition
InfiniBand Network
ZFS Volumes/Data Sets
Oracle
Sun ZFS
Storage
Appliance
Binaries
Configurations
Backups
Logs
Tenant-Specific NAS Storage
NFS
iSCSI
Immutable Global Zone
Immutable Global Zone
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|	 32	
Multiple Tenant Consolidation
Oracle	SuperCluster	Example	–	Provider	Viewpoint	
Client
Access
Network
Application Domain
Database Domain
SPARC
M7
Server
Tenant A Zone 2
Oracle Database
Tenant B Zone 2
Oracle Database
Tenant B Zone 1
Application
Tenant A Zone 1
Application
VLAN B
Tenant
B
HTTPS
VLAN A
HTTPS
Tenant
A
RDSv3
Tenant B Network
Partition
Tenant A
Network
Partition
NFSv4
iSCSI
Application B
Storage
Application A
Storage
Database A
Storage
Database B
Storage
Sun ZFS
Storage
Appliance
InfiniBand
Network
Tenant A
Disk Groups
Tenant B
Disk Groups
Exadata
Storage
Servers
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|	 33	
Multiple Tenant Centralized Key Management
Oracle	SuperCluster	and	Oracle	Key	Manager		Example	–	Provider	Viewpoint
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|	 34	
Achieving	PCI-DSS	Compliance*	
Secure	isola8on	of	SuperCluster	Domains/Zones	
Apply	Solaris	IPfilter	Firewall	for	network	traffic	control	
Enable	SuperCluster	Secure-By-Default	&	Password	policies	
Protect	network	flow	with	segmenta8on	and	enable	IPSec/IKE	
	Enforce	stronger	isola8on	for	Domains/Zones,	ASM	scoping	
Encrypt	ZFS	data	sets	and	use	database	encryp8on	(TDE)	
Use	TLSv1.2,	SSH,	IPSec/IKE	for	encrypted	communica8on		
Use	Immutable	Solaris	Zones,	enable	ASLR	and	Non-exec	stack	
Use	Solaris	Vscan	services	for	An8-virus/malware	scans	
Use	Oracle	SuperCluster	QFSDP	and	automated	CVE	updates	
Enable	Strong	authen8ca8on	using	PAM	and	password	polices	
Enforce	Role	based	access	control	and	Rights/Privilege	profile	
Enforce	preven8ve	physical	access	controls	
	
Enable	logging	and	audit	policies	for	all	opera8ons	
Enable	File	integrity	checks	and	monitoring	(BART)	
		
Establish	a	Process,	Policy,	Procedure	control	
as	per	PCI-DSS	requirements	
Enable	stronger	encryp8on	with	Solaris	FIPS	mode		
Enable	verified	boot	at	ILOM	
Use	Key	management	with	Oracle	Key	Manager	
*	Refer	:	“Oracle	SuperCluster	and	PCI	Compliance		–	Coalfire,	September	2014”
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|	 35	
SuperCluster	Compliance	
Security	ConfiguraHon	Compliance	and	RemediaHon	-		PCI-DSS,	STIG,	and	more...
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|	 36	
Oracle SuperCluster Security Capability Summary
Compute Storage Network Database
Secure
Isolation
!  Physical
!  Electrical
!  Hypervisor-Mediated
!  Kernel-Mediated
!  Physical
!  ASM Instances
!  ZFS Data Sets
!  Physical (Ethernet)
!  Ethernet VLANs
!  InfiniBand Partitions
!  Multitenant
!  Instances
!  Schema
!  Labels
Access
Control
!  RBAC / Privileges
!  LDOM Administration
!  Zone Administration
!  ZFS ACLs
!  Exadata Security
!  NFS Security
!  IP Filter / iptables
!  Switch ACLs
!  Audit Vault and
Database Firewall
!  Roles and Privileges
!  Real Application
Security
!  Database Vault
Data
Protection
!  Immutable Zones
!  Read-Only Mounts
!  ZFS Administration
!  ZFS Encryption
!  LOFI Encryption
!  TDE
!  SSH
!  SSL / TLS
!  IPsec / IKE
!  Virtual Private DB
!  Data Masking
!  Redaction
Monitoring
and Auditing
!  Solaris Auditing
!  Linux Auditing
!  BART / AIDE
!  ZFS Storage
Appliance Logs
!  Exadata Storage
Auditing
!  IP Filter / iptables
!  Switch Logs
!  Database Auditing
!  Audit Vault and
Database Firewall
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|	 37	
Oracle SuperCluster Security Summary
Complete Tested
! !
! !
Integrated
Trusted
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|	 38
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|	 39	
Further Information
•  Oracle	SuperCluster	Home	Page	
h=ps://www.oracle.com/engineered-systems/supercluster/index.html	
•  Oracle	SuperCluster	Security	White	Papers	
– Oracle	SuperCluster	T5-8	Plamorm	Security	Principles	and	Capabili8es	
h=p://www.oracle.com/technetwork/server-storage/sun-sparc-enterprise/documenta8on/
o13-052-osc-t5-8-security-1989641.pdf	
– Secure	Database	Consolida8on	Using	the	Oracle	SuperCluster	T5-8	Plamorm	
h=p://www.oracle.com/technetwork/server-storage/sun-sparc-enterprise/documenta8on/
o13-053-securedb-osc-t5-8-1990064.pdf	
– Oracle	SuperCluster	T5-8	Security	Technical	Implementa8on	Guide	(STIG)	
Valida8on	and	Best	Prac8ces	on	Database	Servers	
h=p://www.oracle.com/technetwork/server-storage/hardware-solu8ons/s8g-sparc-
supercluster-1841833.pdf
Secure Multi-tenancy on Private Cloud Environment (Oracle SuperCluster)
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|	 41	
Multiple Tenant Consolidation
Oracle	SuperCluster	Example	–	Tenant	Viewpoint	(Alternate)	
SSL
SSL
Client
Access
Network
Oracle Database Cluster (RAC)
Tenant Specific
Immutable Zone
Oracle Database
Tenant Specific
Immutable Zone
Oracle Database
RDSv3
IPoIB
IPoIB
SSL
SSH
Oracle WebLogic Cluster
Tenant Specific
Immutable Zone
Oracle WebLogic
Tenant Specific
Immutable Zone
Oracle WebLogicTenant
Specific
VLANs
External Tenant
Specific
InfiniBand
Network
Partition
Storage
and RAC
Use Only
Tenant-Specific
Internal
Communications
Oracle Exadata Storage Servers
RDSv3
Oracle Exadata Storage and RAC
Specific Communications
Tenant Specific Disk Group(s)
Exadata Storage Partition
InfiniBand Network
ZFS Volumes/Data Sets
Oracle
Sun ZFS
Storage
Appliance
Binaries
Configurations
Backups
Logs
Tenant-Specific NAS Storage
iSCSITenant
Specific
VLAN
Multi-Tier
Traffic
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|	 42	42	
Zone	Isola8on	
Domain	Isola8on	
System	Isola8on	
RDS	v3	
RDS	v3	
iSCSI	
NFS	v4	
Infiniband	Network	40GbE		
[Full/Limited	Membership]	
10GbE	Network	
[Client	Access]	
Electrical	Isola8on	
TLSv1.2	
App	Domain	DB	
Domain	
TLSv1.2	
Oracle	ZFS	Storage	
Encrypted	ZFS	Data	Sets	
bin,	configs,	backups,	logs	
Oracle	Exadata	Storage	Cells	
ASM	Scoped	Security	Disk	Group(s)	
Transparent	Data	Encryp8on	
Layered	Security	
Read-Only	Immutable	Zones	
Dedicated	IB	Par88on	
Fine	Grained	RBAC	
IP	Filter	Firewalls	
IPSec/IKE	Channels	
Centralized	Audit	
Oracle	Key		
Manager	
Secure	Connec8on	
VLAN-A	
VLAN-B	
Secure	Connec8on	Tenant-A	
Tenant-B	
Secure Multitenancy
Cloud	Provider	Viewpoint
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|	 43	
Oracle	Key	Manager	–	Key	Management	Appliance	
•  Oracle	Key	Manager	Appliance	for	SuperCluster	
–  Simple	automa8c	installa8on	and	integrates	with	SuperCluster	
Management	Network		
–  No	OS/driver	administra8on	or	maintenance	is	required	
–  Dedicated	key	management	and	key	transport	(service)	networks	
–  Conforms	to	stringent	federal	security	cer8fica8ons	(FIPS	140-2	level	3)	
–  Secure	Key	Management	via	RBAC	with	Segrega8on	for	du8es	
–  SuperCluster	Tenant	Key	Management	using	Key	Groups	and	Key	
Group	Policies	
•  Supports	all	SuperCluster	hosted	Encryp8on	End-points	via	
Solaris	PKCS#11	KMS	
–  ZFS	Encryp8on,	Oracle	Transparent	Data	Encryp8on	
–  Java,	Fusion	Middleware	and	Fusion	Applica8ons		(Via	PKCS#11)	
	
OKM	3
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|	 44	
Safe	Harbor	Statement	
The	preceding	is	intended	to	outline	our	general	product	direc8on.	It	is	intended	for	
informa8on	purposes	only,	and	may	not	be	incorporated	into	any	contract.	It	is	not	a	
commitment	to	deliver	any	material,	code,	or	func8onality,	and	should	not	be	relied	upon	
in	making	purchasing	decisions.	The	development,	release,	and	8ming	of	any	features	or	
func8onality	described	for	Oracle’s	products	remains	at	the	sole	discre8on	of	Oracle.
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|	 45

More Related Content

PDF
Secure Multitenancy on Oracle SuperCluster
PDF
Management Cloud Oracle
PDF
TLV - Whats new in MySQL 8
PPTX
Oracle Cloud Hybrid Storage Tiering
PDF
Oow MySQL Whats new in security overview sept 2017 v1
PDF
Percona Live - Dublin 01 my sql ha-mysql-clusters
PPTX
RethinkDB on Oracle Linux
PDF
Rapid private cloud with oracle vm and oracle openstack for oracle linux
Secure Multitenancy on Oracle SuperCluster
Management Cloud Oracle
TLV - Whats new in MySQL 8
Oracle Cloud Hybrid Storage Tiering
Oow MySQL Whats new in security overview sept 2017 v1
Percona Live - Dublin 01 my sql ha-mysql-clusters
RethinkDB on Oracle Linux
Rapid private cloud with oracle vm and oracle openstack for oracle linux

What's hot (20)

PDF
MySQL Manchester TT - MySQL Enterprise Edition
PPTX
Oracle cloud, private, public and hybrid
PPT
MySQL Tech Tour 2015 - 5.7 Connector/J/Net
PPTX
Oracle IaaS/PaaS - Experience Technology Night
PDF
MySQL Manchester TT - Replication Features
PDF
MySQL Tech Tour 2015 - Alt Intro
PDF
APIC EM APIs: a deep dive
PDF
Intermedia Customer Presentation
PDF
Cisco Connect Halifax 2018 Cisco dna - deeper dive
PDF
Cisco Connect Halifax 2018 Application agility and programmability with cis...
PDF
Cisco Connect Toronto 2018 an introduction to Cisco kinetic
PDF
Cisco Connect Toronto 2018 an introduction to Cisco kinetic
PDF
ChaoSlingr: Introducing Security-Based Chaos Testing
PDF
Cisco Connect Ottawa 2018 data centre security
PDF
MySQL Intro JSON NoSQL
PDF
Cisco Connect Vancouver 2017 - Embedding IR into the DNA of the business
PDF
Cisco Connect Halifax 2018 Application insight and zero trust policies with...
PDF
Cisco connect montreal 2018 saalvare md-program-xr-v2
PDF
PDF
Identity-Based Security and Privacy for the Internet of Things
MySQL Manchester TT - MySQL Enterprise Edition
Oracle cloud, private, public and hybrid
MySQL Tech Tour 2015 - 5.7 Connector/J/Net
Oracle IaaS/PaaS - Experience Technology Night
MySQL Manchester TT - Replication Features
MySQL Tech Tour 2015 - Alt Intro
APIC EM APIs: a deep dive
Intermedia Customer Presentation
Cisco Connect Halifax 2018 Cisco dna - deeper dive
Cisco Connect Halifax 2018 Application agility and programmability with cis...
Cisco Connect Toronto 2018 an introduction to Cisco kinetic
Cisco Connect Toronto 2018 an introduction to Cisco kinetic
ChaoSlingr: Introducing Security-Based Chaos Testing
Cisco Connect Ottawa 2018 data centre security
MySQL Intro JSON NoSQL
Cisco Connect Vancouver 2017 - Embedding IR into the DNA of the business
Cisco Connect Halifax 2018 Application insight and zero trust policies with...
Cisco connect montreal 2018 saalvare md-program-xr-v2
Identity-Based Security and Privacy for the Internet of Things
Ad

Similar to Secure Multi-tenancy on Private Cloud Environment (Oracle SuperCluster) (20)

PDF
High Performance Security and Virtualization for Oracle Database and Cloud-En...
PDF
Lucw lsec-securit-20110907-4-final-5
PDF
Maa wp sun_apps11i_db10g_r2-2
PDF
Maa wp sun_apps11i_db10g_r2-2
PPTX
Best Practices for running the Oracle Database on EC2 webinar
PDF
Oracle Cloud
PDF
Oracle E-Business Suite On Oracle Cloud
PDF
Oracle Database 12c Multitenant for Consolidation
PDF
Latest Innovations in Database as a Service Enabled by Oracle Enterprise Manager
PPTX
OCI Overview
PDF
Cloud Consolidation with Oracle (RAC) - How much is too much?
PDF
Oracle super cluster for oracle e business suite
PDF
Představení Oracle SPARC Miniclusteru
PDF
Oracle database in cloud, dr in cloud and overview of oracle database 18c
PPTX
Simplify IT: Oracle SuperCluster
PPTX
BGOUG17: Cloudy with a chance of MySQL
PPTX
Database as a Service, Collaborate 2016
PDF
Oracle Cloud Infrastructure
PPTX
Oracle Security Overview from Cloud World 2022
PDF
Oracle RAC 12c Overview
High Performance Security and Virtualization for Oracle Database and Cloud-En...
Lucw lsec-securit-20110907-4-final-5
Maa wp sun_apps11i_db10g_r2-2
Maa wp sun_apps11i_db10g_r2-2
Best Practices for running the Oracle Database on EC2 webinar
Oracle Cloud
Oracle E-Business Suite On Oracle Cloud
Oracle Database 12c Multitenant for Consolidation
Latest Innovations in Database as a Service Enabled by Oracle Enterprise Manager
OCI Overview
Cloud Consolidation with Oracle (RAC) - How much is too much?
Oracle super cluster for oracle e business suite
Představení Oracle SPARC Miniclusteru
Oracle database in cloud, dr in cloud and overview of oracle database 18c
Simplify IT: Oracle SuperCluster
BGOUG17: Cloudy with a chance of MySQL
Database as a Service, Collaborate 2016
Oracle Cloud Infrastructure
Oracle Security Overview from Cloud World 2022
Oracle RAC 12c Overview
Ad

More from Ramesh Nagappan (13)

PDF
Post Quantum Cryptography: Technical Overview
PDF
Biometric Authentication for J2EE applications - JavaONE 2005
PDF
Interoperable Provisioning in a distributed world
PDF
High Performance Security With SPARC T4 Hardware Assisted Cryptography
PDF
Analysis of Security and Compliance using Oracle SPARC T-Series Servers: Emph...
PDF
ICAM - Demo Architecture review
PDF
Government Citizen ID using Java Card Platform
PDF
PIV Card based Identity Assurance in Sun Ray and IDM environment
PDF
Java Platform Security Architecture
PDF
Managing PIV Card Lifecycle and Converging Physical & Logical Access Control
PDF
Stronger Authentication with Biometric SSO
PDF
Stronger/Multi-factor Authentication for Enterprise Applications
PDF
Wire-speed Cryptographic Acceleration for SOA and Java EE Security
Post Quantum Cryptography: Technical Overview
Biometric Authentication for J2EE applications - JavaONE 2005
Interoperable Provisioning in a distributed world
High Performance Security With SPARC T4 Hardware Assisted Cryptography
Analysis of Security and Compliance using Oracle SPARC T-Series Servers: Emph...
ICAM - Demo Architecture review
Government Citizen ID using Java Card Platform
PIV Card based Identity Assurance in Sun Ray and IDM environment
Java Platform Security Architecture
Managing PIV Card Lifecycle and Converging Physical & Logical Access Control
Stronger Authentication with Biometric SSO
Stronger/Multi-factor Authentication for Enterprise Applications
Wire-speed Cryptographic Acceleration for SOA and Java EE Security

Recently uploaded (20)

PDF
Machine learning based COVID-19 study performance prediction
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PDF
Spectral efficient network and resource selection model in 5G networks
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PPTX
MYSQL Presentation for SQL database connectivity
PPTX
Big Data Technologies - Introduction.pptx
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PPTX
Cloud computing and distributed systems.
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
DOCX
The AUB Centre for AI in Media Proposal.docx
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PDF
cuic standard and advanced reporting.pdf
PDF
NewMind AI Monthly Chronicles - July 2025
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PPTX
A Presentation on Artificial Intelligence
Machine learning based COVID-19 study performance prediction
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
Advanced methodologies resolving dimensionality complications for autism neur...
Spectral efficient network and resource selection model in 5G networks
The Rise and Fall of 3GPP – Time for a Sabbatical?
MYSQL Presentation for SQL database connectivity
Big Data Technologies - Introduction.pptx
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Unlocking AI with Model Context Protocol (MCP)
Network Security Unit 5.pdf for BCA BBA.
Chapter 3 Spatial Domain Image Processing.pdf
Diabetes mellitus diagnosis method based random forest with bat algorithm
Cloud computing and distributed systems.
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
The AUB Centre for AI in Media Proposal.docx
Agricultural_Statistics_at_a_Glance_2022_0.pdf
cuic standard and advanced reporting.pdf
NewMind AI Monthly Chronicles - July 2025
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
A Presentation on Artificial Intelligence

Secure Multi-tenancy on Private Cloud Environment (Oracle SuperCluster)