Application Data Protection Administration

The Application Data Protection tile in CipherTrust Manager Products list provides centralized configuration and policy management as well as a unified display for all the application configurations with their associated data protection connector on the CipherTrust Manager. Currently, the Application Data Protection tile provides central management only for CipherTrust Data Protection Gateway (DPG).

The Application Data Protection tile consists of:

  • Central management: a single place to configure data protection for applications and databases.

  • Single pane of glass: a dashboard that quickly shows the current status of all the applications or databases under protection. It also displays the status of each connector in use.

Central Management

Application Data Protection tile in CipherTrust Manager Products stores the configurations and policies for all the applications and databases under protection. These configurations and policies are created and managed by the Application Data Protection Administrator. They are shared with the associated clients when a new connector is registered or a running connector is notified of change through the heartbeat mechanism. To use centralized management, the connectors must be registered on CipherTrust Manager.

Let's consider a scenario where the user's environment has 10 instances of application protected by CipherTrust Data Protection Gateway (DPG). Now, the admin wants to update the symmetric cache expiry interval for all these nodes. In the past, the admin would have to manually change every configuration file, which is a tedious task, but with central management in picture, the symmetric cache expiry interval is updated in the configuration and, upon save, is updated in all running instances of the connector mapped to that configuration. Central management minimizes manual intervention.

The main objectives of central management are:

  1. Defining application or database to be protected

  2. Generating a registration token

  3. Registering connector on the CipherTrust Manager using the registration token

  4. Retrieving configurations and policies for the the connector the from CipherTrust Manager and using them for any cryptographic operations

  5. Updating configuration and policies as needed

How it works

The following diagram shows the basic flow of Application Data Protection solution:

  1. The Application Data Protection Administrator defines an application and how to protect data associated to that application.

  2. The Administrator receives a registration token when configuration is done.

  3. The Application Data Protection Administrator gives the registration token to the DevOps team to insert it into their orchestrator configuration for application deployment.

  4. The orchestrator deploys application with its associated connector (in this case, DPG). The connector uses the registration token to register with CipherTrust Manager.

  5. The connector fetches the configuration and policies associated to the application.

Single pane of glass

The Application Data Protection tile in CipherTrust Manager Products provides a unified view for all the applications that are defined on the CipherTrust Manager. With all the associated connectors (protecting applications) at one place, it becomes easy for the Application Data Protection Administrator to manage and keep track of them. To know more about this topic, refer to Single Pane of Glass.

User Roles

The Application Data Protection tile has the following users/groups with different responsibilities in administering and using the system.

Application Data Protection Admins

There is a group named Application Data Protection Admins. Users within this group are Application Data Protection Administrators.

The Application Data Protection Administrator is responsible for creating and managing the following resources:

  • Defining application which includes:

    • configuring connector settings

    • configuring protection policy

    • creating user sets

    • configuring access policies

    • creating character set

Application Data Protection clients

There is a group named Application Data Protection Connectors. Users who are part of this group only have read access to the Application Data Protection pages.

