Data security

更新时间:
复制 MD 格式

The Financial Linker provides server-side and client-based encryption to mitigate security risks for data in the cloud.

Data encryption

Encryption of static data at rest

The ECS servers used for the linker have encryption at rest enabled by default. This prevents attackers from bypassing data access controls.

Encryption of data in transit

The linker supports Transport Layer Security (TLS) for data transmission. Communication between the client and the server is encrypted using TLS.

Server-side encryption

The linker uses Simple Log Service (SLS) for logging. Data is encrypted using the service keys provided by SLS. A unique, non-expiring encryption key is generated for each Logstore. This encryption supports the Advanced Encryption Standard (AES) algorithm by default and the SM4 encryption algorithm.

Database connection encryption

Secure Sockets Layer (SSL) encryption is supported for database connections.

Database or table encryption

User data is stored in PolarDB. By default, data storage is encrypted to ensure data security.

Data isolation

Multi-tenant data isolation

Data from different users is isolated to prevent unauthorized access or modification.

Data leakage prevention

Sensitive data detection

The service analyzes and detects sensitive data. It supports control policies for sensitive data, such as encrypted storage and masked display.

Alibaba Cloud Data Management Service (DMS) detects abnormal access to sensitive data to promptly identify and block the threat of sensitive data leakage.

Backup and disaster recovery

Multi-zone disaster recovery

To provide a more stable and reliable service, the linker service uses a cross-zone ACK cluster. This cluster supports node-level fault tolerance and enables link restoration within seconds.

If the primary zone experiences a data center failure or becomes unavailable, the service switches to a secondary zone to restore service. The interruption lasts for about 30 s.