The Financial Linker provides server-side and client-based encryption to mitigate security risks for data in the cloud.
Data encryption
Encryption of static data at rest
The ECS servers used for the linker have encryption at rest enabled by default. This prevents attackers from bypassing data access controls.
Encryption of data in transit
The linker supports Transport Layer Security (TLS) for data transmission. Communication between the client and the server is encrypted using TLS.
Server-side encryption
The linker uses Simple Log Service (SLS) for logging. Data is encrypted using the service keys provided by SLS. A unique, non-expiring encryption key is generated for each Logstore. This encryption supports the Advanced Encryption Standard (AES) algorithm by default and the SM4 encryption algorithm.
Database connection encryption
Secure Sockets Layer (SSL) encryption is supported for database connections.
Database or table encryption
User data is stored in PolarDB. By default, data storage is encrypted to ensure data security.
Data isolation
Multi-tenant data isolation
Data from different users is isolated to prevent unauthorized access or modification.
Data leakage prevention
Sensitive data detection
The service analyzes and detects sensitive data. It supports control policies for sensitive data, such as encrypted storage and masked display.
Alibaba Cloud Data Management Service (DMS) detects abnormal access to sensitive data to promptly identify and block the threat of sensitive data leakage.
Backup and disaster recovery
Multi-zone disaster recovery
To provide a more stable and reliable service, the linker service uses a cross-zone ACK cluster. This cluster supports node-level fault tolerance and enables link restoration within seconds.
If the primary zone experiences a data center failure or becomes unavailable, the service switches to a secondary zone to restore service. The interruption lasts for about 30 s.