Protect Your Data with HYOK Solutions by Baffle DPS
Publication date: May 28, 2021 (Diagram history)
This architecture shows how to use Baffle Data Protection Service (DPS) to implement Hold Your Own Key (HYOK) solutions. With Baffle DPS, you can add data-centric protection on AWS.
Protect Your Data with HYOK Solutions by Baffle DPS
-
End-of-day point-of-sale (POS) data downloads from wholesale and retail partner systems and saves on-premises.
-
The Baffle DPS data ingestion layer uses the on-premises encryption key with Format-Preserving Encryption (FPE). It tokenizes, anonymizes, and maps data flow before sending it to AWS.
-
A dedicated connection () or AWS Site-to-Site VPN secures the data while in transit.
-
Encrypted data arrives at AWS and stores without the encryption key, in either structured or unstructured format.
-
You can query encrypted data in AWS with various services, but the data remains encrypted.
-
The Baffle DPS data consumption layer uses the on-premises decryption key. It decrypts, de-tokenizes, and maps data flow back to clear-text form.
-
Clear-text data feeds business intelligence or downstream applications.
Further reading
For additional information, refer to
Diagram history
To be notified about updates to this reference architecture diagram, subscribe to the RSS feed.
| Change | Description | Date |
|---|---|---|
Initial publication | Reference architecture diagram first published. | May 28, 2021 |
Note
To subscribe to RSS updates, you must have an RSS plugin enabled for the browser you are using.