Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Table of Contents
Problem Statement

Currently, EVE does not have capabilities of data security at rest. This is being designed and implemented. While EVE provides capabilities or building blocks, it is up to the EVE Controller to stitch them together to achieve a security goal. For this EVE needs to define its interface towards EVE controller, and provision a way to define security policies from the Controller.  This proposal defines such an interface.

...

Proposed change in the EVE Provisioning

...

Workflow

Current Workflow in Provisioning EVE

The current user driven, device management event flow at the high level, is as follows, 


...

New Stage in the Workflow - The Security Policy

...

Enforcement 

We propose a new stage/API in EVE Provisioning, where the controller can enforce the device policies on EVE, before EVE launches the pillar microservices. The reason we need this framework is because:

...