Cloud Computing and VirtualizationUnit 811 min read
Cloud Storage: Models, Services, and Technologies
Unit 8 of Cloud Computing and Virtualization explores cloud storage architectures, including object, block, and file storage models, storage-as-a-service (STaaS), data lifecycle management, and real-world implementations like AWS S3, Google Cloud Storage, and NEPSE’s data repositories. It covers encryption, redundancy,
TAKEAWAYS:
- Cloud storage is categorized into object, block, and file storage, each optimized for different use cases (e.g., media files vs. databases).
- Storage-as-a-Service (STaaS) models (public, private, hybrid) balance cost, scalability, and security.
- Data redundancy (RAID, replication) and encryption (AES, TLS) ensure reliability and security in cloud storage.
- Lifecycle management automates data tiering (hot/cold/archival) to reduce costs.
- Real-world examples: NEPSE uses cloud storage for secure share trading data, while Daraz relies on object storage for product images.
- Exam focus: Compare storage models, explain redundancy techniques, and analyze trade-offs in STaaS deployments.
1. Introduction to Cloud Storage
Cloud storage provides on-demand, scalable data storage over the internet, eliminating the need for physical hardware. It is a critical component of cloud computing, enabling businesses and individuals to store, manage, and retrieve data efficiently.
Key Characteristics of Cloud Storage
- Scalability: Storage capacity can be increased or decreased dynamically.
- Accessibility: Data is accessible from anywhere with an internet connection.
- Durability: Redundancy ensures data is not lost due to hardware failures.
- Cost-Effectiveness: Pay-as-you-go models reduce upfront infrastructure costs.
- Security: Encryption, access controls, and compliance certifications (e.g., ISO 27001) protect data.
2. Types of Cloud Storage
Cloud storage is classified into three primary models, each suited for different workloads:
A. Object Storage
- Stores unstructured data (e.g., images, videos, backups) as objects with metadata.
- Uses a flat namespace (no hierarchical folders).
- Examples: Amazon S3, Google Cloud Storage, Microsoft Azure Blob Storage.
How It Works:
- Data is divided into objects (e.g., a video file).
- Each object has a unique identifier (key) and metadata (e.g., file type, timestamp).
- Objects are stored in containers/buckets (logical groupings).
Worked Example: NEPSE Share Trading Data NEPSE stores trading records (CSV, JSON) in object storage for:
- Immutability: Prevents tampering with historical data.
- Scalability: Handles millions of daily transactions.
- Disaster Recovery: Replicates data across multiple regions.
erDiagram
BUCKET ||--o{ OBJECT : "contains"
OBJECT {
string key
string metadata
binary data
}
BUCKET {
string name
string access_policy
}B. Block Storage
- Stores structured data (e.g., databases, virtual machine disks) as fixed-size blocks.
- Used for high-performance applications (e.g., databases, VMs).
- Examples: AWS EBS, Azure Disk Storage, Google Persistent Disk.
How It Works:
- Data is split into blocks (e.g., 4KB each).
- Blocks are assigned unique addresses and stored across multiple drives (RAID).
- Applications read/write blocks directly.
Worked Example: Daraz Order Processing Daraz uses block storage for:
- Order databases (MySQL/PostgreSQL) requiring low-latency access.
- Virtual machine disks hosting web servers.
- RAID 10 for fault tolerance (mirroring + striping).
C. File Storage
- Stores structured data in a hierarchical file system (e.g.,
/home/user/documents). - Used for shared access (e.g., team collaboration).
- Examples: AWS EFS, Google Filestore, Azure Files.
How It Works:
- Data is organized in folders/subfolders.
- Supports NFS (Network File System) or SMB (Server Message Block) protocols.
- Access controls (permissions) are applied at the file/folder level.
Worked Example: Khalti Transaction Logs Khalti uses file storage for:
- Audit logs (CSV/JSON files) shared across compliance teams.
- NFS mounts for real-time access by fraud detection systems.
3. Storage-as-a-Service (STaaS) Models
Cloud storage is deployed in three primary models, each with trade-offs:
| Model | Description | Pros | Cons | Example Use Case |
|---|---|---|---|---|
| Public | Third-party provider (e.g., AWS, Google) | Low cost, scalable, managed | Less control, security risks | Startups, personal backups |
| Private | On-premises or dedicated cloud | Full control, high security | High cost, maintenance overhead | Banks (NMB, Global IME), NEPSE |
| Hybrid | Combines public + private storage | Flexibility, cost optimization | Complex management | Healthcare (patient records) |
Real-World Example: Ncell’s Hybrid Storage Ncell uses:
- Public cloud (AWS S3): Stores customer call logs (cold data).
- Private cloud: Hosts real-time billing databases (hot data).
4. Data Redundancy and Replication
To ensure durability, cloud storage uses:
- Replication: Copies data across multiple availability zones (AZs).
- Example: AWS S3 replicates data to 3 AZs by default.
- RAID (Redundant Array of Independent Disks):
- RAID 1 (Mirroring): Duplicates data across drives.
- RAID 5 (Striping + Parity): Distributes data + error correction.
- RAID 10 (Mirroring + Striping): High performance + fault tolerance.
Worked Example: Pathao Driver Data Pathao replicates driver location data 3x across regions to:
- Ensure 99.99% uptime during traffic surges.
- Recover quickly if a data center fails.
5. Data Encryption and Security
Cloud storage secures data using:
- At-Rest Encryption:
- AES-256: Encrypts data stored on disks.
- Example: Google Cloud Storage encrypts data by default.
- In-Transit Encryption:
- TLS/SSL: Secures data during transfer (e.g., HTTPS).
- Access Controls:
- IAM (Identity and Access Management): Role-based permissions (e.g.,
s3:PutObject). - Example: NEPSE restricts share price data access to approved brokers.
- IAM (Identity and Access Management): Role-based permissions (e.g.,
6. Data Lifecycle Management
Automates storage tiering to optimize costs:
- Hot Storage: Frequently accessed data (e.g., active databases).
- Cold Storage: Rarely accessed (e.g., archived logs).
- Archive Storage: Long-term, low-cost (e.g., tax records).
Example: NTC’s Network Logs NTC uses lifecycle policies to:
- Move daily logs to cold storage after 30 days.
- Archive yearly logs to glacier-like storage (retrieval in hours).
stateDiagram-v2
[*] --> Hot: "Active Usage"
Hot --> Cold: "After 30 days"
Cold --> Archive: "After 1 year"
Archive --> [*]: "Permanent Retention"7. Cloud Storage Providers Comparison
| Provider | Object Storage | Block Storage | File Storage | Unique Feature |
|---|---|---|---|---|
| AWS | S3 | EBS | EFS | S3 Intelligent Tiering (auto-moves data) |
| Google Cloud | Cloud Storage | Persistent Disk | Filestore | Live Migration (zero downtime) |
| Microsoft Azure | Blob Storage | Disk Storage | Azure Files | Hierarchical Namespace (HNS) |
Real-World Example: eSewa’s Multi-Cloud Strategy eSewa uses:
- AWS S3: Stores transaction receipts (object storage).
- Azure Disk Storage: Hosts payment gateway databases (block storage).
8. Challenges in Cloud Storage
| Challenge | Solution |
|---|---|
| Latency | Use edge caching (e.g., Cloudflare). |
| Compliance | Adopt GDPR/HIPAA-compliant providers. |
| Vendor Lock-in | Use multi-cloud tools (e.g., Kubernetes). |
| Cost Overruns | Set lifecycle policies and budget alerts. |
In the Real World
NEPSE (Nepal Stock Exchange)
- Uses object storage (AWS S3) to store share trading records with immutable backups to prevent fraud.
- How it works: Every trade is logged as an object with a timestamp and cryptographic hash, ensuring tamper-proof records.
Daraz (Nepal’s E-Commerce Giant)
- Relies on block storage (AWS EBS) for order databases and file storage (EFS) for product catalogs.
- Why? Block storage ensures low-latency for checkout processes, while file storage allows shared access for inventory teams.
Khalti (Digital Payment Platform)
- Employs hybrid storage: Hot storage (private cloud) for real-time transactions and cold storage (AWS Glacier) for audit logs.
- Security: Uses AES-256 encryption for all stored data and TLS 1.3 for transactions.
Exam Tip
Compare Storage Models:
- Object storage = unstructured data (e.g., videos).
- Block storage = databases/VMs.
- File storage = shared folders (e.g., team documents).
- Exam Question: "Which storage type would you recommend for storing 10TB of customer call recordings for a telecom company like NTC?" Answer: Object storage (e.g., AWS S3) because it’s cost-effective for unstructured, rarely accessed data.
Redundancy Techniques:
- RAID 10 is preferred for high availability (used in banks).
- Multi-AZ replication is used in public clouds (e.g., AWS S3).
- Exam Question: "Explain how RAID 10 ensures fault tolerance." Answer: Combines mirroring (RAID 1) and striping (RAID 0) across multiple disks, so if one disk fails, data remains accessible from mirrored copies.
STaaS Trade-offs:
- Public cloud: Cheaper but less secure (suitable for startups).
- Private cloud: More secure but expensive (used by NMB Bank).
- Hybrid cloud: Best for sensitive + scalable needs (e.g., healthcare records).
Lifecycle Management:
- Hot → Cold → Archive is a common pattern.
- Exam Question: "How would you reduce storage costs for a company like Pathao storing driver location logs?" Answer: Implement automated tiering—move logs to cold storage after 30 days and archive after 1 year.
Security:
- Always mention encryption (AES-256, TLS) and access controls (IAM).
- Exam Question: "What security measures would you recommend for NEPSE’s cloud storage?"
Answer:
- At-rest encryption (AES-256).
- In-transit encryption (TLS 1.3).
- Immutable backups (WORM storage).
- Role-based access (only brokers can access share data).
Final Note: Cloud storage is not just about capacity—it’s about security, compliance, and cost optimization. Always relate answers to real-world Nepalese examples (NEPSE, Khalti, NTC) to score full marks!
Based on the PU BE Computer (PU) syllabus for Cloud Computing and Virtualization (CMP424), unit 8.
Discussion
Loading…