CMP424 Cloud Computing and Virtualization

Cloud Computing and VirtualizationUnit 811 min read

Cloud Storage: Models, Services, and Technologies

Unit 8 of Cloud Computing and Virtualization explores cloud storage architectures, including object, block, and file storage models, storage-as-a-service (STaaS), data lifecycle management, and real-world implementations like AWS S3, Google Cloud Storage, and NEPSE’s data repositories. It covers encryption, redundancy,

TAKEAWAYS:

  • Cloud storage is categorized into object, block, and file storage, each optimized for different use cases (e.g., media files vs. databases).
  • Storage-as-a-Service (STaaS) models (public, private, hybrid) balance cost, scalability, and security.
  • Data redundancy (RAID, replication) and encryption (AES, TLS) ensure reliability and security in cloud storage.
  • Lifecycle management automates data tiering (hot/cold/archival) to reduce costs.
  • Real-world examples: NEPSE uses cloud storage for secure share trading data, while Daraz relies on object storage for product images.
  • Exam focus: Compare storage models, explain redundancy techniques, and analyze trade-offs in STaaS deployments.

1. Introduction to Cloud Storage

Cloud storage provides on-demand, scalable data storage over the internet, eliminating the need for physical hardware. It is a critical component of cloud computing, enabling businesses and individuals to store, manage, and retrieve data efficiently.

Key Characteristics of Cloud Storage

  • Scalability: Storage capacity can be increased or decreased dynamically.
  • Accessibility: Data is accessible from anywhere with an internet connection.
  • Durability: Redundancy ensures data is not lost due to hardware failures.
  • Cost-Effectiveness: Pay-as-you-go models reduce upfront infrastructure costs.
  • Security: Encryption, access controls, and compliance certifications (e.g., ISO 27001) protect data.

2. Types of Cloud Storage

Cloud storage is classified into three primary models, each suited for different workloads:

A. Object Storage

  • Stores unstructured data (e.g., images, videos, backups) as objects with metadata.
  • Uses a flat namespace (no hierarchical folders).
  • Examples: Amazon S3, Google Cloud Storage, Microsoft Azure Blob Storage.

How It Works:

  1. Data is divided into objects (e.g., a video file).
  2. Each object has a unique identifier (key) and metadata (e.g., file type, timestamp).
  3. Objects are stored in containers/buckets (logical groupings).

Worked Example: NEPSE Share Trading Data NEPSE stores trading records (CSV, JSON) in object storage for:

  • Immutability: Prevents tampering with historical data.
  • Scalability: Handles millions of daily transactions.
  • Disaster Recovery: Replicates data across multiple regions.
erDiagram
    BUCKET ||--o{ OBJECT : "contains"
    OBJECT {
        string key
        string metadata
        binary data
    }
    BUCKET {
        string name
        string access_policy
    }

B. Block Storage

  • Stores structured data (e.g., databases, virtual machine disks) as fixed-size blocks.
  • Used for high-performance applications (e.g., databases, VMs).
  • Examples: AWS EBS, Azure Disk Storage, Google Persistent Disk.

How It Works:

  1. Data is split into blocks (e.g., 4KB each).
  2. Blocks are assigned unique addresses and stored across multiple drives (RAID).
  3. Applications read/write blocks directly.

Worked Example: Daraz Order Processing Daraz uses block storage for:

  • Order databases (MySQL/PostgreSQL) requiring low-latency access.
  • Virtual machine disks hosting web servers.
  • RAID 10 for fault tolerance (mirroring + striping).

C. File Storage

  • Stores structured data in a hierarchical file system (e.g., /home/user/documents).
  • Used for shared access (e.g., team collaboration).
  • Examples: AWS EFS, Google Filestore, Azure Files.

How It Works:

  1. Data is organized in folders/subfolders.
  2. Supports NFS (Network File System) or SMB (Server Message Block) protocols.
  3. Access controls (permissions) are applied at the file/folder level.

Worked Example: Khalti Transaction Logs Khalti uses file storage for:

  • Audit logs (CSV/JSON files) shared across compliance teams.
  • NFS mounts for real-time access by fraud detection systems.

3. Storage-as-a-Service (STaaS) Models

Cloud storage is deployed in three primary models, each with trade-offs:

Model Description Pros Cons Example Use Case
Public Third-party provider (e.g., AWS, Google) Low cost, scalable, managed Less control, security risks Startups, personal backups
Private On-premises or dedicated cloud Full control, high security High cost, maintenance overhead Banks (NMB, Global IME), NEPSE
Hybrid Combines public + private storage Flexibility, cost optimization Complex management Healthcare (patient records)

Real-World Example: Ncell’s Hybrid Storage Ncell uses:

  • Public cloud (AWS S3): Stores customer call logs (cold data).
  • Private cloud: Hosts real-time billing databases (hot data).

4. Data Redundancy and Replication

To ensure durability, cloud storage uses:

  1. Replication: Copies data across multiple availability zones (AZs).
    • Example: AWS S3 replicates data to 3 AZs by default.
  2. RAID (Redundant Array of Independent Disks):
    • RAID 1 (Mirroring): Duplicates data across drives.
    • RAID 5 (Striping + Parity): Distributes data + error correction.
    • RAID 10 (Mirroring + Striping): High performance + fault tolerance.

Worked Example: Pathao Driver Data Pathao replicates driver location data 3x across regions to:

  • Ensure 99.99% uptime during traffic surges.
  • Recover quickly if a data center fails.

5. Data Encryption and Security

Cloud storage secures data using:

  1. At-Rest Encryption:
    • AES-256: Encrypts data stored on disks.
    • Example: Google Cloud Storage encrypts data by default.
  2. In-Transit Encryption:
    • TLS/SSL: Secures data during transfer (e.g., HTTPS).
  3. Access Controls:
    • IAM (Identity and Access Management): Role-based permissions (e.g., s3:PutObject).
    • Example: NEPSE restricts share price data access to approved brokers.

6. Data Lifecycle Management

Automates storage tiering to optimize costs:

  • Hot Storage: Frequently accessed data (e.g., active databases).
  • Cold Storage: Rarely accessed (e.g., archived logs).
  • Archive Storage: Long-term, low-cost (e.g., tax records).

Example: NTC’s Network Logs NTC uses lifecycle policies to:

  1. Move daily logs to cold storage after 30 days.
  2. Archive yearly logs to glacier-like storage (retrieval in hours).
stateDiagram-v2
    [*] --> Hot: "Active Usage"
    Hot --> Cold: "After 30 days"
    Cold --> Archive: "After 1 year"
    Archive --> [*]: "Permanent Retention"

7. Cloud Storage Providers Comparison

Provider Object Storage Block Storage File Storage Unique Feature
AWS S3 EBS EFS S3 Intelligent Tiering (auto-moves data)
Google Cloud Cloud Storage Persistent Disk Filestore Live Migration (zero downtime)
Microsoft Azure Blob Storage Disk Storage Azure Files Hierarchical Namespace (HNS)

Real-World Example: eSewa’s Multi-Cloud Strategy eSewa uses:

  • AWS S3: Stores transaction receipts (object storage).
  • Azure Disk Storage: Hosts payment gateway databases (block storage).

8. Challenges in Cloud Storage

Challenge Solution
Latency Use edge caching (e.g., Cloudflare).
Compliance Adopt GDPR/HIPAA-compliant providers.
Vendor Lock-in Use multi-cloud tools (e.g., Kubernetes).
Cost Overruns Set lifecycle policies and budget alerts.

In the Real World

  1. NEPSE (Nepal Stock Exchange)

    • Uses object storage (AWS S3) to store share trading records with immutable backups to prevent fraud.
    • How it works: Every trade is logged as an object with a timestamp and cryptographic hash, ensuring tamper-proof records.
  2. Daraz (Nepal’s E-Commerce Giant)

    • Relies on block storage (AWS EBS) for order databases and file storage (EFS) for product catalogs.
    • Why? Block storage ensures low-latency for checkout processes, while file storage allows shared access for inventory teams.
  3. Khalti (Digital Payment Platform)

    • Employs hybrid storage: Hot storage (private cloud) for real-time transactions and cold storage (AWS Glacier) for audit logs.
    • Security: Uses AES-256 encryption for all stored data and TLS 1.3 for transactions.

Exam Tip

  1. Compare Storage Models:

    • Object storage = unstructured data (e.g., videos).
    • Block storage = databases/VMs.
    • File storage = shared folders (e.g., team documents).
    • Exam Question: "Which storage type would you recommend for storing 10TB of customer call recordings for a telecom company like NTC?" Answer: Object storage (e.g., AWS S3) because it’s cost-effective for unstructured, rarely accessed data.
  2. Redundancy Techniques:

    • RAID 10 is preferred for high availability (used in banks).
    • Multi-AZ replication is used in public clouds (e.g., AWS S3).
    • Exam Question: "Explain how RAID 10 ensures fault tolerance." Answer: Combines mirroring (RAID 1) and striping (RAID 0) across multiple disks, so if one disk fails, data remains accessible from mirrored copies.
  3. STaaS Trade-offs:

    • Public cloud: Cheaper but less secure (suitable for startups).
    • Private cloud: More secure but expensive (used by NMB Bank).
    • Hybrid cloud: Best for sensitive + scalable needs (e.g., healthcare records).
  4. Lifecycle Management:

    • Hot → Cold → Archive is a common pattern.
    • Exam Question: "How would you reduce storage costs for a company like Pathao storing driver location logs?" Answer: Implement automated tiering—move logs to cold storage after 30 days and archive after 1 year.
  5. Security:

    • Always mention encryption (AES-256, TLS) and access controls (IAM).
    • Exam Question: "What security measures would you recommend for NEPSE’s cloud storage?" Answer:
      • At-rest encryption (AES-256).
      • In-transit encryption (TLS 1.3).
      • Immutable backups (WORM storage).
      • Role-based access (only brokers can access share data).

Final Note: Cloud storage is not just about capacity—it’s about security, compliance, and cost optimization. Always relate answers to real-world Nepalese examples (NEPSE, Khalti, NTC) to score full marks!

Based on the PU BE Computer (PU) syllabus for Cloud Computing and Virtualization (CMP424), unit 8.

Discussion

Loading…