Title: Towards mitigating data security risks in JD cloud environments
Date: 2018-05-25 14:20-15:30
Location: R103, CSIE
Speaker: Dr. Yueh-Hsun Lin JD Silicon Valley R&D Center
Hosted by: Prof. Hsu-Chun Hsiao


Data breaches happen daily, in too many places at once to keep count. In recent years, data security against breaches and leaks becomes one of the top priorities security task for high tech companies. Proprietary data such as customer accounts, transaction records, or even credentials stored in data centers or personal computers could be leaked through numerous of attacks, making data security more challenging. On the other hand, data lifecycle becomes so complicated and difficult to maintain its security especially in a large Internet company like JD. A trade-off between data usability and security remains a hard issue to be solved. Therefore, we present Transparent Data Encryption (TDE) service framework, offering encryption as a service (EaaS) for different applications running on JD internal clouds. TDE guarantees sensitive data could be accessed only by authenticated and authorized applications. Combing with data flow analysis and additional monitor mechanism built-in for TDE, we turn data security risk into a controllable and visualized target.



Dr. Yueh-Hsun Lin is the Principal Data Security Architect of JD.com's Silicon Valley Research Center, where he builds up core data security services to protect JD proprietary data and customer information. JD Security team is developing edge technologies preventing internal cloud services from outside and inside threats.

Prior to JD.com, Dr. Lin was the Senior Staff Scientist of Samsung Research America (SRA) where he focuses on protocol design and develops a couple of new features hardening security in mobile payments, Android security, and Internet of Things (IoT) security for in-vehicle network and Smartthings platforms. At the end of 2016, he received KNOX research star award for his contribution. Prior to SRA, Dr. Lin worked as Postdoc Research Fellow in CyLab, Carnegie Mellon University. He worked on edge technologies, including advanced key management, network security, and trust computing. 

