Cloud API & Gateway Security
![]()
Cloud Security Background
The enterprise has already taken its first baby steps to cloud orientation with wide deployment of virtualized infrastructure, use of SaaS, and IaaS (Infrastructure as a Service) for short-lived projects requiring a few isolated servers. However, the next evolution to PaaS (Platform as a Service) will require a mastery of portable cloud security architectures based on service virtualization, federated identity, and token exchange.
A cloud gateway delivers these capabilities and enables the Enterprise to project their security policies on the cloud to protect data at rest and data in flight among dynamically scalable data center environments. This on-premise or cloud hosted gateway approach has emerged as the recommend cloud computing security model to secure, govern, control, and broker interactions with cloud providers.
Intel Solution
Intel® Expressway Service Gateway’s cloud gateway can be used with hybrid, private, or public cloud models, or for creating secure community clouds. Intel is strategically engaged with standards bodies and the vendor community to deliver secure client-to-cloud interactions with the Intel Expressway Service Gateway as a focus point for continued Intel innovations in hardware & software cloud optimizations.
Intel Expressway Service Gateway acts as a secure broker delivering:
- Saas security cloud connectors to popular providers such as Amazon and Salesforce.com
- API governance, quality of service, and throttling
- Security Token Service (STS) validation & exchange. SAML, Kerberos, CA* SiteMinder, and many other credential formats supported
- Single point of audit for security policies & integration with SIEM or other monitoring solutions
- "Write once…apply anywhere" security policy enforcement
- Builds a repeatable security model that can be readily shifted among cloud providers
Additional Information
White Paper: Taking Control of the Cloud for the Enterprise
White Paper: Cloud Security Reference Architecture Guide
Cloud Webinar: Chewing the Cloud: Attacking Cloud-based Services

