• DocumentCode
    1820641
  • Title

    Compliant Cloud Computing (C3): Architecture and Language Support for User-Driven Compliance Management in Clouds

  • Author

    Brandic, Ivona ; Dustdar, Schahram ; Anstett, Tobias ; Schumm, David ; Leymann, Frank ; Konrad, Ralf

  • Author_Institution
    Distrib. Syst. Group, Vienna Univ. of Technol., Vienna, Austria
  • fYear
    2010
  • fDate
    5-10 July 2010
  • Firstpage
    244
  • Lastpage
    251
  • Abstract
    Cloud computing represents a promising computing paradigm, where computational power is provided similar to utilities like water, electricity or gas. While most of the Cloud providers can guarantee some measurable non-functional performance metrics e.g., service availability or throughput, there is lack of adequate mechanisms for guaranteeing certifiable and auditable security, trust, and privacy of the applications and the data they process. This lack represents an obstacle for moving most business relevant applications into the Cloud. In this paper we devise a novel approach for compliance management in Clouds, which we termed Compliant Cloud Computing (C3). On one hand, we propose novel languages for specifying compliance requirements concerning security, privacy, and trust by leveraging domain specific languages and compliance level agreements. On the other hand, we propose the C3 middleware responsible for the deployment of certifiable and auditable applications, for provider selection in compliance with the user requirements, and for enactment and enforcement of compliance level agreements. We underpin our approach with a use case discussing various techniques necessary for achieving security, privacy, and trust in Clouds as for example data fragmentation among different protection domains or among different geographical regions.
  • Keywords
    Internet; data privacy; middleware; programming languages; security of data; C3 middleware; cloud providers; compliance level agreements; compliant cloud computing; domain specific languages; nonfunctional performance metrics; service privacy; service security; service trust; user requirements; user-driven compliance management; Business; Cloud computing; Clouds; DSL; Portals; Security; Unified modeling language; Compliance managmenet; DSLs; SLAs;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Cloud Computing (CLOUD), 2010 IEEE 3rd International Conference on
  • Conference_Location
    Miami, FL
  • Print_ISBN
    978-1-4244-8207-8
  • Electronic_ISBN
    978-0-7695-4130-3
  • Type

    conf

  • DOI
    10.1109/CLOUD.2010.42
  • Filename
    5557988