- Research Article
3
- 10.2139/ssrn.1712565
Data Portability: Key to Cloud Portability and Interoperability
- Nov 21, 2010
- SSRN Electronic Journal
- Shahab Ahmed
Data Portability: Key to Cloud Portability and Interoperability
Cloud computing has become an alternative IT infrastructure where users, infrastructure providers, and service providers all share and deploy resources for their business processes and applications. In order to deliver cloud services cost effectively, users' data is stored in a cloud where applications are able to perform requests from clients efficiently. As data is transferred to the cloud, data owners are concerned about the loss of control of their data and cloud service providers (CSPs) are concerned about their ability to protect data when it is moved about both within and out of its own environment. Many security and protection mechanisms have been proposed to protect cloud data by employing various policies, encryption techniques, and monitoring and auditing approaches. However, data is still exposed to potential disclosures and attacks if it is moved and located at another cloud where there is no equivalent security measure at visited sites. In a realistic cloud scenario with hierarchical service chain, the handling of data in a cloud can be delegated by a CSP to a subprovider or another. However, CSPs do not often deploy the same protection schemes. Movement of user's data is an important issue in cloud, and it has to be addressed to ensure the data is protected in an integrated manner regardless of its location in the environment. The user is concerned whether its data is located in locations covered by the service level agreement, and data operations are protected from unauthorized users. When user's data is moved to data centers located at locations different from its home, it is necessary to keep track of its locations and data operations. This chapter discusses data protection and mobility management issues in cloud environment and in particular the implementation of a trust-oriented data protection framework.
Data Portability: Key to Cloud Portability and Interoperability
Data Portability: Key to Cloud Portability and Interoperability
JCDC: A blockchain-based framework for secure data storage and circulation in JointCloud
JCDC: A blockchain-based framework for secure data storage and circulation in JointCloud
Conceptual Service Level Agreement Mechanism to Minimize the SLA Violation with SLA Negotiation Process in Cloud Computing Environment
Online service is used to be as Pay-Per-Use in Cloud computing. Service user need not be in a long time contract with cloud service providers. Service level agreements (SLAs) are understandings marked between a cloud service providers and others, for example, a service user, intermediary operator, or observing operators. Since cloud computing is an ongoing technology giving numerous services to basic business applications and adaptable systems to manage online agreements are significant. SLA maintains the quality-of-service to the cloud user. If service provider fails to maintain the required service SLA is considered to be SLA violated. The main aim is to minimize the SLA violations for maintain the QoS of their cloud users. In this research article, a toolbox is proposed to help the procedure of exchanging of a SLA with the service providers that will enable the cloud client in indicating service quality demands and an algorithm as well as Negotiation model is also proposed to negotiate the request with the service providers to produce a better agreement between service provider and cloud service consumer. Subsequently, the discussed framework can reduce SLA violations as well as negotiation disappointments and have expanded cost-adequacy. Moreover, the suggested SLA toolkit is additionally productive to clients so clients can secure a sensible value repayment for diminished QoS or conceding time. This research shows the assurance level in the cloud service providers can be kept up by as yet conveying the services with no interruption from the client's perspective
Read moreImplications of Cloud Computing for Personal Data Protection and Privacy in the Era of the Cloud: An Indian Perspective
Reeta Sony A.L - National Law University, New Delhi, India. E-mail:reeta.sony@nludelhi.ac.in.Sri Krishna Deva Rao - Professor, National Law University, New Delhi, India. E-mail: psrikrishnadevarao@gmail.com.Bhukya Devi Prasad - Council of Scientific and Industrial Research, New Delhi, India. E-mail: bdeviprasad@csir.res.in. Cloud computing refers to anything that involves delivering hosted services over the Internet. It is fast, cheap, flexible and elastic in nature. In spite of its benefits, cloud computing raises risks for data protection and privacy. One key issue presented by cloud computing is the fact that it changes our thinking of what we consider to be "our data" Data is no longer physically stored on a specific set of computers or servers, but is rather geographically distributed. The globalised nature of cloud computing poses a challenge for personal data protection, which requires a clear location for personal data, an identification of the processor and a responsible individual for data processing. Cloud data can be misused and/or shared with third parties without prior knowledge or consent of the data owner. The direct participation of an individual in transborder data transfer, third party participation in data storage, the processing and transmission of dataand, finally, negligence of data protection due diligence from cloud service providers, makes data protection and privacy laws more relevant. The recent PRISM surveillance programme scandal at the US National Security Agency (NSA) demonstrated the privacy risks that citizens around the world take on when their personal information is stored and processed in the cloud. This situation requires awell-established techno-legal solution along international standards. India, unlike the European Union, has no dedicated regulatory framework to deal with privacy and personal data protection. Although cloud computing is still in its initial stages in India, existing laws for people who are currently using facilities offeredby cloud service providers are extremely inadequate. However, cloud computing requires legal protection in India under the country's data protection laws, privacy laws and data breach laws, which must meet "international standards'! It is the right time for the Indian government to enact appropriate regulatory frameworks to protect personal data and privacy in the cloud era. The overall objective of this paper is to understand the impact of cloud computing on privacy and personal data protection and to analyse present legal frameworks governing privacy and personal data protection in India and Europe.
Read moreCloud Service Pricing Strategy Based on Service Level Agreement with Default Compensation
The emergence of cloud computing has completely changed the entire IT world. There is no doubt that making a profit is a cloud service provider (CSP)’s ultimate goal. To make a profit, a CSP needs a reasonable pricing strategy. At the same time, in order to increase the attractiveness of cloud service, CSPs tend to write default clauses in the service level agreement (SLA) and the default cost will affect the profit of CSPs. To determine an optimal pricing strategy, this paper builds some bi-level programming models of CSPs and users. The basic model does not consider default compensation and the default cost is included in the extended model. Finally, the comparison results of the two models prove that it is significant for the CSP to set default compensation clauses.
Read moreMulti-Layered Attack Recognition (MLAR) Model to Protect Cloud From EDOS Attacks
In this paper, the work is carried upon the security of cloud computing environment from the economic denial of service (EDOS) attacks. The cloud computing environments have become popular in the past decade, as number of businesses has shifted their work online to the cloud. The cloud service providers offer the maximum uptime for their users, which is committed in the form of service level agreements (SLAs). The uptime is the term used to indicate the availability of the cloud computing resources for client's application to run its processes. If at any point, the client application is not able to run its operations due to non-availability of resources, it is considered as the downtime, which is negative to the uptime and considered as SLA violation. The SLAs keep the information about the SLA violations and their settlements, which is considered as the loss of the cloud service providers. For example, the uptime of 99.99% is committed by cloud service provider, and due to any internal or external reason, achieved uptime is lower than committed value, the cloud service provider may face a penalty as per defined in the SLA, which is considered direct profit loss for the service provider. In order to reduce the financial losses due to the EDOS attacks, the proposed model is designed by combining the periodic authentication, pattern analysis and data flow control mechanisms to prevent the cloud from attacks. The proposed Multi-Layered Attack Recognition (MLAR) Model has outperformed the existing controlled access based EDOS (CA-EDOS) prevention model on the basis of resource utilization and response delay parameters.
Read moreData protection management in university libraries in the UK
The paper, based on British Library funded research, examines a range of issues relating to data protection management in UK university library and information services. A general description of data protection legislation in the UK is followed by a brief overview of the aspects which involve personal data in libraries. The result of an impact survey of UK university libraries ranging in size are reported in detail and discussed. Institutional experiences are noted, including the penetration of information technology (IT) into library activities, together with the organisation of data protection responsibilities and practice. Almost all institutions are registered under the Data Protection Act 1984 and many have someone specially designated to oversee data protection. There is extensive use of IT in the libraries surveyed, particularly for cataloguing, ordering and circulation, although far fewer have automated reference logs and personnel records. A small number of libraries disclose details of book borrowings. Very few individuals have exercised their right of access to data, and having to pay a fee for doing so does not appear to be a disincentive. Data protection awareness and training issues are examined both subjectively and objectively. Data protection is included at induction training in just under half the responding libraries and at fewer as an ongoing activity. Specialist conferences and seminars do not feature highly. A majority of respondents claim adequate knowledge of data protection for themselves and their staff, though some report it as poor. A checklist of relevant sources illustrates respondents’ reading on the subject and reveals that a significant minority have not consulted anything. Respondents’ perceptions about the legislation and its future development are noted. The vast majority believe that data protection legislation has made no difference to the way that they manage. The legislation is regarded as being evenly balanced between data users and individuals by almost half the respondents, and an equal proportion see it as favouring individuals. Disappointingly few have views on improving and modifying the current legislation. The results are assessed in a concluding commentary which highlights areas of interest and concern, and makes some comparisons with an earlier study in a related area. Given the overall outcome of the survey, the importance of raising awareness and nurturing good practice is stated.
Read moreA User-Priorities-Based Strategy for Three-Phase Intelligent Recommendation and Negotiating Agents for Cloud Services
As the field of information technology expands, there is a huge need for cloud service providers (CSP). CSP’s vast solutions and services support Cloud, IoT, Fog, and Edge computing. In today’s competitive cloud market, customer satisfaction is critical more than ever. CSP and consumer satisfaction with service level agreement (SLA) fulfillment have always been given more attention. As a result of signing SLA and CSP agreements to supply resources in high demand, customers are now experiencing issues with resource delivery. Cloud and heterogeneous environments necessitate an intelligent recommender and negotiation agent model (IRNAM) to handle responsibilities in the current system. The Recommender system recommends CSP as per users’ priorities, which eases the filtration process. The negotiation process provided by IRNAM ensures that users’ choices are prioritized with maximum jobs to CSP. IRNAM keeps track of the most critical metrics and can reach decisions quickly and for the best possible deal. It uses an analytical concession algorithm that analyzes consumer and CSP choices to find a reliable, secure server with the simplest solution. The negotiation process uses user’s and CSP choice metrics, performance factors, evaluation measures, and success factors in the best execution time to decide. IRNAM provides a flexible and valuable way for selecting CSP and negotiating for services on the user’s terms while considering CSP satisfaction.
Read moreThe Flip-Flop SLA Negotiation Strategy Using Concession Extrapolation and 3D Utility Function
A service level agreement (SLA) is part of a contract between a cloud service provider (CSP) and a cloud service user (CSU) which defines and describes different agreed properties of the service. The negotiation of the SLA between a CSU and a CSP is a pivotal process in the SLA life cycle. An SLA may include many negotiable quality of service (QoS) parameters with each QoS parameter having multiple acceptable values. Different combinations of acceptable values for all QoS parameters grow exponentially as number of QoS parameters and their selectable values increase. Manually negotiating for all of the QoS parameters considering their various options can be an erroneous and diligent task with lower utility. In this paper, a time efficient flip-flop negotiation strategy for the SLAs in cloud services is presented. The flip-flop negotiation strategy is based on a time dependent 3D utility function and on a dynamic concession strategy using the polynomial extrapolation of opponent's concession. This negotiation strategy is useful for time-critical cloud services as it operates with a motive of reaching an agreement at earlier time without compromising over the utility level of the agreement. Moreover, a multi-provider concurrent negotiation method is presented in this work using the flip-flop negotiation strategy. Multiple experiments are performed (using the implementation of flip-flop negotiation strategy) to test the presented work. The results of the experiments enforce the validity of the flip-flop negotiation strategy for such cloud services where time is an important factor during the SLA negotiation process.
Read moreEffective Third Party Auditing in Cloud Computing
Cloud computing is the next phase in the Internet's evolution, providing the means through which computing power, computing infrastructure, applications, business processes can be delivered to businesses and individual as a service wherever and whenever they need. Businesses who use cloud service providers (CSP) tend to have service level agreements (SLA) that act as contract and define the level of expected service from the CSP, including availability, performance and security. Recent research suggests the use of third party auditors (TPA) as a mean to monitor CSPs. This paper shows how CSP may deceit the SLA to reduce their cost and become more competitive, while avoiding detection by TPAs. The paper presents a crowdsourced TPA model to monitor the CSPs and consequently detect any deception.
Read morePerformance Difference Prediction in Cloud Services for SLA-Based Auditing
Cloud computing allows individuals and organizations outsource their applications to cloud due to the flexibility and cost savings. However, cloud service providers (CSPs) may offer reduced resources to tenant by virtualization technology for illegal economic benefit. Most cloud tenants don't have specialized knowledge to detect the CSPs' service level agreement (SLA) disruption. To address this issue, we propose a worst-case performance prediction scheme to audit the SLA disruption of cloud by comparison between actual performance cost and the predicted worst-case performance cost. Firstly, we insert labels into application, and collect the running time information on cloud on a small input dataset. The historical information is used to identify the frequent block. Then, we construct the performance cost function for each hotspot block, and resort to curve fitting method to obtain the performance cost function of each frequent block. Finally, we get the worst-case performance prediction by performance estimation model and performance cost function of each one on large input dataset. The experiments show that our proposed scheme can achieve high sensitiveness on cloud SLA and fulfill cloud SLA auditing.
Read moreCloud Computing: Understanding the Technology before Getting “Clouded”
The IT Industry and the wider media are abuzz with the phrase “cloud computing” and most of us have no idea what this latest terminology means. This paper starts by addressing the question – “what is cloud computing, and provides an understanding of the technology?” Cloud computing is related to technologies that has been around for ages, however, what can be done differently with the same technology when integrated with Internet is cloud computing.Individuals who might be considering cloud computing services for personal use will also benefit by the information provided. Web sites like Flickr, FaceBook, YouTube and others are used to store and share personal photos, music and videos for free. Easy as: 1). Register, 2). Upload, 3). Share. Free and easy, there has to be a downside, and there is awareness regarding this.There is information regarding cloud computing for businesses! Businesses, who wish to get on the “flight to the clouds” like their peers to keep their heads above the “cloud” and competition. With cloud service providers, businesses can tap into the IT services that they need, when they need, for as long as they need; without investing in any IT infrastructure. The result is a far more agile and cost-effective IT services and this paper looks at how and why.After looking at the good of cloud computing, the bad, and the ugly is revealed. Not all our experiences on the Internet have been totally positive. A range of security and trust issues exist. Individuals and businesses ask is “how secured are their information once it is with the cloud service providers?” There is analysis on the ownership of data and information stored with the cloud service providers and taxonomy of data that you post on social networking web sites.Finally, anecdotes about cloud computing that support our endeavour to compute in the cloud. Cloud computing is not a hype, it is a reality. Cloud computing is not a fad, it is here to stay. The question is no longer “will cloud computing happen?” but “how you are going to exploit this technology?”Keywordscloud computingvirtual computingcluster computingdistributed computingpervasive computing
Read moreAutomated Mapping of Service Level Agreements to Application Programming Interfaces of Different Cloud Service Providers
Most of the web (mobile) applications are using cloud computing technology. Developers who want to develop an application can make use of the provisions and services provided by a cloud service provider. There are a number cloud service providers (CSPs). Each of these cloud service providers offer a number of services. Going through all the services of all the CSPs and finding out what service matches the requirements in the SLA document, manually is time consuming, error prone and tedious. And opting for all the services will add extra charges for the owner. Hence it is important to have a system that can match the requirements in the SLA (Service Level Agreement) document with the APIs (Application Programming Interfaces) of the cloud service providers. This paper proposes a method to match the requirements of a businessman with the APIs of the CSPs. The requirements are written in a text document and the description of the APIs of CSPs are written in another text document. Then using text similarity in natural language processing, the APIs that satisfy the requirements in the text document are identified.
Read moreEvaluation of SLA-based decision strategies for VM scheduling in cloud data centers
Service level agreements (SLAs) gain more and more importance in the area of cloud computing. An SLA is a contract between a customer and a cloud service provider (CSP) in which the CSP guarantees functional and non-functional quality of service parameters for cloud services. Since CSPs have to pay for the hardware used as well as penalties for violating SLAs, they are eager to fulfill these agreements while at the same time optimizing the utilization of their resources.In this paper we examine SLA-aware VM scheduling strategies for cloud data centers. The service level objectives considered are resource usage and availability. The sample resources are CPU and RAM. They can be overprovisioned by the CSPs which is the main leverage to increase their revenue. The availability of a VM is affected by migrating it within and between data centers. To get realistic results, we simulate the effect of the strategies using the FederatedCloudSim framework and real-world workload traces of business-critical VMs.Our evaluation shows that there are considerable differences between the scheduling strategies in terms of SLA violations and the number of migrations. From all strategies considered, the combination of the Minimization of Migrations strategy for VM selection and the Worst Fit strategy for host selection achieves the best results.
Read moreService Level Agreement in cloud computing: Taxonomy, prospects, and challenges
Service Level Agreement in cloud computing: Taxonomy, prospects, and challenges