Page 818 - Cloud computing: From paradigm to operation
P. 818
5 Intercloud and interoperability
Title Distributed image platform in trusted inter-cloud
– In case of connectivity problem between CSP(Intermediary) and CSP1, the
SaaS service is automatically established between CSP(Intermediary) and
CSP3.
In particular, an example of such service could be sharing information of patients'
healthcare between hospitals. The hospitals can exchange all medical data of
patients, while other agencies such as insurance or government have access
limited to statistical information only without personally identifiable information
(PII).
Roles CSC, CSP(PaaS), CSP(SaaS)
Figure (optional)
Pre-conditions (optional) – The primary CSP(PaaS) and secondary CSPs are in trusted inter-cloud
relationship.
– The CSP1(SaaS) and CSP3(SaaS) effects security, safety and confidentiality
polices.
– The CSP2(SaaS) performs service out of business regulatory policy.
Post-conditions (optional) – The CSP(Intermediary) guarantees security and confidentiality policy of SaaS.
– The CSP(Intermediary) establishes service between CSC and CSP1(SaaS).
– The CSP(Intermediary) establishes service between CSC and CSP3 (SaaS) in
case CSP1(SaaS) fails.
Derived requirements – security and confidentiality policies
– unified (commonly adopted) security policies and metadata
– interoperability and dependability
– support appropriate level of robustness
– security policy negotiation terminology
– management of distributed data
– resiliency service from multiple CSPs
I.2.5 Use case of distributed information exchange system in trusted inter-cloud
This use case illustrates the security and confidentiality aspect of trusted inter-cloud between a primary CSP
and secondary CSPs. The intermediary pattern of inter-cloud used to illustrate the use case is an example
only.
Table I.2.5 – Distributed information exchange system in trusted inter-cloud
Title Distributed information exchange system in trusted inter-cloud
Description – The CSC from regulation business domain (e.g., healthcare, finance, defence),
requests the CSP for a service to build an information exchange system. CSC
requires that information will be distributed respecting business regulatory
policies and data regulation policy.
– The CSC requests that distributed information exchange system fits regulatory
policy to reach safety, security and confidentiality constraints.
810