Page 819 - Cloud computing: From paradigm to operation
P. 819
Intercloud and interoperability 5
Title Distributed information exchange system in trusted inter-cloud
– The CSC requests that physical location (localization) for their data store as
well as CSP can be chosen by CSC in an elastic manner.
– The primary CSP(SaaS) in an inter-cloud intermediary pattern (acts as
CSP(Intermediary)) is the contact point for CSC.
– The CSP(Intermediary) integrates and validate SaaS services from multiple
CSPs (secondary CSPs).
– The CSP2(SaaS) offers the same service as CSP1(SaaS) or CSP3(SaaS) but does
not meet the required business regulatory policy.
– For the CSP(Intermediary), in order to respect the request of CSC, it is
necessary to validate security and confidentiality policies from secondary
CSP1(SaaS), CSP2(SaaS) and CSP3(SaaS). In case of negative validation, the
secondary CSP offer is not presented to CSC.
– In case of connectivity problem between CSP(Intermediary) and CSP1, the
SaaS service is automatically established between CSP(Intermediary) and
CSP3.
In particular, an example of such service could be PaaS-based processing of
satellite image data for farm crop analysis.
Roles CSC,CSP(SaaS)
Figure (optional)
Pre-conditions (optional) – The primary CSP(SaaS) and secondary CSPs are in a trusted inter-cloud
relationship.
– The CSP1(SaaS) and CSP3(SaaS) effects security, safety and confidentiality
policies.
– The CSP2(SaaS) performs service out of business regulatory policy.
Post-conditions (optional) – The CSP(Intermediary) guarantees the security and confidentiality policy of
SaaS.
– The CSP(Intermediary) establishes service between CSC and CSP1(SaaS).
– The CSP(Intermediary) establishes service between CSC and CSP3(SaaS) in case
of failed CSP1(SaaS).
Derived requirements – security and confidentiality policies
– master service agreements
– on-demand data security services
– deployment and monitoring of security policies around CSPs
– respect data regulation policy (e.g., medical, financial, defence, etc.)
NOTE – Regulation policy concern regulation applied to particular business.
– respect business regulatory policies
– resiliency service
– respect laws and regulations,
– respect local policies.
811