A Cloud Accountability Policy Representation Framework

نویسندگان

  • Walid Benghabrit
  • Hervé Grall
  • Jean-Claude Royer
  • Mohamed Sellami
  • Monir Azraoui
  • Kaoutar Elkhiyaoui
  • Melek Önen
  • Anderson Santana de Oliveira
  • Karin Bernsmed
چکیده

Nowadays we are witnessing the democratization of cloud services. As a result, more and more endusers (individuals and businesses) are using these services for achieving their electronic transactions (shopping, administrative procedures, B2B transactions, etc.). In such scenarios, personal data is generally flowed between several entities and end-users need (i) to be aware of the management, processing, storage and retention of personal data, and (ii) to have necessary means to hold service providers accountable for the usage of their data. In fact, dealing with personal data raises several privacy and accountability issues that must be considered before to promote the use of cloud services. In this paper, we propose a framework for the representation of cloud accountability policies. Such policies offer to end-users a clear view of the privacy and accountability obligations asserted by the entities they interact with, as well as means to represent their preferences. This framework comes with two novel accountability policy languages; an abstract one, which is devoted for the representation of preferences/obligations in an human readable fashion, a concrete one for the mapping to concrete enforceable policies. We motivate our solution with concrete use case

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

A Novel Information Accountability Framework for Cloud Computing

Cloud computing is an emerging paradigm in the computer industry where the computing is moved to a cloud of computer systems. The cloud computing core concept is, simply, that the vast computing resources that we need will reside somewhere out there in the cloud of computer systems and we will connect to them and use them as and when needed. The difficulty of how to provide proper security as w...

متن کامل

CLOUD ACCOUNTABILITY PROJECT D : C - 4 . 1 : Policy Representation Framework

Component Design The component diagram (Figure 4.2) describes a part of the health care actors and their interactions. We have the data subject Kim and his relative Sandra. Sandra is a joint data controller. There are three cloud providers (named cloudX, cloudY and cloudZ). The data controller is the hospital and Leslie is the auditor. These entities are represented as components in the diagram...

متن کامل

A-PPL: An Accountability Policy Language

The inherent lack of control of users over their data raises various security and privacy challenges in Cloud Computing. One approach to encourage customers to take advantage of the Cloud is the design of new accountability solutions which aid and enable customers to control and be informed on how their data is processed. In this paper, we focus on accountability policies and propose A-PPL, an ...

متن کامل

Evaluation of a Security Service Level Agreement

Data breaches are the most serious security breaks among all types of cybersecurity threats. While Cloud hosting services provide assurances against data loss, understanding the security service level agreements (SSLAs) and privacy policies offered by the service providers empowers consumers to assess risks and costs associated with migrating their information technology (IT) operations to the ...

متن کامل

پاسخگویی در شبکه خط‌‌مشی عمومی

Policy networks consist of state and social actors whose interactions lead to the formulation and/or implementation of policies. One of the characteristics of networks is that power is usually distributed and lies in the relationships among actors. Therefore, network accountability can be problematic. The purpose of this study is to form a theoretical framework for accountability in public poli...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2014