| 
View
 

Secure Data Publishing

Page history last edited by meyerschalk 17 years ago

Defintion or Problems Statement:

(There is the need to define strict rules for the storing, access and loggivity of data in a cloud to establish trust to exist between the cloud provider and a user of the cloud service) 

1. we need a way to know what service and who have access to our data in a cloud.

2. we need to restrict the life cycle of our data in a could(expire data liek content)

3. Services in a cloud should only have access to data in a cloud on a needs to perform task basis

4. we should be able to termeinate the cloud access to our data at ant time with confidance that all the data is removed

 

What is needed.

(special attibute is needed for data access, when added[by |when], updated[by| when] and acceed[by,when]) 

1. Request to a cloud for the competion of a service shall have minimal information.

2. The need for a protocol header and a clous shall unpact data based on service type, service level and security descitor

3. Service sall request additional data from a "secure data vault".

4. After the completion of the service execution the data result from the service shall be placed in the secure data vault and a unique result key shall be created

5. The result key shall be return to the requested of the service

6. The requester of the service can then retrieve the data from the secure dat vauld

6. The requester have the resposibility to expire the data, update the offical data warehouse and update any logs needed for legal and finatila reasons

 

What this acomplish

1. knowledge on where the data is loaded and located in the cload in the cload

2. The services in the cloud should not cache or  store data any where else but in the vault

3. The location and management of the vault can then be audited by the client

4. Policies on data retention should be set and review and audited

5. when the contract between the vendor and cloud proiver expire removal can be confirmed through and audit

6. Backups can be store with a external provider and can only be use for recovery by cloud provider with approval cform client as the data belongs to the client 

 

This is just the start fo a definition and specification process and we believe that if there are simple and clear rules that all clouds can easily follow this will also provide a data access pattern for services in a cloud to ensure uniform data management.

Comments (0)

You don't have permission to comment on this page.