The user control over the life cycle of data is of an extreme importance in clouds in order to determine whether the service provider adheres to the client’s pre-specified needs in the contract between them or not, significant clients concerns raise on some aspects like social, location and the laws to which the data are subject to. The problem is even magnified more with the lack of transparency by Cloud Service Providers (CSPs). Auditing and compliance enforcement introduce different set of challenges in cloud computing that are not yet resolved. In this paper, a conducted questionnaire showed that the data owners have real concerns about not just the secrecy and integrity of their data in cloud environment, but also for spatial, temporal, and legal issues related to their data especially for sensitive or personal data. The questionnaire results show the importance for the data owners to address mainly three major issues: Their ability to continue the work, the secrecy and integrity of their data, and the spatial, legal, temporal constraints related to their data. Although a good volume of work was dedicated for auditing in the literature, only little work was dedicated to the fulfillment of the contractual obligations of the CSPs. The paper contributes to knowledge by proposing an extension to the auditing models to include the fulfillment of contractual obligations aspects beside the important aspects of secrecy and integrity of client’s data.
KeywordsAuditingPublic AudibilityDynamic Data AuditingSpatial ControlTemporal ControlLogging DataContractual Obligations
Pardeshi, P.M. and Borade, D.R. (2015) Improving Data Integrity for Data Storage Security in Cloud Computing. International Journal of Computer Science and Network Security (IJCSNS), 15, 75.
Henze, M., Hummen, R. and Wehrle, K. (2013) The Cloud Needs Cross-Layer Data Handling Annotations. 2013 IEEE Security and Privacy Workshops (SPW), Washington DC, 23-24 May 2013, 18-22. http://dx.doi.org/10.1109/spw.2013.31
Marinescu, D.C. (2013) Cloud Computing: Theory and Practice. Newnes.
Liu, C.-W., et al. (2016) A Survey of Attribute-Based Access Control with User Revocation in Cloud Data Storage. International Journal of Network Security, 18, 900-916.
Kishore, N. and Sharma, S. (2016) Secured Data Migration from Enterprise to Cloud Storage–Analytical Survey. BVICAM’s International Journal of Information Technology, 8(1).
Kumar, D. and Karuppuchamy, V. (2016) Competent Demonstrable Data Possession for Integrity Verification in Multi-Cloud Storage. International Research Journal of Engineering and Technology (IRJET), 3, 464-468.
Brandenburger, M., Cachin, C. and Knezevic, N. (2016) Securing Integrity and Consistency of a Cloud Storage Service with Efficient Client Operations. US Patent No. 20,160,048,703.
Ghafghazi, H., et al. (2016) Secure Data Storage Structure and Privacy-Preserving Mobile Search Scheme for Public Safety Networks. arXiv preprint arXiv:1602.04493
Wu, S., Li, K.C., Mao, B. and Liao, M. (2016) DAC: Improving Storage Availability with Deduplication-Assisted Cloud-of-Clouds. Future Generation Computer Systems.
Pasquier, T. and Eyers, D. (2016) Information Flow Audit for Transparency and Compliance in the Handling of Personal Data. In IC2E International Workshop on Legal and Technical Issues in Cloud Computing (CLaw'16). IEEE.
Hsien, W.-F., Yang, C.-C. and Hwang, M.-S. (2016) A Survey of Public Auditing for Secure Data Storage in Cloud Computing. International Journal of Network Security, 18, 133-142.
Pasquier, T.F.M. and Powles, J.E. (2015, March) Expressing and Enforcing Location Requirements in the Cloud Using Information Flow Control. In Cloud Engineering (IC2E), 2015 IEEE International Conference on (pp. 410-415). IEEE.
BrancoJr, T. and Santos, H. (2016, June) What Is Missing for Trust in the Cloud Computing? In Proceedings of the 2016 ACM SIGMIS Conference on Computers and People Research (pp. 27-28). ACM.
Jain, S., Kumar, R., Kumawat, S. and Jangir, S.K. (2014) An Analysis of Security and Privacy Issues, Challenges with Possible Solution in Cloud Computing. In National Conference on Computational and Mathematical Sciences (COMPUTATIA-IV), Technically Sponsored By: ISITA and RAOPS, Jaipur.
Chen, Z. and Yoon, J. (2010, July) IT Auditing to Assure a Secure Cloud Computing. In 2010 6th World Congress on Services (pp. 253-259). IEEE.
Zaigham, M. (2011) Data Location and Security Issues in Cloud Computing. International Conference on Emerging Intelligent Data and Web Technologies (EIDWT), Tirana, 7-9 September 2011, 49-54.
Irfan, G., Rehman, A. and Islam, M.H. (2011) Cloud Computing Security Auditing. 2nd International Conference on Next Generation Information Technology (ICNIT), Gyeongju, 21-23 June 2011, 143-148.
Golzardi, E. (2015) Cloud Computing Security: A Survey. Journal of Information Sciences and Computing Technologies, 5, 377-385.
Deswarte, Y., Quisquater, J.J. and Saïdane, A. (2004) Remote Integrity Checking. In Integrity and Internal Control in Information Systems VI (pp. 1-11). Springer US.
Wang, Q., Wang, C., Ren, K., Lou, W. and Li, J. (2011) Enabling Public Auditability and Data Dynamics for Storage Security in Cloud Computing. IEEE Transactions on Parallel and Distributed Systems, 22, 847-859. http://dx.doi.org/10.1109/TPDS.2010.183
Massonet, P., Naqvi, S., Ponsard, C., Latanicki, J., Rochwerger, B. and Villari, M. (2011, May) A Monitoring and Audit Logging Architecture for Data Location Compliance in Federated Cloud Infrastructures. In Parallel and Distributed Processing Workshops and Phd Forum (IPDPSW), 2011 IEEE International Symposium on (pp. 1510-1517). IEEE.
Eskandari, M., De Oliveira, A.S. and Crispo, B. (2014) VLOC: An Approach to Verify the Physical Location of a Virtual Machine Cloud. 6th International Conference on Cloud Computing Technology and Science (Cloud Com), Singapore, 15-18 December 2014, 86-94. http://dx.doi.org/10.1109/cloudcom.2014.47
Wüchner, T., Müller, S. and Fischer, R. (2013, December) Compliance-Preserving Cloud Storage Federation Based on Data-Driven Usage Control. In Cloud Computing Technology and Science (CloudCom), 2013 IEEE 5th International Conference on (Vol. 2, pp. 285-288). IEEE.
Pasquier, T., Singh, J., Bacon, J. and Eyers, D. (2016) Information Flow Audit for PaaS Clouds. International Conference on Cloud Engineering (IC2E), Berlin, 4-8 April 2016, 81-88. http://dx.doi.org/10.1109/ic2e.2016.19
Tan, Y.S., Ko, R.K.L. and Holmes, G. (2013) Security and Data Accountability in Distributed Systems: A Provenance Survey. 10th International Conference on High Performance Computing and Communications & 2013 IEEE International Conference on Embedded and Ubiquitous Computing (HPCC_EUC), Zhangjiajie, 13-15 November 2013, 1571-1578.
Meena, K. and Gomathy, M. (2016) study on Security Frameworks and Data Protection Techniques for Public Cloud Environment. APPN Journal of Engineering and Applied Sciences, 11, 5933-5939.
Khan, M.A. (2016) A Survey of Security Issues for Cloud Computing. Journal of Network and Computer Applications, 71, 11-29. http://dx.doi.org/10.1016/j.jnca.2016.05.010
Brindha, T. and Shaji, R.S. (2015) An Analysis of Data Leakage and Prevention Techniques in Cloud Environment. 2015 International Conference on Control, Instrumentation, Communication and Computational Technologies (ICCICCT), Noorul Islam University, 18-19 December 2015, 350-355.
Singh, J., Pasquier, T., Bacon, J., Ko, H. and Eyers, D. (2016) Twenty Security Considerations for Cloud-Supported Internet of Things. IEEE Internet of Things Journal, 3, 269-284. http://dx.doi.org/10.1109/JIOT.2015.2460333