Chap1:
Introduction to Cloud Computing
7
0
Part 3:
Cloud reference model : Role Based
Architecture
38
Cloud Computing Reference Architecture (CCRA) (NIST*)
▪ The CCRA developed by NIST is a framework that defines the roles and
responsibilities within a cloud computing ecosystem.
▪ It provides a standard model to understand, design, and discuss cloud systems,
ensuring consistent cloud service definitions.
72
Cloud Computing Reference Architecture (NIST*)
73
Actors’ Roles
▪ Cloud Services Consumer:
▪ A person or organization that maintains a business relationship with, and
uses service from, Cloud Providers.
▪ SLAs (QoS, security, remedies for performance failures) are required to
specify the technical performance requirements fulfilled by a cloud provider.
▪ Cloud Services Providers:
▪ A person, organization, or entity responsible for making a service available
to interested parties.
▪ Amazon Web Services, Microsoft Azure, Google Cloud Platform, IBM 74
Cloud, Rackspace,…
Actors’ Roles
▪ Cloud Services Providers:
75
Actors’ Roles (…)
▪ Cloud Brokers:
▪ Aggregation: enabling to consumers the consumption of cloud services via a
cloud application marketplace approved by the company
▪ Integration: facilitating the data exchange among cloud applications and on
premise applications to orchestrate business processes
▪ Customization: enhancing cloud services with security mechanisms (non-
compromised data) and Identity management services (manage user credentials)
▪ IBM Cloud Broker, RackNap, Odin Service Automation, Ubersmith, AppDirect
76
Actors’ Roles (…)
▪ Cloud Auditors:
▪ A party that can conduct independent assessment of cloud services, information system
operations, performance and security of the cloud implementation.
▪ Identify compliance requirements: corporate policies and standards, laws and
regulations (e.g., HIPAA) as well as customer service level agreements (SLA).
77
Actors’ Roles (…)
▪ Cloud Carrier:
▪ An intermediary that provides connectivity and transport of cloud services from
Cloud Providers to Cloud Consumers.
▪ Meetings constraints and SLAs
▪ Bridging the gap between networking and datacenters
▪ Securing communications among cloud actors (e.g., encrypting connections
between consumers and providers)
▪ Offering applications flexibility (centralized or decentralized)
78
Actors’ Roles (…)
▪ Regulators:
▪ The entities that ensure organizations are in compliance with the
regulatory framework. These can be government agencies,
certification bodies, or parties to a contract.
79
Architectural Components
▪ Service Deployment: public, private, community and hybrid.
▪ Service Orchestration: the composition of system components to support the
cloud providers activities.
▪ Arrangement, coordination and management of computing resources.
▪ Three layers: service layer, resource abstraction and control layer and physical resource layer
▪ Cloud Service Management: service-related functions that are necessary for the
management and operation of those services required by cloud consumers.
80
Architectural Components (…)
▪ Security: Cloud Computing systems need to address security requirements:
▪ Authentication, authorization, availability, confidentiality,
▪ identity management, integrity, audit, security monitoring,
▪ incident response, and security policy management.
▪ Security spans across all layers of the reference model, ranging from physical security to
application security.
▪ Security is not only under the responsibility of cloud providers, but also cloud
consumer, cloud carrier, cloud broker (if they are involved).
▪ Cloud auditor: audit and report security of cloud computing architecture and actors involved.
81
Architectural Components (…)
▪ Privacy: Effective and Secure collection, processing, communication, use and
disposition of personal information and personally identifiable information in the
cloud should be provided.
The involved parties/actors in cloud-based solutions are, in general, trusted and
assumed to access, manage, and share users’ information as envisioned.
Data breaches could occur
The confidential information could end-up being disclosed
The sensitive data could be accessed by malicious/criminal minded users.
82
Conclusion
83