Multi-cloud applications: data and code fragmentation for improved security

被引:3
|
作者
Lovrencic, Rudolf [1 ]
Skvorc, Dejan [1 ]
机构
[1] Univ Zagreb, Fac Elect Engn & Comp, Zagreb, Croatia
关键词
Distributed applications; Distributed databases; Cloud computing; Security and privacy; ENCRYPTION;
D O I
10.1007/s10207-022-00658-8
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
When deciding against outsourcing their data to the cloud, organizations often point to security as the primary reason. If cloud is not used as a passive storage only, but rather both the data and the code required for their processing are being outsourced, then the data privacy may get compromised in two ways: (i) in the storage if not being encrypted and (ii) during the processing through various execution-level attacks. Encrypting the data before outsourcing enhances their security while in the storage, but disables their processing in the cloud. On the other hand, if a cloud has the ability to decrypt the data before processing, then they remain vulnerable during the execution. In this paper, we present a paradigm for outsourcing both the data and the code to the cloud in a way that preserves data privacy, while still enabling their processing outside the organization. The paradigm leverages constraint-based data and code fragmentation and deploys these fragments to multiple independent computer clouds. We introduce several architectural patterns for secure computation in a multi-cloud environment, demonstrate the paradigm use, and examine introduced performance penalty on a simple application.
引用
收藏
页码:713 / 721
页数:9
相关论文
共 50 条
  • [1] Multi-cloud applications: data and code fragmentation for improved security
    Rudolf Lovrenčić
    Dejan Škvorc
    International Journal of Information Security, 2023, 22 : 713 - 721
  • [2] Multi-cloud Applications Security Monitoring
    Carvallo, Pamela
    Cavalli, Ana R.
    Mallouli, Wissam
    Rios, Erkuden
    GREEN, PERVASIVE, AND CLOUD COMPUTING (GPC 2017), 2017, 10232 : 748 - 758
  • [3] A Platform for Security Monitoring of Multi-cloud Applications
    Carvallo, Pamela
    Cavalli, Ana R.
    Mallouli, Wissam
    PERSPECTIVES OF SYSTEM INFORMATICS, PSI 2017, 2018, 10742 : 59 - 71
  • [4] Security Risk Optimization for Multi-cloud Applications
    Lovrencic, Rudolf
    Jakobovic, Domagoj
    Skvorc, Dejan
    Gros, Stjepan
    APPLICATIONS OF EVOLUTIONARY COMPUTATION, EVOAPPLICATIONS 2020, 2020, 12104 : 659 - 669
  • [5] Combined Security Framework for Multi-Cloud Environment
    Aditya, Suresh Kumar
    Premkumar, Kavya
    Anitha, R.
    Mukherjee, Saswati
    2014 9TH INTERNATIONAL CONFERENCE FOR INTERNET TECHNOLOGY AND SECURED TRANSACTIONS (ICITST), 2014, : 100 - 105
  • [6] Hybrid Multi-Cloud Data Security (HMCDS) Model and Data Classification
    Zardari, Munwar Ali
    Jung, Low Tang
    Zakaria, Mohamed Nordin B.
    2013 INTERNATIONAL CONFERENCE ON ADVANCED COMPUTER SCIENCE APPLICATIONS AND TECHNOLOGIES (ACSAT), 2014, : 166 - 171
  • [7] Simultaneous Ammunition for the Data Security and Privacy in the Multi-Cloud Computing
    Bhadlawala, Sunny
    Srivastava, S. S.
    2017 INTERNATIONAL CONFERENCE ON CURRENT TRENDS IN COMPUTER, ELECTRICAL, ELECTRONICS AND COMMUNICATION (CTCEEC), 2017, : 442 - 446
  • [8] Ensemble Security and Multi-Cloud Load Balancing for Data in Edge-based Computing Applications
    Dornala, Raghunadha Reddi
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2023, 14 (08) : 7 - 13
  • [9] Innovative model for security of multi-cloud platform: data integrity perspective
    Jebakumari, S. Adlin
    Mahajan, Shriya
    Raichura, Harshit
    Nisha, B.
    Reddy, B.
    Ahmed, Zahid
    INTERNATIONAL JOURNAL OF SYSTEM ASSURANCE ENGINEERING AND MANAGEMENT, 2024,
  • [10] A framework for evaluating security in multi-cloud environments
    Afolaranmi, Samuel Olaiya
    Ferrer, Borja Ramis
    Lastra, Jose Luis Martinez
    IECON 2018 - 44TH ANNUAL CONFERENCE OF THE IEEE INDUSTRIAL ELECTRONICS SOCIETY, 2018, : 3059 - 3066