Skip to main content

A Brokerage Approach for Secure Multi-Cloud Storage Resource Management

  • Conference paper
  • First Online:
Security and Privacy in Communication Networks (SecureComm 2020)

Abstract

Nowadays, more cloud customers are utilizing multiple cloud service providers (CSPs) to store their data in the cloud as it provides better data availability and service reliance than storing in the single CSP. However, there are several challenges faced by cloud customers to securely manage their cloud storage resources for cloud end-users (a user or a service) in the multi-cloud scenario, such as diverse APIs and service implementations in multiple CSP as CSP is not required to comply with cloud computing standards and multi-cloud resource management skill gap. In this paper, we present a unified multi-cloud storage resource management framework for managing cloud storage resources and their configurations for Object Storage and Identity and Access Management services following the cloud brokerage approach. We propose a unified cloud storage resource model continuing our previous work to tackle the various data and cloud access control models of cloud storage resources in multiple CSPs. Based on the unified model, we introduce a unified multi-cloud storage resource management platform to manage cloud storage resources and grant/revoke access for the cloud end-user developed for two popular public CSPs: Amazon Web Services and Google Cloud. The unified platform collects and processes information about the cloud storage resources that allows cloud customers to discover, create, delete, modify, evaluate, and monitor cloud storage resources across various CSPs.

This is a preview of subscription content, log in via an institution to check access.

Access this chapter

Chapter
USD 29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
eBook
USD 39.99
Price excludes VAT (USA)
  • Available as EPUB and PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book
USD 54.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Institutional subscriptions

Notes

  1. 1.

    https://aws.amazon.com/.

  2. 2.

    https://cloud.google.com/.

  3. 3.

    https://www.cisecurity.org/cis-benchmarks/.

  4. 4.

    https://jclouds.apache.org/.

  5. 5.

    https://libcloud.apache.org/.

  6. 6.

    https://aws.amazon.com/s3/.

  7. 7.

    https://aws.amazon.com/iam/.

  8. 8.

    https://cloud.google.com/storage/.

  9. 9.

    https://cloud.google.com/iam/.

  10. 10.

    https://cloud.google.com/resource-manager/.

  11. 11.

    https://docs.aws.amazon.com/en_pv/AmazonS3/latest/dev/UsingBucket.html.

  12. 12.

    https://cloud.google.com/storage/docs/json_api/v1/buckets.

  13. 13.

    https://docs.aws.amazon.com/en_pv/AmazonS3/latest/dev/UsingObjects.html.

  14. 14.

    https://cloud.google.com/storage/docs/json_api/v1/objects.

  15. 15.

    https://docs.aws.amazon.com/en_pv/IAM/latest/UserGuide/id_users.html.

  16. 16.

    https://cloud.google.com/iam/docs/service-accounts.

  17. 17.

    https://docs.aws.amazon.com/en_pv/IAM/latest/UserGuide/reference_policies_actions-resources-contextkeys.html.

  18. 18.

    https://cloud.google.com/storage/docs/access-control/using-iam-permissions.

  19. 19.

    https://docs.aws.amazon.com/en_pv/IAM/latest/UserGuide/access_policies.html.

  20. 20.

    https://cloud.google.com/iam/docs/understanding-roles.

  21. 21.

    https://docs.aws.amazon.com/AmazonS3/latest/dev/acl-overview.html.

  22. 22.

    https://cloud.google.com/storage/docs/access-control/lists.

  23. 23.

    https://docs.aws.amazon.com/AmazonS3/latest/dev/ServerLogs.html.

  24. 24.

    https://cloud.google.com/storage/docs/access-logs.

  25. 25.

    https://docs.aws.amazon.com/en_pv/IAM/latest/UserGuide/id_credentials_access-keys.html.

  26. 26.

    https://cloud.google.com/iam/docs/creating-managing-service-account-keys.

  27. 27.

    https://www.cisecurity.org/benchmark/amazon_web_services/.

  28. 28.

    https://aws.amazon.com/cloudtrail/.

  29. 29.

    https://cloud.google.com/logging, formerly Google Cloud Stackdriver.

  30. 30.

    https://docs.aws.amazon.com/awscloudtrail/latest/userguide/view-cloudtrail-events.html.

  31. 31.

    https://aws.amazon.com/cloudtrail/faqs.

  32. 32.

    https://cloud.google.com/logging/docs/export/using_exported_logs.

  33. 33.

    https://www.terraform.io/.

  34. 34.

    https://www.chef.io.

References

  1. Amazon Web Services: Shared responsibility model. https://aws.amazon.com/compliance/shared-responsibility-model/ (2020). (Accessed 14 July 2020)

  2. Bohli, J.M., Gruschka, N., Jensen, M., Iacono, L.L., Marnau, N.: Security and privacy-enhancing multicloud architectures. IEEE Trans. Dependable Secure Comput. 10(4), 212–224 (2013)

    Article  Google Scholar 

  3. Cloud Security Alliance: Top threats to cloud computing: The egregious 11 (2019). https://cloudsecurityalliance.org/download/artifacts/top-threats-to-cloud-computing-egregious-eleven/

  4. Elango, D.M., Fowley, F., Pahl, C.: An ontology-based architecture for an adaptable cloud storage broker. In: Mann, Z.Á., Stolz, V. (eds.) ESOCC 2017. CCIS, vol. 824, pp. 86–101. Springer, Cham (2018). https://doi.org/10.1007/978-3-319-79090-9_6

    Chapter  Google Scholar 

  5. Factor, M., et al.: Secure logical isolation for multi-tenancy in cloud storage. In: 2013 IEEE 29th Symposium on Mass Storage Systems and Technologies (MSST), pp. 1–5. IEEE (2013)

    Google Scholar 

  6. Heilig, L., Lalla-Ruiz, E., Voß, S.: A cloud brokerage approach for solving the resource management problem in multi-cloud environments. Comput. Ind. Eng. 95, 16–26 (2016)

    Article  Google Scholar 

  7. Hill, Z., Humphrey, M.: Csal: a cloud storage abstraction layer to enable portable cloud applications. In: 2010 IEEE Second International Conference on Cloud Computing Technology and Science, pp. 504–511. IEEE (2010)

    Google Scholar 

  8. Hu, H., Wen, Y., Chua, T.S., Li, X.: Toward scalable systems for big data analytics: a technology tutorial. IEEE Access 2, 652–687 (2014)

    Article  Google Scholar 

  9. Jennings, B., Stadler, R.: Resource management in clouds: survey and research challenges. J. Netw. Syst. Manage. 23(3), 567–619 (2015)

    Article  Google Scholar 

  10. Krotsiani, M., Spanoudakis, G.: Continuous certification of non-repudiation in cloud storage services. In: 2014 IEEE 13th International Conference on Trust, Security and Privacy in Computing and Communications, pp. 921–928. IEEE (2014)

    Google Scholar 

  11. Lee, C.A.: Cloud federation management and beyond: requirements, relevant standards, and gaps. IEEE Cloud Comput. 3(1), 42–49 (2016)

    Article  Google Scholar 

  12. Liaqat, M., et al.: Federated cloud resource management: review and discussion. J. Netw. Comput. Appl. 77, 87–105 (2017)

    Article  Google Scholar 

  13. Mansouri, Y., Toosi, A.N., Buyya, R.: Data storage management in cloud environments: taxonomy, survey, and future directions. ACM Comput. Surv. (CSUR) 50(6), 91 (2018)

    Article  Google Scholar 

  14. Nachiappan, R., Javadi, B., Calheiros, R.N., Matawie, K.M.: Cloud storage reliability for big data applications: a state of the art survey. J. Netw. Comput. Appl. 97, 35–47 (2017)

    Article  Google Scholar 

  15. Newton, C.: How a typo took down s3, the backbone of the internet - the verge. https://www.theverge.com/2017/3/2/14792442/amazon-s3-outage-cause-typo-internet-server (2017). (Accessed on 7 August 2020)

  16. Petcu, D.: Multi-cloud: expectations and current approaches. In: Proceedings of the 2013 international workshop on Multi-cloud applications and federated clouds, pp. 1–6 (2013)

    Google Scholar 

  17. Rafique, A., Van Landuyt, D., Reniers, V., Joosen, W.: Towards an adaptive middleware for efficient multi-cloud data storage. In: Proceedings of the 4th Workshop on CrossCloud Infrastructures & Platforms, pp. 1–6 (2017)

    Google Scholar 

  18. Raj, P., Raman, A.: Multi-cloud management: technologies, tools, and techniques. Software-Defined Cloud Centers. CCN, pp. 219–240. Springer, Cham (2018). https://doi.org/10.1007/978-3-319-78637-7_10

    Chapter  Google Scholar 

  19. Schnjakin, M., Korsch, D., Schoenberg, M., Meinel, C.: Implementation of a secure and reliable storage above the untrusted clouds. In: Computer Science & Education (ICCSE), 2013 8th International Conference on, pp. 347–353. IEEE (2013)

    Google Scholar 

  20. Sukmana, M.I., Torkura, K.A., Cheng, F., Meinel, C., Graupner, H.: Unified logging system for monitoring multiple cloud storage providers in cloud storage broker. In: 2018 International Conference on Information Networking (ICOIN), pp. 44–49. IEEE (2018)

    Google Scholar 

  21. Sukmana, M.I., Torkura, K.A., Graupner, H., Cheng, F., Meinel, C.: Unified cloud access control model for cloud storage broker. In: 2019 International Conference on Information Networking (ICOIN), pp. 60–65. IEEE (2019)

    Google Scholar 

  22. Takabi, H., Joshi, J.B., Ahn, G.J.: Security and privacy challenges in cloud computing environments. IEEE Security & Privacy 8(6), 24–31 (2010)

    Article  Google Scholar 

  23. Toosi, A.N., Calheiros, R.N., Buyya, R.: Interconnected cloud computing environments: challenges, taxonomy, and survey. ACM Comput. Surv. (CSUR) 47(1), 1–47 (2014)

    Article  Google Scholar 

  24. Torkura, K.A., Sukmana, M.I., Cheng, F., Meinel, C.: Slingshot-automated threat detection and incident response in multi cloud storage systems. In: 2019 IEEE 18th International Symposium on Network Computing and Applications (NCA), pp. 1–5. IEEE (2019)

    Google Scholar 

  25. Torkura, K.A., Sukmana, M.I., Strauss, T., Graupner, H., Cheng, F., Meinel, C.: Csbauditor: proactive security risk analysis for cloud storage broker systems. In: 2018 IEEE 17th International Symposium on Network Computing and Applications (NCA), pp. 1–10. IEEE (2018)

    Google Scholar 

  26. Varghese, B., Buyya, R.: Next generation cloud computing: new trends and research directions. Future Gener. Comput. Syst. 79, 849–861 (2018)

    Article  Google Scholar 

Download references

Author information

Authors and Affiliations

Authors

Corresponding author

Correspondence to Muhammad Ihsan Haikal Sukmana .

Editor information

Editors and Affiliations

Rights and permissions

Reprints and permissions

Copyright information

© 2020 ICST Institute for Computer Sciences, Social Informatics and Telecommunications Engineering

About this paper

Check for updates. Verify currency and authenticity via CrossMark

Cite this paper

Sukmana, M.I.H., Torkura, K.A., Prasetyo, S.D.S., Cheng, F., Meinel, C. (2020). A Brokerage Approach for Secure Multi-Cloud Storage Resource Management. In: Park, N., Sun, K., Foresti, S., Butler, K., Saxena, N. (eds) Security and Privacy in Communication Networks. SecureComm 2020. Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering, vol 336. Springer, Cham. https://doi.org/10.1007/978-3-030-63095-9_6

Download citation

  • DOI: https://doi.org/10.1007/978-3-030-63095-9_6

  • Published:

  • Publisher Name: Springer, Cham

  • Print ISBN: 978-3-030-63094-2

  • Online ISBN: 978-3-030-63095-9

  • eBook Packages: Computer ScienceComputer Science (R0)

Publish with us

Policies and ethics