Skip to main content

On Location-determined Cloud Management for Legally Compliant Outsourcing

  • Conference paper
  • First Online:
ISSE 2015

Abstract

When organisations are outsourcing their data processing to clouds, the cloud providers have to support them in achieving legal compliance. This is particular challenging in globally distributed clouds where the data centres are located in multiple countries with different legislation. Here, the cloud providers have to implement technical constraints based on the legal requirements which apply individually for each cloud customer. In this paper, the legal requirements of cloud customers and their corresponding technical constraints are modelled in a technically decidable and enforceable manner, using information flow control in virtual resource management, and a solution to implement the support of legal requirements in cloud environments is proposed. The solution proposed covers the translation of legal requirements of cloud customers into technical security policies which are applied in virtual resource management of clouds. For these purposes an information model, denoted as the Cloud Security Matrix, is defined using the methods of information flow control. In the model, cloud resources (virtual and hardware) are classified and the allowed information flows are defined. The information model is capable to express both location and security constraints including authenticity, integrity and availability. The technical feasibility of a location-based assignment of virtual resources is shown in a proof-of-concept implementation based on OpenStack.

This is a preview of subscription content, log in via an institution to check access.

Access this chapter

Chapter
USD 29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
eBook
USD 39.99
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book
USD 54.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Institutional subscriptions

Preview

Unable to display preview. Download preview PDF.

Unable to display preview. Download preview PDF.

Author information

Authors and Affiliations

Authors

Corresponding authors

Correspondence to Bernhard Doll , Dirk Emmerich , Ralph Herkenhöner , Ramona Kühn or Hermann de Meer .

Editor information

Editors and Affiliations

Rights and permissions

Reprints and permissions

Copyright information

© 2015 Springer Fachmedien Wiesbaden

About this paper

Cite this paper

Doll, B., Emmerich, D., Herkenhöner, R., Kühn, R., de Meer, H. (2015). On Location-determined Cloud Management for Legally Compliant Outsourcing. In: Reimer, H., Pohlmann, N., Schneider, W. (eds) ISSE 2015. Springer Vieweg, Wiesbaden. https://doi.org/10.1007/978-3-658-10934-9_6

Download citation

  • DOI: https://doi.org/10.1007/978-3-658-10934-9_6

  • Published:

  • Publisher Name: Springer Vieweg, Wiesbaden

  • Print ISBN: 978-3-658-10933-2

  • Online ISBN: 978-3-658-10934-9

  • eBook Packages: Computer ScienceComputer Science (R0)

Publish with us

Policies and ethics