网络与信息安全学报 (Oct 2016)

Cloud Trustworthiness Evaluation as a cloud service:architecture,key technologies and implementations

  • Chuan-yi LIU,
  • He-zhong PAN,Guo-feng WANG,
  • Lu-lu LIANG,
  • Bin-xing FANG

DOI
https://doi.org/10.11959/j.issn.2096-109x.2016.00102
Journal volume & issue
Vol. 2, no. 10
pp. 36 – 47

Abstract

Read online

A "big clouds audited by a small cloud" scheme was proposed,by introducing an independent trusted third party (TTP) dealing with run-time data collection,verification,audit and evaluation remotely,in a continuous and data-driven model,compared with traditionally certification based audit.The TTP mainly adopts data flow visualization,data monitoring and encryption to protect the rights of users.It provides the basis for users to choose a trusted cloud platform and for cloud platform to prove own trusted credentials.In-depth study,the following key technologies were broken through:1) the introduction of an independent trusted third party as an intermediate layer between cloud platform and users as well as administrators; 2) continuous,real-time remote data collection and data analysis; 3) strong non-intrusive evidence gathering.

Keywords