From regulatory obligations to enforceable accountability policies in the cloud

  • Walid Benghabrit
  • , Hervé Grall
  • , Jean Claude Royer
  • , Mohamed Sellami
  • , Monir Azraoui
  • , Kaoutar Elkhiyaoui
  • , Melek Önen
  • , Anderson Santana De Oliveira
  • , Karin Bernsmed

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

The widespread adoption of the cloud model for service delivery triggered several data protection issues. As a matter of fact, the proper delivery of these services typically involves sharing of personal/ business data between the different parties involved in the service provisioning. In order to increase cloud consumer’s trust, there must be guarantees on the fair use of their data. Accountability provides the necessary assurance about the data governance practices to the different stakeholders involved in a cloud service chain. In this context, we propose a framework for the representation of accountability policies. Such policies offer to end-users a clear view of the privacy and accountability clauses asserted by the entities they interact with, as well as means to represent their preferences. Our framework offers two accountability policy languages: (i) an abstract language called AAL devoted for the representation of preferences/clauses in an human readable fashion, and (ii) a concrete one for the implementation of enforceable policies.

Original languageEnglish
Title of host publicationCloud Computing and Services Sciences - International Conference in Cloud Computing and Services Sciences, CLOSER 2014, Revised Selected Papers
EditorsMarkus Helfert, Frédéric Desprez, Donald Ferguson, Frank Leymann, Víctor Méndez Muñoz
PublisherSpringer Verlag
Pages134-150
Number of pages17
ISBN (Print)9783319254135
DOIs
Publication statusPublished - 1 Jan 2015
Externally publishedYes
EventInternational Conference in Cloud Computing and Services Sciences, CLOSER 2014 - Barcelona, Spain
Duration: 3 Apr 20145 Apr 2014

Publication series

NameCommunications in Computer and Information Science
Volume512
ISSN (Print)1865-0929

Conference

ConferenceInternational Conference in Cloud Computing and Services Sciences, CLOSER 2014
Country/TerritorySpain
CityBarcelona
Period3/04/145/04/14

Keywords

  • Accountability
  • Data protection
  • Framework
  • Policy enforcement
  • Policy language

Fingerprint

Dive into the research topics of 'From regulatory obligations to enforceable accountability policies in the cloud'. Together they form a unique fingerprint.

Cite this