Perspectives on Cloud Computing and Standards. Peter Mell, Tim Grance NIST, Information Technology Laboratory



Similar documents
Perspectives on Moving to the Cloud Paradigm and the Need for Standards. Peter Mell, Tim Grance NIST, Information Technology Laboratory

Perspectives on Cloud Computing and Standards. Peter Mell, Tim Grance NIST, Information Technology Laboratory

The NIST Definition of Cloud Computing (Draft)

The NIST Definition of Cloud Computing

Cloud Computing and Security Risk Analysis Qing Liu Technology Architect STREAM Technology Lab

Cloud Computing. Course: Designing and Implementing Service Oriented Business Processes

Security & Trust in the Cloud

ITL BULLETIN FOR JUNE 2012 CLOUD COMPUTING: A REVIEW OF FEATURES, BENEFITS, AND RISKS, AND RECOMMENDATIONS FOR SECURE, EFFICIENT IMPLEMENTATIONS

Cloud Computing Submitted By : Fahim Ilyas ( ) Submitted To : Martin Johnson Submitted On: 31 st May, 2009

The Hybrid Cloud: Bringing Cloud-Based IT Services to State Government

OWASP Chapter Meeting June Presented by: Brayton Rider, SecureState Chief Architect


Architecting the Cloud

Cloud Computing; What is it, How long has it been here, and Where is it going?

CHAPTER 8 CLOUD COMPUTING

IS PRIVATE CLOUD A UNICORN?

CLOUD SECURITY SECURITY ASPECTS IN GEOSPATIAL CLOUD. Guided by Prof. S. K. Ghosh Presented by - Soumadip Biswas

See Appendix A for the complete definition which includes the five essential characteristics, three service models, and four deployment models.

The Magical Cloud. Lennart Franked. Department for Information and Communicationsystems (ICS), Mid Sweden University, Sundsvall.

Cloud Computing. IST 501 Fall Dongwon Lee, Ph.D.

Effectively and Securely Using the Cloud Computing Paradigm. Peter Mell, Tim Grance NIST, Information Technology Laboratory

INTRODUCTION TO CLOUD COMPUTING CEN483 PARALLEL AND DISTRIBUTED SYSTEMS

Clo l ud d C ompu p tin i g

VMware vcloud Powered Services

A Cloud Computing Handbook for Business

Cloud definitions you've been pretending to understand. Jack Daniel, Reluctant CISSP, MVP Community Development Manager, Astaro

Flying into the Cloud: Do You Need a Navigator? Services. Colin R. Chasler Vice President Solutions Architecture Dell Services Federal Government

A Study on Analysis and Implementation of a Cloud Computing Framework for Multimedia Convergence Services

Cloud computing: the state of the art and challenges. Jānis Kampars Riga Technical University

Capability Paper. Today, aerospace and defense (A&D) companies find

Strategies for Secure Cloud Computing

Topics. Images courtesy of Majd F. Sakr or from Wikipedia unless otherwise noted.

White Paper on CLOUD COMPUTING

Cloud Computing: The Next Computing Paradigm

Cloud Computing For Distributed University Campus: A Prototype Suggestion

Cloud Computing An Elephant In The Dark

IT Risk and Security Cloud Computing Mike Thomas Erie Insurance May 2011

Lecture 02a Cloud Computing I

Running head: TAKING A DEEPER LOOK AT THE CLOUD: SOLUTION OR 1

Cloud Computing and Standards

Federal Cloud Computing Initiative Overview

CLOUD COMPUTING. A Primer

Security Issues in Cloud Computing

Private Cloud 201 How to Build a Private Cloud

BUSINESS MANAGEMENT SUPPORT

CSO Cloud Computing Study. January 2012

Table of Contents. Abstract... Error! Bookmark not defined. Chapter 1... Error! Bookmark not defined. 1. Introduction... Error! Bookmark not defined.

Why Private Cloud? Nenad BUNCIC VPSI 29-JUNE-2015 EPFL, SI-EXHEB

NATO s Journey to the Cloud Vision and Progress

Future of Cloud Computing. Irena Bojanova, Ph.D. UMUC, NIST

A Survey on Cloud Security Issues and Techniques

Business Intelligence (BI) Cloud. Prepared By: Pavan Inabathini

Cloud Computing and Government Services August 2013 Serdar Yümlü SAMPAŞ Information & Communication Systems

CHOOSING THE RIGHT CLOUD COMPUTING SOLUTION FOR YOU

East African Information Conference th August, 2013, Kampala, Uganda. Security and Privacy: Can we trust the cloud?

What is Cloud Computing? First, a little history. Demystifying Cloud Computing. Mainframe Era ( ) Workstation Era ( ) Xerox Star 1981!

Effectively and Securely Using the Cloud Computing Paradigm. Peter Mell, Tim Grance NIST, Information Technology Laboratory

Cloud Manufacturing Olena Skarlat

A Strawman Model. NIST Cloud Computing Reference Architecture and Taxonomy Working Group. January 3, 2011

Security Considerations for Public Mobile Cloud Computing

Getting Familiar with Cloud Terminology. Cloud Dictionary

Interoperability & Portability for Cloud Computing: A Guide.

Cloud Computing in the Federal Sector: What is it, what to worry about, and what to negotiate.

Architectural Implications of Cloud Computing

Virtualization Technologies in SCADA/EMS/DMS/OMS. Vendor perspective Norman Sabelli Ventyx, an ABB company

What Is It? Business Architecture Research Challenges Bibliography. Cloud Computing. Research Challenges Overview. Carlos Eduardo Moreira dos Santos

ITSM in the Cloud. An Overview of Why IT Service Management is Critical to The Cloud. Presented By: Rick Leopoldi RL Information Consulting LLC

LEGAL ISSUES IN CLOUD COMPUTING

OVERVIEW Cloud Deployment Services

Essential Characteristics of Cloud Computing: On-Demand Self-Service Rapid Elasticity Location Independence Resource Pooling Measured Service

Cloud Security considerations for business adoption. Ricci IEONG CSA-HK&M Chapter

Tutorial on Client-Server Architecture

Improving IT Service Management Architecture in Cloud Environment on Top of Current Frameworks

Enhancing Operational Capacities and Capabilities through Cloud Technologies

How To Understand Cloud Computing

Cloud Computing in the Enterprise An Overview. For INF 5890 IT & Management Ben Eaton 24/04/2013

TECHNOLOGY GUIDE THREE. Emerging Types of Enterprise Computing

Cloud Computing in the Czech Republic

Cloud Glossary. A Guide to Commonly Used Terms in Cloud Computing

Cloud Computing and Software Agents: Towards Cloud Intelligent Services

OIT Cloud Strategy 2011 Enabling Technology Solutions Efficiently, Effectively, and Elegantly

journey to a hybrid cloud

AskAvanade: Answering the Burning Questions around Cloud Computing

Cloud Computing Technology

The Trend and Challenges of Cloud Computing: A Literature Review

Transcription:

Perspectives on Cloud Computing and Standards Peter Mell, Tim Grance NIST, Information Technology Laboratory

Caveats and Disclaimers This presentation provides education on cloud technology and its benefits to set up a discussion of cloud security It is NOT intended to provide official NIST guidance and NIST does not make policy Any mention of a vendor or product is NOT an endorsement or recommendation Citation Note: All sources for the material in this presentation are included within the Powerpoint notes field on each slide 2

3 NIST Cloud Research Team Peter Mell Project Lead 301-975-5572 peter.mell@nist.gov Tim Grance Program Manager 301-975-4242 grance@nist.gov Lee Badger 301-975-3176 mark.badger@nist.gov Erika McCallister 301-975-5144 erika.mccallister@nist.gov Karen Scarfone 301-975-8136 karen.scarfone@nist.gov

A Perspective on Cloud Computing and Standards Cloud computing is a convergence of many technologies Some have their own standards This convergence combined with massively scaled deployments represents revolutionary capabilities We have a choice Proprietary stovepipe clouds Development of an expensive cloud integration market Standards based clouds Standards are necessary to achieve full adoption and to reap the full economic benefits 4

5 Cloud Standards: Concerns Major concerns to be addressed by standards: Vendor lock-in Limitations of developing for proprietary models and APIs Lack of cloud integration Proprietary integration with internal data centers

6 Cloud Standards: Needed focus Needed focus of standards: Standardized cloud control interfaces Payment systems Processing Application hosting Storage Security service / Logging Cloud application and workload portability

7 So where are we? Today cloud specific standards don t exist Good vendor APIs (e.g., cloud interfaces) and protocols (e.g., for virtualization and application mobility) Some patents are held in this space Standards from participating technologies don t solve the problem (e.g., GRID, SOA/WS) Cloud computing will progress without standards Possible resulting scenarios Standards may take years to develop A single vendor could dominate and everyone integrates with them Cloud integration vendors may ease problem

8 Hurdles to Standardization Hurdle 1: Many organizations embarking on standards creation Lack of large formal standards bodies Need balanced representation of interests Hurdle 2: Over specification inhibits innovation Hurdle 3: Many models of cloud computing Need a definition and to work on standards for particular models Hurdle 4: Patents and intellectual property Will vendors give their cloud APIs and protocols to the community?

9 Solutions for Industry 1: Work together on complementary standards 2: Agree on the models of cloud computing that will be the focus of specific standards 3: Collaborate on identifying a minimal subset for standardization 4: Avoid using patents to inhibit the progress of standards Everyone will benefit as the cloud computing industry grows

10 A idea: The Cloud Interoperability Profile We need to define minimal standards Enable cloud integration, application portability, and data portability Avoid over specification that will inhibit innovation Could there be a blueprint for cloud design? Cloud Interoperability Profile (CIP) Specifies versions of standards Separately addresses different cloud models Example: WS-I Basic Profile for SOA

11 A Working Definition of Cloud Computing Cloud computing is a pay-per-use model for enabling convenient, on-demand network access to a shared pool of configurable and reliable computing resources (e.g., networks, servers, storage, applications, services) that can be rapidly provisioned and released with minimal consumer management effort or service provider interaction. The cloud model is comprised of five key characteristics, three delivery models, and four deployment models.

12 5 Key Cloud Characteristics On-demand self-service Ubiquitous network access Resource pooling Rapid elasticity Pay per use

13 3 Cloud Delivery Models Cloud Software as a Service (SaaS) Use provider s applications over a network Cloud Platform as a Service (PaaS) Deploy customer-created applications to a cloud Cloud Infrastructure as a Service (IaaS) Rent processing, storage, network capacity, and other fundamental computing resources To be considered cloud they must be deployed on top of cloud infrastructure that enables the key characteristics

14 4 Cloud Deployment Models Private cloud enterprise owned or leased Community cloud shared infrastructure for specific community Public cloud Sold to the public, mega-scale infrastructure Hybrid cloud composition of two or more clouds Two types: internal and external

15 Common Cloud Characteristics Cloud computing often leverages: Massive scale Virtualization Free software Autonomic computing Multi-tenancy Geographically distributed systems Advanced security technologies

16 Foundational Elements of Cloud Computing Primary Technologies Virtualization Grid technology Service Oriented Architectures Distributed Computing Broadband Networks Browser as a platform Free and Open Source Software Other Technologies and Important Issues Autonomic Systems Web application frameworks Service Level Agreements Patents/Intellectual Property Role of data location

17 Migration Paths for Cloud Adoption Use public clouds Option 1: as is with multi-tenancy Option 2: no multi-tenancy of servers or storage + enhanced organization defined security Develop private clouds Procure an external private cloud Migrate data centers to be private clouds (fully virtualized) Use hybrid-cloud technology Leverage a private and public cloud architectures Workload portability between private and public clouds Build or procure community clouds

18 Planned NIST Cloud Computing Publication NIST is planning a series of publications on cloud computing NIST FY09 Special Publication What problems does cloud computing solve? What are the technical characteristics of cloud computing? How can we best leverage cloud computing and maintain or enhance security, privacy, and transparency?

19 Questions? Peter Mell NIST, Information Technology Laboratory Computer Security Division 301-975-5572 mell@nist.gov Tim Grance NIST, Information Technology Laboratory Computer Security Division 301-975-4242 grance@nist.gov