Towards Tracking Data Flows in Cloud Architectures

07/10/2020
by   Immanuel Kunz, et al.
0

As cloud services become central in an increasing number of applications, they process and store more personal and business-critical data. At the same time, privacy and compliance regulations such as GDPR, the EU ePrivacy regulation, PCI, and the upcoming EU Cybersecurity Act raise the bar for secure processing and traceability of critical data. Especially the demand to provide information about existing data records of an individual and the ability to delete them on demand is central in privacy regulations. Common to these requirements is that cloud providers must be able to track data as it flows across the different services to ensure that it never moves outside of the legitimate realm, and it is known at all times where a specific copy of a record that belongs to a specific individual or business process is located. However, current cloud architectures do neither provide the means to holistically track data flows across different services nor to enforce policies on data flows. In this paper, we point out the deficits in the data flow tracking functionalities of major cloud providers by means of a set of practical experiments. We then generalize from these experiments introducing a generic architecture that aims at solving the problem of cloud-wide data flow tracking and show how it can be built in a Kubernetes-based prototype implementation.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
03/09/2022

Getting Critical: Making Sense of the EU Cybersecurity Framework for Cloud Providers

In this chapter, we review how the EU cybersecurity regulatory framework...
research
03/10/2020

IoT Expunge: Implementing Verifiable Retention of IoT Data

The growing deployment of Internet of Things (IoT) systems aims to ease ...
research
06/02/2020

Securing Your Collaborative Jupyter Notebooks in the Cloud using Container and Load Balancing Services

Jupyter has become the go-to platform for developing data applications b...
research
04/19/2023

Visualising Personal Data Flows: Insights from a Case Study of Booking.com

Commercial organisations are holding and processing an ever-increasing a...
research
02/10/2018

Same Same, but Different: A Descriptive Differentiation of Intra-cloud Iaas Services

Users of cloud computing are overwhelmed with choice, even within the se...
research
08/19/2022

Globus Automation Services: Research process automation across the space-time continuum

Research process automation–the reliable, efficient, and reproducible ex...

Please sign up or login with your details

Forgot password? Click here to reset