Trust management, privacy, authorization, and authentication in cloud computing environments
Διαχείριση εμπιστοσύνης, ιδιωτικότητα, εξουσιοδότηση και αυθεντικοποίηση σε νεφοϋπολογιστικά περιβάλλοντα
Doctoral Thesis
Author
Γεωργιοπούλου, Ζαφειρούλα
Georgiopoulou, Zafeiroula
Date
2022-07View/ Open
Keywords
Νεφελώδης υπολογιστική ; Μοντέλα εμπιστοσύνης ; Μετρική εμπιστοσύνης ; Ιδιωτικότητα ; Προσωπικά δεδομέναAbstract
This thesis deals with cloud computing security in terms of trust, privacy and authentication. In cloud computing environments, successful trust management can compensate the countermeasures that have been adopted for mitigating the security and privacy risks that the cloud comes across. This thesis proposes a trust model that is taking into account specific parameters. These parameters are presented together with a detailed analysis of how, each of them, could be applied/utilized by the trust model for quantifying the trust of the cloud providers to their users. In the context of finding measures to eliminate the risks, the factors that affect the trust of the cloud provider to the users were defined and a corresponding trust model with the respective metrics was developed. The model was simulated in the environment of a university. This thesis also analyzes how a cloud computing service provider will achieve compliance with the General Data Protection Regulation (GDPR) by proposing technical and organizational measures. Furthermore, this thesis is endeavoring to assist organizations to protect the privacy of their users and the security of the data that they store and process. Users may be the customers of the organization (people using the offered services) or the employees (users who operate the systems of the organization). To this direction, a privacy impact assessment (PIA) method, that has been developed with other researchers of the Systems Security Lab, has been adopted for use by the cloud providers supporting them to explicitly take into account the specific organizational characteristics.