Blockchain-as-a-Service (BaaS) :: providers & trust

Slides:



Advertisements
Similar presentations
Pros and Cons of Cloud Computing Professor Kam-Fai Wong Faculty of Engineering The Chinese University of Hong Kong.
Advertisements

Cloud Computing - clearing the fog Rob Gear 8 th December 2009.
1. 2 New Computing Models, and What They Mean to the Small and Mid Sized Business Consumer How your business can make practical decisions between “The.
Securing and Auditing Cloud Computing Jason Alexander Chief Information Security Officer.
CLOUD COMPUTING. IAAS / PAAS / SAAS LAYERS. Olena Matokhina Development and Consulting Team Lead 2 ABOUT PRESENTER.
Security Framework For Cloud Computing -Sharath Reddy Gajjala.
Page  1 SaaS – BUSINESS MODEL Debmalya Khan DEBMALYA KHAN.
Presentation to the Housing Technology Conference Tim Cowland- Senior Consultant 27 th February 2014 The Rise of the Housing Cloud.
Cloud Computing Kwangyun Cho v=8AXk25TUSRQ.
Speaker: Meng-Ting Tsai Date:2010/11/25 The Information Assurance Practices of Cloud Computing Vendors IEEE Communications Society.
© 2012 IBM Corporation IBM Security Systems 1 © 2012 IBM Corporation Cloud Security: Who do you trust? Martin Borrett Director of the IBM Institute for.
Software Acquisition Management. Cloud Computing 2.
3/12/2013Computer Engg, IIT(BHU)1 CLOUD COMPUTING-1.
Cloud Architecture. SPI Model Cloud Computing Classification Model – SPI Cloud Computing Classification Model – SPI - SaaS: (Software as a Service) -
What could possibly go wrong IoT meets The Law Data Insights talk May 5, 2016, Cambridge Ian Walden Jon Crowcroft
Introduction to Enterprise Systems. Slide 2 Objectives Review the enterprise ecosystem.
CS 6027 Advanced Networking FINAL PROJECT ​. Cloud Computing KRANTHI ​ CHENNUPATI PRANEETHA VARIGONDA ​ SANGEETHA LAXMAN ​ VARUN ​ DENDUKURI.
Clouding with Microsoft Azure
When BPM meets Blockchain
Blockchain as a Service
MANAGEMENT INFORMATION SYSTEMS
Introduction to Cloud Technology
Self-enforcing and executing contracts
Chapter 6: Securing the Cloud
The Revolutionary Benefits Of Blockchain
Understanding The Cloud
Avenues International Inc.

A Blockchain Implementation
Roles and Boundaries – 1/2
By: Raza Usmani SaaS, PaaS & TaaS By: Raza Usmani
Project “Bletchley” Vision
Cloud Security– an overview Keke Chen
Tutorials of Q.8: cloud security related works in SG17
VIRTUALIZATION & CLOUD COMPUTING
IOT Critical Impact on DC Design
How DLTs might impact the financial sector
Federated IdM Across Heterogeneous Clouding Environment
Introduction to Hyperledger Fabric
Paul Woods Chair, MITIGATION: Ensuring we procure cloud services taking into account of the risks involved Paul Woods Chair, ISNorthEast.
Performance Testing Methodology for Cloud Based Applications
LEGAL & ETHICAL ISSUES InsurTech & Health Insurance Providers
AWS. Introduction AWS launched in 2006 from the internal infrastructure that Amazon.com built to handle its online retail operations. AWS was one of the.
Introduction to Enterprise Systems
Blockchain at UB B. Ramamurthy
Assessing the Security of the Cloud
Immersion Workshop Agenda
Developing a Baseline On Cloud Security Jim Reavis, Executive Director
Which blockchain? The future at a crossroad
ideas to mobile apps in record time,
GlobAL Public Procurement Conference September 2018
Cloud Computing: IT Seminar
Blockchain technology at Change Healthcare
Distributed Ledger Technology (DLT) and Blockchain
Which blockchain? The future at a crossroad
JOINED AT THE HIP: DEVSECOPS AND CLOUD-BASED ASSETS
Emerging technologies-
The Canterbury Clinical Network
Andreas Fuchsberger Current Standardisation Activities – Blockchain and Distributed Ledger Technologies Open Source Platforms.
Fundamental Concepts and Models
FST Network All Rights Reserved
Computer Science and Engineering
Data Provenance in the Additive Manufacturing (AM) Thread Additive Manufacturing Business Model Workshop Day 2 Outbrief 31 May 2018.
IT Management Services Infrastructure Services
The future of financial infrastructure An ambitious look at how blockchain can reshape financial services An Industry Project of the Financial Services.
We make your contracts work for you
Hyperledger Fabric 소개 및 튜토리얼
Cloud Computing for Wireless Networks
Presentation transcript:

Blockchain-as-a-Service (BaaS) :: providers & trust Jat Singh and Dave Michels www.jatsingh.com

Key takeaway BaaS is [increasingly] ‘a thing’ Considering security, privacy and trust? DON’T FORGET THE PROVIDER[S]! DLTs aim at improving trust---- decentralises so trust is in the netowrk. Doesn’t this preclude?

Trust [governance] considerations Overview Nature of BaaS Trust [governance] considerations Intuition about baas [ DEPENDS ]

BaaS & Cloud BaaS: the supporting infrastructure Similar to a ‘cloud’ offering Economies of scale Elasticity Expertise Security + standards Main providers [cloud, contracts] IBM (Hyperledger) Microsoft (Coco Framework [eth] ) BaaS – offers what previous talk described as a service [not ethereum etc]

Why? “Blockchain revolution” DLT applications for business >> BaaS targets this Focus: Established businesses & business networks [ experimentation ]

Modes of uptake (service models) Applications Full-stack solution oriented App with (‘some’ ledger ‘somewhere’) “Software-as-a-Service” (SaaS) Platform-oriented Select, customise, configure components “Platform-as-a-Service” (PaaS) Modular, tight platform integration Business – SaaS or PaaS. Apps dominant

Example from MS – ledger components down the bottom, integration/managemnet services higher Aspects might be confirgured (or integrated). Apps from the topdown Microsoft

Private & permissioned Private: dedicated chain Permissioned: restricted participants Current BaaS focus Established networks, data sensitivity ‘Safe’ experimentation Facilitates tenancy Why not a traditional application/database? # counterparties; autonomy, power & competition; assurance levels; disintermediation Ease of deployment? Recognition: audit is important! Initial applications focus on private/permission chains. Following the business model

Opportunities regardless BaaS-cloud business Opportunities regardless BaaS for open chains? Comes with maturity… B2B >> B2C (or C2C) [“Sharing economy”] If BaaS provider == cloud provider – opportunities all the same!!

TRUST Blockchain => disintermediation Remove trust/reliance on third parties BaaS…!? DLTs aim at improving trust---- decentralises so trust is in the netowrk. Doesn’t this preclude?

transparency & control [[ who did/can do what? ]] GOVERNANCE transparency & control [[ who did/can do what? ]] DLTs aim at improving trust---- decentralises so trust is in the netowrk. Doesn’t this preclude?

Tenancy: participant trust Cloud tenancy Provider  tenant contract Tenants configure & control services; pays… Blockchain – multi-party scenarios Ledger mediates multiple parties Tenancy in a BaaS context? Who controls what? Who pays? Major players? Depends: Organisational structure: consortia vs. federation [governance arrangements] Systems architecture Tenancy is interesting --- regards trust re other participants

Research opportunities? Configations – can set policies over how the network operates, how multi-party workflow tools operate, etc Research opportunities?

Provider trust BaaS => Re-centralisation? Trust those managing the infrastructure “Trusted” re cloud an ongoing issue: Highly-regulated sectors; auditability Providers => better security(!?) Depends: Risk profile Centralised v federated architecture How much does a provider control? How much can participants see? Trust in who manages the infrastructure

Architectures BaaS Provider Organisation Y Organisation X Architecture aspects are important – e.g. these nodes different to Organisation Y Organisation X

Architectures BaaS Provider Organisation Y Organisation X Here whre the organisation doesn’t host the nodes. Then up to what is exposed to them via the provider… Organisation Y Organisation X

Architectures BaaS Provider Organisation Y Organisation X Here whre the organisation doesn’t host the nodes. Then up to what is exposed to them via the provider… Organisation Y Organisation X

Architectures Myriad of possibilities  trust (more than just nodes) BaaS Provider Here whre the organisation doesn’t host the nodes. Then up to what is exposed to them via the provider… Organisation Y Organisation X Myriad of possibilities  trust (more than just nodes)

Architecture, configuration, role of entities, role of provider(s), contracts AFFECT THE THREAT MODEL DLTs aim at improving trust---- decentralises so trust is in the netowrk. Doesn’t this preclude?

Emerging: silicon-based trust Trusted execution environments (enclaves) Hardware foundations for building trust Security: encryption, code isolation, attestation Much promise for DLT Hyperledger Sawtooth Lake & Coco Framework Keys, smart contracts And also cloud in general… “remove provider from the loop” Trusted cloud: Preclude need for BaaS? Threats/risks? Trust the tech? Supply chain? On going work on trusted computing architectures – raise levels of trust in comp in genreal, including cloud

Trusting the outside Interactions with BaaS (1) Parties (2) Data Access controls: identity, permissions Right tenant; right chain (2) Data Oracles: event validity Agreed; consensus; hardware-backed Service providers as validation entities? Depends on application x Trust regarding interactions with the cloud

Concluding remarks BaaS still emerging Similar benefits to cloud Role in emerging systems: we shall see! Direct S&P implications:: threat models Specifics of the application and participants Traditional business-cases? Consumer chains? Nature of systems & DLT architecture Role of the provider, tenants Who governs what? Overlaps with “trusted cloud” (accountability)

me (Compliant & Accountable Systems) www. jatsingh me (Compliant & Accountable Systems) www.jatsingh.com proj (Microsoft Cloud Computing Research Centre) www.mccrc.org