CamFlow: Managed Data-sharing for Cloud Services
Thomas F. J.-M. Pasquier, Jatinder Singh, David Eyers, Jean, Bacon

TL;DR
CamFlow introduces a cloud-based Information Flow Control system that enhances data protection, sharing, and transparency across cloud services, addressing isolation and security challenges in multi-tenant environments.
Contribution
It presents a novel cloud-deployed IFC framework that enforces data owners' policies, improves data sharing, and provides comprehensive audit logging for cloud applications.
Findings
Demonstrates effective data flow enforcement in cloud environments.
Provides transparent audit logs for data movements.
Enhances data protection and sharing capabilities.
Abstract
A model of cloud services is emerging whereby a few trusted providers manage the underlying hardware and communications whereas many companies build on this infrastructure to offer higher level, cloud-hosted PaaS services and/or SaaS applications. From the start, strong isolation between cloud tenants was seen to be of paramount importance, provided first by virtual machines (VM) and later by containers, which share the operating system (OS) kernel. Increasingly it is the case that applications also require facilities to effect isolation and protection of data managed by those applications. They also require flexible data sharing with other applications, often across the traditional cloud-isolation boundaries; for example, when government provides many related services for its citizens on a common platform. Similar considerations apply to the end-users of applications. But in…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
