Cloud Computing and Internet Technology
Cloud computing is the on-demand delivery over a network of a shared pool of configurable resources such as servers, storage, platforms and applications. Resources can be rapidly provisioned and released with minimal provider interaction, pooled among users, elastically scaled and measured for billing or control.
Essential Characteristics
Section titled “Essential Characteristics”Five characteristics distinguish cloud computing from merely hosting a server at a remote site:
-
On-demand self-service: a customer provisions computing, storage or application capability automatically without waiting for manual provider action.
-
Broad network access: services are available through standard network mechanisms to suitable web, mobile and enterprise clients.
-
Resource pooling: provider resources serve multiple tenants dynamically, with logical isolation and location independence at the abstraction promised to the customer.
-
Rapid elasticity: capacity can scale outward/inward or upward/downward with demand and may appear effectively unlimited.
-
Measured service: use is monitored, controlled and reported, enabling metering, quotas, optimization and usage-based charging.
Cloud architecture from clients and secure API access to alternative service models and common resource foundations, with four deployment models and the five essential characteristics.
A request in the figure is authenticated at a portal or API gateway, scheduled onto pooled virtualized or containerized resources, connected to storage/network services, monitored, scaled and metered. Virtualization is a common enabling mechanism, but cloud computing also requires service automation, pooling, elasticity and measurement.
Cloud Service Models
Section titled “Cloud Service Models”The service model identifies the abstraction delivered and, consequently, the management boundary between provider and customer.
| Model | Provider delivers/manages | Customer mainly manages | Example use |
|---|---|---|---|
| SaaS | Complete hosted application through a browser or API | Users, data, access policy and permitted configuration | Web mail or online office suite |
| PaaS | Infrastructure, OS, runtime, middleware and managed platform services | Application code, data and application configuration | Telecom self-care API deployed without administering servers |
| IaaS | Virtual machines, virtual networking and storage on physical infrastructure | Guest OS, patches, middleware, applications, data and network rules | Elastic web-server VMs with block storage |
IaaS, PaaS and SaaS service models.
SaaS gives the least infrastructure control and the most provider management; IaaS gives the most customer control and operational responsibility. PaaS trades low-level control for faster application development and deployment.
Deployment Models
Section titled “Deployment Models”| Deployment | Ownership and access | Suitable application |
|---|---|---|
| Public cloud | Provider-owned infrastructure logically shared among tenants; reached over public or private network links | A public website that scales during demand peaks |
| Private cloud | Infrastructure dedicated to one organization, operated on its premises or by a host | Subscriber or billing systems under internal policy |
| Community cloud | Infrastructure shared by organizations with common mission, security or regulatory requirements; operated by members or a provider | A public-sector or industry consortium shares a governed sector platform |
| Hybrid cloud | Policy-connected private and public environments that coordinate workloads or data | Keep customer records private while public capacity handles bursts or encrypted backup |
Cloud deployment models.
Hybrid does not mean an arbitrary collection of unrelated systems: the public and private parts require networking, identity, management and data-movement policies that let them operate together.
Benefits and Risks
Section titled “Benefits and Risks”| Potential benefit | Risk or limitation |
|---|---|
| Rapid provisioning and shorter deployment time | Misconfiguration can also be created and replicated rapidly |
| Elastic capacity for variable demand | Poor scaling rules may increase cost or fail during a demand spike |
| Resource sharing and reduced initial capital expense | Recurring cost can be unpredictable without metering, budgets and lifecycle control |
| Broad access and managed services | Provider/network outage and latency affect availability and response time |
| Provider-managed infrastructure and economies of scale | Migration difficulty, proprietary services and vendor lock-in |
| Geographic reach and backup options | Data-residency, sovereignty, privacy and legal requirements constrain location and movement |
Cloud benefits and corresponding limitations.
Cloud use changes the ownership and concentration of risk; it does not make capacity planning, security, backup or disaster recovery unnecessary. A customer must understand service limits, outage dependencies, exit strategy and total operating cost.
Security and Shared Responsibility
Section titled “Security and Shared Responsibility”The provider is commonly described as securing the cloud (facilities, physical hardware and provider-controlled service layers), while the customer secures its permitted configuration, identities, workloads and data in the cloud. The exact boundary is contractual and changes with the service model.
| Layer or control | IaaS | PaaS | SaaS |
|---|---|---|---|
| Facilities, hardware, core network, hypervisor | Provider | Provider | Provider |
| Guest OS and patching | Customer | Provider | Provider |
| Runtime and middleware | Customer | Provider | Provider |
| Application code | Customer | Customer | Provider |
| Data classification, user access and allowed configuration | Customer | Customer | Customer |
Typical shared-responsibility boundary.
Important controls include:
-
Identity and access management: use MFA, least privilege, role separation and prompt revocation rather than shared permanent credentials.
-
Data protection: encrypt data in transit and at rest, control keys, classify sensitive data and retain tested backups.
-
Isolation and configuration: enforce tenant isolation, private-by-default network/storage policy, patch customer-owned layers and continuously check configuration.
-
Visibility and response: collect audit and service logs, monitor anomalies and costs, define incident responsibilities and test recovery.
-
Governance: verify location, retention, deletion, compliance, availability objectives and provider exit arrangements.
Encryption does not replace authorization, and provider backup features do not remove the customer’s duty to define retention and test restoration. Shared responsibility means divided tasks, not an absence of responsibility.
Internet Technology Context
Section titled “Internet Technology Context”The Internet is a packet-switched network of interconnected networks using the TCP/IP protocol suite. An IP address identifies an interface for routing packets. The Domain Name System (DNS) resolves human-readable names to IP addresses and other records. The World Wide Web is an Internet application: a browser uses a URL to identify a resource, HTTP or HTTPS to request it, and HTML plus related formats to represent the page.
Cloud services may be reached over the public Internet or private links; cloud computing and the Internet are therefore related but not synonyms. HTTPS protects a connection in transit, while cloud IAM determines whether the authenticated principal is authorized to use the requested resource.
Quick Review
Section titled “Quick Review”-
Five characteristics: on-demand self-service, broad network access, resource pooling, rapid elasticity and measured service.
-
Service models: IaaS supplies virtual resources, PaaS supplies a managed application platform, and SaaS supplies the application.
-
Deployments: public is provider-shared, private is dedicated to one organization, community is shared by organizations with common requirements, and hybrid coordinates distinct clouds.
-
Shared responsibility: the provider/customer boundary changes by service model; customer data, identity and permitted configuration remain customer concerns.
-
Internet/Web: the Internet is the TCP/IP network; the Web is an HTTP application running over it.