Skip to content

Cloud Computing and Internet Technology

Cloud computing is the on-demand delivery over a network of a shared pool of configurable resources such as servers, storage, platforms and applications. Resources can be rapidly provisioned and released with minimal provider interaction, pooled among users, elastically scaled and measured for billing or control.

Five characteristics distinguish cloud computing from merely hosting a server at a remote site:

  1. On-demand self-service: a customer provisions computing, storage or application capability automatically without waiting for manual provider action.

  2. Broad network access: services are available through standard network mechanisms to suitable web, mobile and enterprise clients.

  3. Resource pooling: provider resources serve multiple tenants dynamically, with logical isolation and location independence at the abstraction promised to the customer.

  4. Rapid elasticity: capacity can scale outward/inward or upward/downward with demand and may appear effectively unlimited.

  5. Measured service: use is monitored, controlled and reported, enabling metering, quotas, optimization and usage-based charging.

Cloud architecture from clients and secure API access to alternative service models and common resource foundations, with four deployment models and the five essential characteristics.

Cloud architecture from clients and secure API access to alternative service models and common resource foundations, with four deployment models and the five essential characteristics.

A request in the figure is authenticated at a portal or API gateway, scheduled onto pooled virtualized or containerized resources, connected to storage/network services, monitored, scaled and metered. Virtualization is a common enabling mechanism, but cloud computing also requires service automation, pooling, elasticity and measurement.

The service model identifies the abstraction delivered and, consequently, the management boundary between provider and customer.

ModelProvider delivers/managesCustomer mainly managesExample use
SaaSComplete hosted application through a browser or APIUsers, data, access policy and permitted configurationWeb mail or online office suite
PaaSInfrastructure, OS, runtime, middleware and managed platform servicesApplication code, data and application configurationTelecom self-care API deployed without administering servers
IaaSVirtual machines, virtual networking and storage on physical infrastructureGuest OS, patches, middleware, applications, data and network rulesElastic web-server VMs with block storage

IaaS, PaaS and SaaS service models.

SaaS gives the least infrastructure control and the most provider management; IaaS gives the most customer control and operational responsibility. PaaS trades low-level control for faster application development and deployment.

DeploymentOwnership and accessSuitable application
Public cloudProvider-owned infrastructure logically shared among tenants; reached over public or private network linksA public website that scales during demand peaks
Private cloudInfrastructure dedicated to one organization, operated on its premises or by a hostSubscriber or billing systems under internal policy
Community cloudInfrastructure shared by organizations with common mission, security or regulatory requirements; operated by members or a providerA public-sector or industry consortium shares a governed sector platform
Hybrid cloudPolicy-connected private and public environments that coordinate workloads or dataKeep customer records private while public capacity handles bursts or encrypted backup

Cloud deployment models.

Hybrid does not mean an arbitrary collection of unrelated systems: the public and private parts require networking, identity, management and data-movement policies that let them operate together.

Potential benefitRisk or limitation
Rapid provisioning and shorter deployment timeMisconfiguration can also be created and replicated rapidly
Elastic capacity for variable demandPoor scaling rules may increase cost or fail during a demand spike
Resource sharing and reduced initial capital expenseRecurring cost can be unpredictable without metering, budgets and lifecycle control
Broad access and managed servicesProvider/network outage and latency affect availability and response time
Provider-managed infrastructure and economies of scaleMigration difficulty, proprietary services and vendor lock-in
Geographic reach and backup optionsData-residency, sovereignty, privacy and legal requirements constrain location and movement

Cloud benefits and corresponding limitations.

Cloud use changes the ownership and concentration of risk; it does not make capacity planning, security, backup or disaster recovery unnecessary. A customer must understand service limits, outage dependencies, exit strategy and total operating cost.

The provider is commonly described as securing the cloud (facilities, physical hardware and provider-controlled service layers), while the customer secures its permitted configuration, identities, workloads and data in the cloud. The exact boundary is contractual and changes with the service model.

Layer or controlIaaSPaaSSaaS
Facilities, hardware, core network, hypervisorProviderProviderProvider
Guest OS and patchingCustomerProviderProvider
Runtime and middlewareCustomerProviderProvider
Application codeCustomerCustomerProvider
Data classification, user access and allowed configurationCustomerCustomerCustomer

Typical shared-responsibility boundary.

Important controls include:

  • Identity and access management: use MFA, least privilege, role separation and prompt revocation rather than shared permanent credentials.

  • Data protection: encrypt data in transit and at rest, control keys, classify sensitive data and retain tested backups.

  • Isolation and configuration: enforce tenant isolation, private-by-default network/storage policy, patch customer-owned layers and continuously check configuration.

  • Visibility and response: collect audit and service logs, monitor anomalies and costs, define incident responsibilities and test recovery.

  • Governance: verify location, retention, deletion, compliance, availability objectives and provider exit arrangements.

Encryption does not replace authorization, and provider backup features do not remove the customer’s duty to define retention and test restoration. Shared responsibility means divided tasks, not an absence of responsibility.

The Internet is a packet-switched network of interconnected networks using the TCP/IP protocol suite. An IP address identifies an interface for routing packets. The Domain Name System (DNS) resolves human-readable names to IP addresses and other records. The World Wide Web is an Internet application: a browser uses a URL to identify a resource, HTTP or HTTPS to request it, and HTML plus related formats to represent the page.

Cloud services may be reached over the public Internet or private links; cloud computing and the Internet are therefore related but not synonyms. HTTPS protects a connection in transit, while cloud IAM determines whether the authenticated principal is authorized to use the requested resource.

  • Five characteristics: on-demand self-service, broad network access, resource pooling, rapid elasticity and measured service.

  • Service models: IaaS supplies virtual resources, PaaS supplies a managed application platform, and SaaS supplies the application.

  • Deployments: public is provider-shared, private is dedicated to one organization, community is shared by organizations with common requirements, and hybrid coordinates distinct clouds.

  • Shared responsibility: the provider/customer boundary changes by service model; customer data, identity and permitted configuration remain customer concerns.

  • Internet/Web: the Internet is the TCP/IP network; the Web is an HTTP application running over it.