Developing a trustworthy computing framework for clouds

The concept of tailored trustworthy spaces (TTSs) has been proposed to build a trustworthy cyberspace and solve the trust and security issues in clouds. However, the problem of building a trustworthy cloud infrastructure to support TTS has not been addressed yet. In this paper, we aim to coordinate trust and security, and propose a trust-based cloud security framework, called trustworthy computing framework (TwCF), for TTS. In this framework, the application-aware policy is adopted to suit the users' security contents. A trust management framework is designed to manage trust, security and policies, and fulfil the trust negotiation and decision-making in TTS. The platform security mechanisms concerning the key elements in cloud security are designed to assure the deployment of security policies. In this paper, the key elements and emerging research issues in TwCF are identified and a case study of establishing a TTS in platform as a service (PaaS) is presented.