Cloud Standards: What, Why, How and Who

| August 9, 2011
Cloud Computing topic of the month

Bob Hayward, chief technology & innovation office CSC Australia & CSC Asia delivered  the following address at Global Access Partner’s Workshop on Cloud Computing in Sydney on Friday 24 June 2011.

Standards are really important. We wouldn’t have the internet if it wasn’t for standards. Those of us that have been in the industry a long time can recall even things like TCP and IP; the fundamental plumbing of the internet. It was a standard. It wasn’t until that standard became adopted and endorsed and used that we really had interoperability across networks.

Then, of course, on top of that you layer things like HTML and XML and other standards that make the world of web browsing and hypertext and documents and so forth that we use every day. The economies and all the business models that we’ve seen on the internet would not have happened if it hadn’t been for those standards. So it’s important to look at standards in the context of cloud, in terms of enabler for those kinds of same business models to take off; to have interoperability and portability, and not to have the kind of lock-in that we see happening.

One of the things I won’t talk about very much is what is cloud in the first place. There are standards, there are definitions. The good news is that in recent times I’ve seen the industry pretty much agree on that. There was a seminal set of documents issued by the US National Institute of Science and Technology in late 2009 which very clearly defined cloud computing; the five characteristics of cloud, the four service types and the four deployment models of cloud computing.
They’ve become pretty well accepted across the industry today. So I no longer attend events where we spend three quarters of our time talking about what is cloud anyway. I think the conversation’s moved beyond that into okay, we understand what cloud is, but now what are the challenges around standards within that environment?
Cloud Computing topic of the monthIf you look at the NIS definitions of business process as a service, software as a service, platform as a service, infrastructure as a service, and you look across those in terms of typical solutions, you might see today, in private cloud, public cloud and traditional IT environments – and I’ve just put up some sample products from a few vendors there: SAP, Microsoft, VMware and, of course, since the years of my slides, CSC as well. You see where these sort of products sets fit in that schema. The issues really resolve around portability and interoperability in a number of different dimensions around this.

First of all, does my software as a service run on other people’s platform? Does my platform run across other people’s infrastructure? That’s one set of standards that we have to consider. Then we have standards across; so in my traditional IT environment do my infrastructure standards work with my private cloud that work and interoperate with things I’m doing in the public cloud? Similarly, in the platform space and, similarly, in the software space.

Then another set of standards we have to think about is how do we manage all of this in a consistent way; around things like security and monitoring and billing and provisioning; all those things. That has to really be considered in the context of all of the above in a consistent way; not just sets of standards that only apply to cloud, but apply to private and traditional IT environments.
You end up with looking at clouds in terms of both functional portability and interoperability between stacks, within the platforms of service, within the infrastructure as a service, within the software as a service, and also associated management standards. These are the sorts of areas where you’re seeing a lot of activity take place.
Just by way of illustration of what I mean, a functional interface is where a client application, for example, running in a virtual machine, can get notification that that virtual machine’s about to run out of capacity, and the application using a consistent API can decide to move itself into a cloud environment; something we call a cloudburst. That requires intelligence. It requires a consistent API set. It requires a standard in order to achieve that objective. That might be an example of a functional interface.
Then you have management interfaces around, as I said, having billing, monitoring, security, quality of service, performance change, configuration type information across all of these. You need interfaces so that tools can do that consistently across these mixed and hybrid type environments.
To illustrate that, these are just examples of the sorts of things we’re talking about in terms of both functional and management interfaces across both software platform and within platform; things like databases and integration and development tools, and then in the infrastructure space as well. (To review Bob’s presentation slides, click here).
In terms of management interfaces, these might be some examples of some of the things that we’d like to see happen around provisioning, metering, billing, quality of service and so forth.
Where are we today? The good news about standards – it’s a cliché to say, but there’s so many to choose from. When you talk about cloud, which is so all encompassing and really touches almost everything we do in IT – storage, networking, servers, into the software arena, into the middleware arena, business process – it really does touch upon everything we do in IT and networking. So there is no shortage of what we call SDOs – standards development organisations – actively engaged in some kind of work around cloud standards.
There were at least 21 of them. There’s probably more. Some of these are working on very specific things; others are more broad. Some of them are groups of vendors working together, or providers; some are more driven out of the user or demand side of the business. You see different kinds of consortium being formed.
Out of all of that you do see some progress being made, but it’s slow progress. If you look at management interface and functional interface, you look at different parts of the stack: infrastructure, platform and across to business process, you see different kinds of standards development organisations seeming to claim those spaces, and are having, probably, more standards work going on in that area. You also see a lot of blank spaces where there’s no-one really actively involved in creating a standard today. So there’s an awful lot of work to be done. You see the object management group, desktop management task force, the Cloud Security Alliance; these are the kinds of organisations beginning to make some progress.

If we look today at where there are the most developed cloud standards, you might see virtual machine portability across infrastructure. There’s a standard emerging around that, called OVF. There’s some open source work going on, sponsored by NASA and a vendor in the States called Rackspace, called the open stack API.

There’s a de facto – everything I’ve talked about so far has been de jure standards. There are, of course, industry de facto standards where you have a dominant vendor whose way of implementing something becomes industry standard. We are experiencing that in cloud. Amazon were clearly the first cab off the rank with a lot of cloud offerings; with, in the air of infrastructure particularly. Their standards – S3 and EC2 – are becoming industry standards just purely because of the fact that they have such a market presence.
You also see other standards there in terms of management, in terms of interoperability and so forth.
Something there called cloud trust protocol. That’s a standard that we at CSC have been advocating and advancing and, just this week, was endorsed by the Cloud Security Alliance. That’s a standard that we’re trying to get all cloud providers to sign up to, where anybody that requests a service of a cloud will be given back 21 pieces of information about that cloud: where is it? What kind of policies govern the use of that cloud? What does it do about replication and backup and so forth? What certifications does it have, from an ISO perspective? Things that you’d like to know about any cloud that you actually go and use. This is something that we – the Cloud Security Alliance is endorsing.
The membership of the Cloud Security Alliance does consist of most of the large providers for cloud services today; so that’s quite an encouraging sign. I think the general message here is that this is very slow progress; that we won’t really see a lot here, I don’t think, that’s going to have a significant impact on the cloud market for quite some time; so we’re going to be struggling with these issues for a number of years before we see some of these cloud standards really have resonance in the industry.
The challenge for us as an industry is: unless we fix some of these problems, it will become an impediment to the uptake of cloud.
The easiest things to do are in the infrastructure space. It’s easy to create standards, at least in infrastructure. It gets harder and harder as you move into software. It’s not simple and there’s a huge switching cost involved. So the higher up the stack you get, the more difficult it gets.
 
I think, on the management side, the clear imperatives are around things like security and transparency; the cloud trust protocol and others like it. If we can lick those, at least we’re making some progress.
 
Bob Hayward is the chief technology & innovation officer for CSC Australia and CSC Asia. Joining in April 2009 he is responsible for the overall direction and business management of CSC’s technology offerings, product strategies and innovation programs.
SHARE WITH: