<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Privacy-Aware Scheduling for Inter-Organizational Processes</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Distributed Systems Group</string-name>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Vienna University of Technology</string-name>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Austria c.hochreiner@infosys.tuwien.ac.at</string-name>
        </contrib>
      </contrib-group>
      <fpage>63</fpage>
      <lpage>68</lpage>
      <abstract>
        <p>Due to the increasing specialization of companies in a globalized world, inter-organizational process enactments have become increasingly relevant in recent years. Nevertheless there are hardly any scheduling approaches that meet the requirements of these inter-organizational processes, especially in terms of privacy aspects. In this paper we present a privacy-aware scheduling approach for hybrid clouds, which represents a vital starting point to design a holistic execution environment for inter-organizational process enactments.</p>
      </abstract>
      <kwd-group>
        <kwd>Cloud Computing</kwd>
        <kwd>Business Process Management</kwd>
        <kwd>Hybrid Clouds</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>Introduction</title>
      <p>The remainder of this paper is structured as follows: In Sect. 2 we state the
motivation for our work and discuss some preliminaries in Sect. 3. We further
present our privacy-aware scheduling approach in Sect. 4 and Sect. 5 concludes
the paper with an outlook on our future work.
2</p>
    </sec>
    <sec id="sec-2">
      <title>Motivation</title>
      <p>
        Business process enactments are usually triggered by process requests. These
process requests are issued by external events, e.g., customer interactions, which
lead to alternating amounts of business process requests respectively changing
resource requirements. In peak-times, when external events issue an extraordinary
amount of process requests, a BPMS may run into an underprovisioning scenario,
since there are not enough resources to enact the process requests according to
their Service Level Agreements (SLAs) [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ]. This leads to a lower Quality of Service
(QoS), e.g., longer response times and SLA violations may also trigger penalty
cost that increase the overall cost for process enactment. Besides the peak-times,
a system with fixed resources is also likely to run into overprovisioning scenarios,
since the computational resources will not be used adequately. This leads to
economically inefficient cost structures for the companies.
      </p>
      <p>
        Public clouds, e.g., Amazon EC2, offer a promising solution to the resource
usage challenges for varying process requests. A cloud-aware BPMS is able to
obtain the required resources on demand in an utility like fashion. This enables
the BPMS to obtain resource elasticity by scaling the computational resources up
and down, based on the changing requirements. Measured services further allow an
exact billing of the computational resources based on the actual resource usage [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ].
This elastic resource provisioning strategy avoids underprovisioning scenarios,
since the public cloud provides enough resources to cover the peak-requirements.
A cloud environment also avoids overprovisioning scenarios, because not required
resources can be released as soon as they are not needed any more.
      </p>
      <p>
        Besides the resource allocation there are also other challenges for BPMS,
like privacy issues for service instantiations of inter-organizational processes, i.e.,
service choreographies. Inter-organizational processes are structured similarly to
business processes. The major difference is that their process steps are assigned
to software services which are provided by different companies instead of only one.
Therefore software services for inter-organizational processes can be executed
on a community cloud [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ]. Nevertheless this common execution environment
is not acceptable for some software services due to privacy restrictions. The
most promising approach to tackle these issues is the creation of a hybrid cloud
which consists of a community cloud and dedicated private clouds for each
company [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ]. Although resource scheduling for hybrid clouds already raised some
attention in terms of scheduling [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ] as well as privacy aware deployments [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ],
there are surprisingly little efforts towards privacy-aware scheduling approaches
for BPMSs [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ].
      </p>
      <sec id="sec-2-1">
        <title>BPMS</title>
      </sec>
      <sec id="sec-2-2">
        <title>Hybrid Cloud</title>
      </sec>
      <sec id="sec-2-3">
        <title>Community Cloud</title>
        <p>Common</p>
        <p>Data
VMVMVMVVMMVMVMVMVM VM</p>
      </sec>
      <sec id="sec-2-4">
        <title>Private Cloud 2</title>
        <sec id="sec-2-4-1">
          <title>VM VMVVMM VMVM</title>
          <p>Sensitive
Data</p>
        </sec>
      </sec>
      <sec id="sec-2-5">
        <title>Private Cloud 3</title>
        <sec id="sec-2-5-1">
          <title>VM VMVVMM VMVM</title>
          <p>Sensitive</p>
          <p>
            Data
In our previous work we presented the Service Instance Placement Problem
(SIPP) [
            <xref ref-type="bibr" rid="ref4">4</xref>
            ], which provides a cost-optimized scheduling and resource provisioning
plan for multiple parallel process enactments. SIPP represents a multi-objective
scheduling strategy which is presented in Sect. 4.1. Up to now the SIPP only
considers a single cloud for process enactments. Therefore it does not consider
any security nor privacy related aspects which are relevant for process enactments
in hybrid cloud environments. Before we describe the privacy related concepts in
detail in Sect. 4.2, we define some preliminaries.
          </p>
          <p>The execution environment for inter-organizational processes consists of a a
community cloud and dedicated private clouds for privacy sensitive services, as
illustrated in Fig. 1. The community cloud hosts all non privacy sensitive services
as well as the BPMS. The BPMS schedules process steps, provisions resources
for the software-based services on the community cloud and also triggers the
deployment of the privacy sensitive services in the dedicated private clouds, based
on the privacy restrictions issued for the services. These restrictions are described
in detail in Sect. 4.2. In terms of computational resources, we assume that the
private clouds offer a limited amount of computational resources, which are only
sufficient to run the privacy sensitive services whereas the community cloud offers
theoretically unlimited resources.</p>
          <p>The inter-organizational processes are composed of multiple process steps that
represent the software-based services provided by the participating companies.
Fig. 2 represents an exemplary inter-organizational process, which shows the
collaboration among 3 companies. Step 3 and 5 are annotated as privacy sensitive
and must only be executed in the dedicated private clouds, whereas all other steps
can be executed in the community cloud. To execute a process step, the BPMS
triggers the deployment of the software-based service on a Virtual Machine (VM)
either on the community cloud or on a private cloud. This deployment results in
a service instance that can be invoked by the BPMS to execute the service and
therefore execute the process step.
ya1n
p
m
o
C
yan2
p
m
o
C
y3an
p
m
o
C</p>
          <p>Step 1
privacy
sensitive</p>
          <p>Step 6
Step 2</p>
          <p>Step 3
Step 4</p>
          <p>
            Step 5
The SIPP is represented by a set of different constraints and equations, which are
described in detail in [
            <xref ref-type="bibr" rid="ref4">4</xref>
            ]. In Eq. 1 the objective for the SIPP optimization model,
i.e., the minimization of the overall execution cost, is shown. This objective
comprises four terms, where the first term represents the overall leasing cost of
the computational resources by summing up the amount of leased VMs γ(v,t)
multiplied by their cost cv. The second term shows the penalty cost, which arise,
if a process is not finished within the given time. Hereby it sums up all delayed
p and multiplies them with predefined penalty cost cipp . In
process instances eip
order to keep the overall cost as low as possible, the optimization model penalizes
idle resources (CPU (fkCv ) and RAM (fkRv )) which are multiplied by the constants
ωfC and ωR. The last term is designed to prioritize process steps x(jip ,kv,t), so
f
that steps with a closer deadline DLip are executed first.
          </p>
          <p>min</p>
          <p>X cv · γ(v,t) + X X
v∈V
−</p>
          <p>X X</p>
          <p>X
p∈P ip∈Ip jip ∈Ji∗p
p∈P ip∈Ip</p>
          <p>1
DLip − τt</p>
          <p>v∈V kv∈Kv
x(jip ,kv,t)
cip · eipp +
p</p>
          <p>X X (ωfC · fkCv + ωfR · fkRv )
4.2</p>
          <p>Privacy Extensions
Since SIPP is designed for a single cloud, we introduced additional constraints and
additional SLA policies to enable the enactment of inter-organizational processes
while respecting the privacy constraints of the services.</p>
          <p>We extended the set of VM types to distinguish between different deployment
locations with their different privacy policies.</p>
          <p>V =
K =</p>
          <p>[
loc∈Loc</p>
          <p>[
loc∈Loc</p>
          <p>Vloc
Kloc
(1)
(2)
(3)</p>
          <p>This differentiation is possible by introducing the identifier loc (loc ∈ Loc),
which represents the type of the cloud, e.g., community cloud or 1 of the private
clouds. The new set of available VMs is then defined by the union of all VMs,
which can be instantiated in the different clouds (Eq. 2). Analogously we also
extended the set of all currently instantiated VMs (Eq. 3).</p>
          <p>In terms of privacy restrictions, there are 2 specification possibilities to restrict
the execution of services regarding the type of the cloud. The first approach
is blacklisting: the SLA lists for every process all services, which must not be
executed on specific clouds. The major downside of this approach is that the
SLA needs to be updated when additional clouds are added.</p>
          <p>The alternative approach is whitelisting, i.e., the SLA for each process lists all
service instantiation possibilities in the different clouds. Since this SLA pursues
a defensive permission approach, there is no need to update the SLA in contrast
to the blacklisting approach, when the cloud environment grows by additional
private or community clouds. Eq. 4 shows an exemplary SLA for the process
presented in Fig. 2.
communityCloud (Service 1, Service 2, Service 4)

privateCloud1 (Service 3)
privateCloud2 (Service 5)</p>
          <p>Based on this SLA for services, a MILP-solver for the optimization problem is
able to generate the instantiation possibilities according to Eq. 5. The constraints
in Eq. 5 evaluate whether a specific process step jip can be instantiated on a
specific VM kvloc by querying whether the process step is listed on the whitelist
for the given cloud loc. If the SLA does not explicitly allow the instantiation
of the process step on the specific VM, the constraint rules out the deployment
option. Otherwise the MILP-solver decides based on other constraints whether the
service is deployed on the specific VM (1) or not (0) as stated in the alternative
branch of the constraint.</p>
          <p>x(jip ,kvloc ,t) =
(0
{0, 1}
, if jip ∈/ SLAPloc , loc ∈ Loc
, else
(4)
(5)
5</p>
        </sec>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>Outlook</title>
      <p>
        In this paper we focused on the formalization of privacy constraints for the
deployment and enactment of inter-organizational processes in hybrid cloud
environments. Although these privacy extensions are relevant for process
enactment, they only represent a small step towards a holistic process scheduling
and resource allocation approach for inter-organizational processes in hybrid
cloud environments. Other relevant topics are data transfer aspects among the
different clouds, which become increasingly relevant for big data applications or a
cost-efficient resource allocation across the cloud environment. In our future work
we will evaluate the proposed privacy constraints in a hybrid cloud environment
based on the Vienna Platform for Elastic Processes (ViePEP) [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ]. Here we plan
to evaluate our approach against other privacy ensuring methods, e.g., encryption
of privacy-sensitive data in terms of performance and cost-efficiency. Further we
will also investigate other areas, like data transfer aspects or pricing policies for
hybrid clouds to enable the enactment of inter-organizational processes in an
economically efficient manner.
      </p>
      <p>Acknowledgments This paper is partially supported by TU Vienna research
funds and supported by the European Union within the SIMPLI-CITY FP7-ICT
project (Grant agreement no. 318201).</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1. van den Bossche, R.,
          <string-name>
            <surname>Vanmechelen</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Broeckhove</surname>
          </string-name>
          , J.:
          <article-title>Cost-optimal scheduling in hybrid iaas clouds for deadline constrained workloads</article-title>
          .
          <source>In: 2010 IEEE 3rd International Conference on Cloud Computing (CLOUD)</source>
          . pp.
          <fpage>228</fpage>
          -
          <lpage>235</lpage>
          . IEEE (
          <year>2010</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <surname>van Der Aalst</surname>
            ,
            <given-names>W.M.</given-names>
          </string-name>
          ,
          <string-name>
            <given-names>Ter</given-names>
            <surname>Hofstede</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.H.</given-names>
            ,
            <surname>Weske</surname>
          </string-name>
          ,
          <string-name>
            <surname>M.</surname>
          </string-name>
          :
          <article-title>Business process management: A survey</article-title>
          .
          <source>In: Business process management</source>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>12</lpage>
          . Springer (
          <year>2003</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <surname>Goyal</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          :
          <article-title>Enterprise usability of cloud computing environments: issues and challenges</article-title>
          .
          <source>In: 2010 19th IEEE International Workshop on Enabling Technologies: Infrastructures for Collaborative Enterprises (WETICE)</source>
          . pp.
          <fpage>54</fpage>
          -
          <lpage>59</lpage>
          . IEEE (
          <year>2010</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <surname>Hoenisch</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Schuller</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hochreiner</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Schulte</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Dustdar</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          :
          <article-title>Elastic process optimization - the service instance placement problem</article-title>
          .
          <source>Tech. Rep. TUV-1841- 2014-01</source>
          , Distributed Systems Group, Vienna University of Technology (
          <year>October 2014</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <surname>Hoenisch</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Schulte</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Dustdar</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Venugopal</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          :
          <article-title>Self-Adaptive Resource Allocation for Elastic Process Execution</article-title>
          .
          <source>In: 6th International Conference on Cloud Computing (CLOUD</source>
          <year>2013</year>
          ). pp.
          <fpage>220</fpage>
          -
          <lpage>227</lpage>
          . IEEE (
          <year>2013</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <surname>Huang</surname>
            ,
            <given-names>Z.</given-names>
          </string-name>
          , van der Aalst,
          <string-name>
            <given-names>W.M.P.</given-names>
            ,
            <surname>Lu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>X.</given-names>
            ,
            <surname>Duan</surname>
          </string-name>
          , H.:
          <article-title>Reinforcement learning based resource allocation in business process management</article-title>
          .
          <source>Data &amp; Knowledge Engineering</source>
          <volume>70</volume>
          (
          <issue>1</issue>
          ),
          <fpage>127</fpage>
          -
          <lpage>145</lpage>
          (
          <year>2011</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <surname>Mell</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Grance</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          :
          <article-title>The NIST Definition of Cloud Computing. Recommendations of the National Institute of Standards and Technology (</article-title>
          <year>2011</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <surname>Rosemann</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>vom Brocke</surname>
          </string-name>
          , J.:
          <article-title>The Six Core Elements of Business Process Management</article-title>
          .
          <source>In: Handbook on Business Process Management 1</source>
          , pp.
          <fpage>107</fpage>
          -
          <lpage>122</lpage>
          . Springer (
          <year>2010</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9.
          <string-name>
            <surname>Schulte</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Janiesch</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Venugopal</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Weber</surname>
            ,
            <given-names>I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hoenisch</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          :
          <article-title>Elastic Business Process Management: State of the Art and Open Challenges for BPM in the Cloud</article-title>
          .
          <source>Future Generation Computer Systems</source>
          <volume>46</volume>
          ,
          <fpage>36</fpage>
          -
          <lpage>50</lpage>
          (
          <year>2015</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10.
          <string-name>
            <surname>Subashini</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kavitha</surname>
          </string-name>
          , V.:
          <article-title>A survey on security issues in service delivery models of cloud computing</article-title>
          .
          <source>Journal of Network and Computer Applications</source>
          <volume>34</volume>
          (
          <issue>1</issue>
          ),
          <fpage>1</fpage>
          -
          <lpage>11</lpage>
          (
          <year>2011</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11.
          <string-name>
            <surname>van der Aalst</surname>
            ,
            <given-names>W.M.P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>ter Hofstede</surname>
            ,
            <given-names>A.H.M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kiepuszewski</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Barros</surname>
            ,
            <given-names>A.P.</given-names>
          </string-name>
          : Workflow Patterns.
          <source>Distributed and Parallel Databases</source>
          <volume>14</volume>
          (
          <issue>1</issue>
          ),
          <fpage>5</fpage>
          -
          <lpage>51</lpage>
          (
          <year>2003</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12.
          <string-name>
            <surname>Weske</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <source>Business Process Management: Concepts</source>
          , Languages, Architectures. Springer, 2nd edn. (
          <year>2012</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          13.
          <string-name>
            <surname>Zhang</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Zhou</surname>
            ,
            <given-names>X.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Chen</surname>
            ,
            <given-names>Y.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Wang</surname>
            ,
            <given-names>X.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ruan</surname>
            ,
            <given-names>Y.</given-names>
          </string-name>
          :
          <article-title>Sedic: privacy-aware data intensive computing on hybrid clouds</article-title>
          .
          <source>In: Proceedings of the 18th ACM conference on Computer and communications security</source>
          . pp.
          <fpage>515</fpage>
          -
          <lpage>526</lpage>
          . ACM (
          <year>2011</year>
          )
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>