[Paper Review] Security and Privacy Concerns in Cloud-based Scientific and Business Workflows: A Systematic Review
This systematic review identifies security and privacy challenges in cloud-based scientific and business workflows, classifying existing solutions across workflow lifecycle phases—execution, monitoring, and adaptation. It reveals critical gaps in end-to-end protection, access control, and trust management, particularly in dynamic, multi-party environments, and outlines key open research issues for securing sensitive data in cloud-native workflows.
Today, the number of data-intensive and compute-intensive applications like business and scientific workflows has dramatically increased, which made cloud computing more popular in the matter of delivering a large amount of computing resources on demand. On the other hand, security is a critical issue affecting the wide adoption of cloud technologies, especially for workflows that are mostly dealing with sensitive data and tasks. In this paper, we carry out a review of the state-of-the-art on how security and privacy concerns in scientific and business workflows in cloud environments are being addressed and identify the limitations and gaps in the current body of knowledge in this area. In this extensive literature review, we first present a classification of the state-of-the-art security solutions organized according to the phases of the workflow life cycle they target. Based on our findings, we provide a detailed review and classification of the most relevant available literature focusing on the execution, monitoring, and adaptation phases of workflows. Finally, we present a list of open research issues related to the security of cloud-based workflows and discuss them.
Motivation & Objective
- To analyze the current state of research on securing cloud-based scientific and business workflows.
- To identify and classify existing security and privacy solutions according to workflow lifecycle phases.
- To uncover limitations and research gaps in current approaches to securing sensitive data and workloads in cloud environments.
- To provide a structured overview of threats and countermeasures in execution, monitoring, and adaptation phases of workflows.
- To highlight open challenges for future research in access control, trust management, and end-to-end security in dynamic cloud workflows.
Proposed method
- Conducted a systematic literature review using predefined search criteria across major academic databases and repositories.
- Classified 126 relevant studies based on the workflow lifecycle phase they target: execution, monitoring, and adaptation.
- Analyzed security mechanisms such as access control, encryption, and auditing techniques applied in each phase.
- Mapped solutions to specific threat categories, including data leakage, unauthorized access, and insider threats.
- Synthesized findings into a taxonomy of security controls and evaluated their coverage across workflow stages.
- Identified recurring limitations such as lack of support for fine-grained access control and insufficient integration with workflow orchestration frameworks.
Experimental results
Research questions
- RQ1What are the primary security and privacy threats in cloud-based scientific and business workflows?
- RQ2How are existing solutions distributed across the workflow lifecycle phases—execution, monitoring, and adaptation?
- RQ3What are the most common security mechanisms employed, and how effective are they in protecting sensitive data?
- RQ4What are the key limitations and gaps in current research on securing cloud-based workflows?
- RQ5What open research challenges remain in achieving end-to-end security and privacy in dynamic, multi-tenant cloud environments?
Key findings
- A significant majority of existing solutions focus on the execution phase, with limited attention to monitoring and adaptation phases.
- Access control mechanisms are frequently proposed but often lack support for fine-grained, policy-based access decisions in dynamic workflows.
- End-to-end encryption and data anonymization are underutilized, especially in monitoring and logging phases.
- Trust management and auditing mechanisms are rarely integrated into workflow orchestration systems, creating visibility and accountability gaps.
- Few solutions address the threat of insider attacks or provide comprehensive logging and traceability across distributed cloud components.
- There is a notable lack of standardized evaluation frameworks for comparing the effectiveness of security solutions in real-world workflow deployments.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.