首页> 外文会议>2012 IEEE 26th International Parallel and Distributed Processing Symposium Workshops amp; PhD Forum >Cloud Services Gateway: A Tool for Exposing Private Services to the Public Cloud with Fine-grained Control
【24h】

Cloud Services Gateway: A Tool for Exposing Private Services to the Public Cloud with Fine-grained Control

机译:云服务网关:一种用于通过细粒度控制向私有云公开私有服务的工具

获取原文
获取原文并翻译 | 示例

摘要

By enabling users to allocate computing resources on demand, cheaply, and in an elastic manner, Cloud Computing has made large computation resources available to small and medium size organizations. However, using the Cloud requires users to place their computations, data, or both in a shared data center own by an outsider. This sharing has raised many security concerns. Such concerns are much apparent with use cases like health informatics, where the security of the information is critical and imposed by government regulations. We propose a hybrid approach to solve this problem, where only computations are moved to the public domains while keeping the data within the private network, and computations may access data through a set of services that expose data following the Principle of Least Privilege. Such architectures will, however, require computations in the cloud to connect to the local network that holds the data, and the obvious solution: that is opening up ports in the organizational firewall could potentially create security loopholes. As an alternative, we propose Cloud Services Gateway (CSG), which enable users to selectively expose their private services that reside inside a firewall to outside clients while maintaining fine grained control. This paper motivates hybrid Cloud architectures and presents the architecture and design decisions of Cloud Services Gateway.
机译:通过使用户能够按需廉价,灵活地分配计算资源,云计算使大型计算资源可供中小型组织使用。但是,使用云需要用户将其计算,数据或两者都放置在外部人拥有的共享数据中心中。这种共享引发了许多安全问题。在诸如卫生信息学之类的用例中,此类担忧尤为明显,在这些案例中,信息的安全性至关重要,并由政府法规强加。我们提出了一种混合方法来解决此问题,在该方法中,只有将计算移到公共域,同时将数据保留在专用网络中,并且计算可以通过遵循最小权限原则公开数据的一组服务访问数据。但是,这样的体系结构将需要云中的计算才能连接到保存数据的本地网络,并且显而易见的解决方案是:在组织防火墙中开放端口可能会造成安全漏洞。作为替代方案,我们提出了云服务网关(CSG),该服务使用户能够将驻留在防火墙内的私有服务选择性地向外部客户端公开,同时保持细粒度的控制。本文旨在激发混合云架构的发展,并提出云服务网关的架构和设计决策。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号