首页> 外文会议>2013 2nd National Conference on Information Assurance >User Centric Access control policy management framework for Cloud applications
【24h】

User Centric Access control policy management framework for Cloud applications

机译:针对云应用程序的以用户为中心的访问控制策略管理框架

获取原文
获取原文并翻译 | 示例

摘要

Cloud computing environment is a collection of various Cloud applications deployed by different Cloud service vendors for their customers. The online availability, variety and easy access of Cloud applications allow users to create, upload and store numerous resources across the Cloud. However, Protection of these resources from different security threats in Cloud environment is still a serious concern for the Cloud users. Cloud applications provide diverse and complex authorization and access control mechanisms to different Cloud users. Moreover, Access control is limited and tightly bound to the functionality of the applications and does not cater the access control requirements of individual users. Securing every resource with different, complex and limited access control solutions is a tedious task and results in poorly protected resources susceptible to unauthorized access and different other security threats. A new approach to access control in Cloud environment is presented in this paper. It externalizes access control from Cloud applications and enables users to create, and manage access control policies on their resources according to their own security and access control requirements. The framework also provides users with a central control point, standard policy definition language and easy to use interface to specify and manage access control on all their resources scattered across the Cloud. We presented the framework and described the protocol which defines the interaction between different components of the system to specify and enforce User-Centric policies using XACML standards.
机译:云计算环境是由不同的云服务供应商为其客户部署的各种云应用程序的集合。云应用程序的在线可用性,多样性和易于访问性使用户可以跨云创建,上传和存储大量资源。但是,保护云资源免受云环境中不同安全威胁的威胁仍然是云用户关注的重点。云应用程序为不同的云用户提供了多种复杂的授权和访问控制机制。而且,访问控制受到限制并且与应用程序的功能紧密绑定,并且不能满足单个用户的访问控制要求。使用不同,复杂且受限的访问控制解决方案保护每个资源是一项繁琐的任务,并且导致资源保护不佳,容易受到未授权的访问和其他不同的安全威胁。本文提出了一种新的云环境访问控制方法。它外部化了来自Cloud应用程序的访问控制,使用户可以根据自己的安全性和访问控制要求在其资源上创建和管理访问控制策略。该框架还为用户提供中央控制点,标准策略定义语言和易于使用的界面,以指定和管理对分散在云中的所有资源的访问控制。我们介绍了该框架并描述了该协议,该协议定义了系统不同组件之间的交互,以使用XACML标准指定和强制执行以用户为中心的策略。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号