【24h】

Towards a Fine-Grained Access Control for Cloud

机译:迈向云的精细访问控制

获取原文
获取原文并翻译 | 示例

摘要

The centerpiece of an efficient Cloud security architecture is a well-defined access control policy. In literature we can find several access control models such as the Mandatory Access Control (MAC), Discretionary Access Control (DAC), Role-Based Access Control (RBAC) and the latest one Usage Control Authorization, oBligation and Condition (UCONABC). The UCONABC is very suitable for the context of distributed systems like cloud computing but it doesn't give any implementation method. In this paper we define the profile centric model using graph formalism and its implementation using matrix. We define the profile as the combination of all possible authorization, obligation, condition, role, etc... and other access parameters like attributes that we can found in Cloud system. We discuss its application using three matrixes (profile definition, profile inheritance and user assignment). Profile centric modeling is an optimum paradigm to define access control policy in complex distributed and elastic system like cloud computing. The proposed solution is validated and implemented over Hadoop distributed file system in the context of Safe Box as a service.
机译:高效的云安全架构的核心是定义明确的访问控制策略。在文献中,我们可以找到几种访问控制模型,例如强制访问控制(MAC),自由访问控制(DAC),基于角色的访问控制(RBAC)和最新的一种使用控制授权,义务和条件(UCONABC)。 UCONABC非常适合像云计算这样的分布式系统的环境,但是它没有提供任何实现方法。在本文中,我们使用图形式主义定义了以轮廓为中心的模型,并使用矩阵对其进行了实现。我们将配置文件定义为所有可能的授权,义务,条件,角色等的组合以及其他访问参数(例如我们可以在云系统中找到的属性)的组合。我们使用三个矩阵(配置文件定义,配置文件继承和用户分配)讨论其应用。以配置文件为中心的建模是定义复杂的分布式弹性系统(如云计算)中的访问控制策略的最佳范例。在Safe Box即服务的上下文中,通过Hadoop分布式文件系统对所提出的解决方案进行了验证和实现。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号