首页> 外文会议>International Conference on Advances in Computing, Communications and Informatics >SignedQuery: Protecting users data in multi-tenant SaaS environments
【24h】

SignedQuery: Protecting users data in multi-tenant SaaS environments

机译:SignedQuery:在多租户SaaS环境中保护用户数据

获取原文

摘要

Software-as-a-Service (SaaS) is emerging as a new software delivery model, where the application and its associated data are hosted in the cloud. Due to the nature of SaaS and the cloud in general, where the data and the computation are beyond the control of the user, data privacy and security becomes a vital factor in this new paradigm. Several research studies reported that security and privacy are cited as the biggest concerns in adopting cloud computing. In multi-tenant SaaS applications, the tenants become concerned about the confidentiality of their data since several tenants are consolidated onto a shared infrastructure. Consequently, several questions raise, such as, how to ensure that tenant's data are only available to authenticated users? How to prohibit a tenant from accessing other's data? To address these concerns, we present SignedQuery, a mechanism designed to facilitate the process of securing data stored on the cloud. SignedQuery ensures data confidentiality by preventing any tenant from accidentally or maliciously accessing other tenants' data without breaking the functionality of the application. SignedQuery utilizes the usage of a signature to sign the tenant's request, so the server can recognize the requesting tenant and ensure that the data to be accessed is belonging to this tenant. SignedQuery intercepts the HTTP request objects at the tenant's internal network, create the signature and attach it to the request headers, then send the request to the SaaS provider where the signature is validated. We have successfully tested SignedQuery against OrangeHRM. The results showed that our approach is feasible, and incur a negligible overhead.
机译:软件即服务(SaaS)正在作为一种新的软件交付模型出现,该应用程序及其相关数据托管在云中。由于SaaS和一般的云的性质,数据和计算超出了用户的控制范围,因此数据隐私和安全性成为此新范式中的重要因素。几项研究报告指出,安全性和隐私是采用云计算的最大关注点。在多租户SaaS应用程序中,由于几个租户已合并到共享的基础架构中,因此租户开始担心其数据的机密性。因此,提出了一些问题,例如,如何确保租户的数据仅对经过身份验证的用户可用?如何禁止租户访问其他人的数据?为了解决这些问题,我们提出了SignedQuery,这是一种旨在促进保护存储在云中的数据的过程的机制。 SignedQuery通过防止任何租户意外或恶意访问其他租户的数据而不破坏应用程序的功能来确保数据机密性。 SignedQuery利用签名的用法对租户的请求进行签名,因此服务器可以识别发出请求的租户,并确保要访问的数据属于该租户。 SignedQuery在租户的内部网络截获HTTP请求对象,创建签名并将其附加到请求标头,然后将请求发送到验证签名的SaaS提供程序。我们已经针对OrangeHRM成功测试了SignedQuery。结果表明,我们的方法是可行的,并且所产生的开销可以忽略不计。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号