首页> 外文会议>IEEE International Conference on Cloud Computing Technology and Science >Access Control and Security Properties Requirements Specification for Clouds' SecLAs
【24h】

Access Control and Security Properties Requirements Specification for Clouds' SecLAs

机译:云SecLA的访问控制和安全属性要求规范

获取原文

摘要

Current Cloud Service Level Agreements (SLAs) do not cover security requirements. Some consortiums have proposed standards for the evaluation of security offered by the Cloud Providers (CP). Cloud Brokers (CB) can then generate Security Level Agreement (SecLA) contracts between customers and providers to fit users' requirements. However, the SecLAs do not provide enough details for complex customers' situations, such as sharing resources with other users/companies, or set up specific Access Controls and Security Properties (ACSP). In this paper, we tackle this issue, by introducing a general Requirement Specification Language (ACSP-RSL) to allow the customers to express their needs in term of ACSP. The underlying formal model, on which is based RSL, is partially presented. The global SecLA definition and negotiation process is thus extended with our proposal. RSL indeed also allows to express Security Requirements currently existing in SecLAs. The negotiation phase between CB and the CPs is discussed. We show how the RSL specifications expressed by the customer can be projected into a generic detection/protection policy expressed as an extension of RSL. A complete use-case for a healthcare system with multitenancy for users and services deployed is given. Its security requirements are analyzed, modeled, expressed and discussed.
机译:当前的云服务级别协议(SLA)不涵盖安全性要求。一些财团已经提出了云提供商(CP)提供的安全性评估标准。然后,Cloud Brokers(CB)可以在客户和提供者之间生成安全级别协议(SecLA)合同,以满足用户的需求。但是,SecLA不能为复杂客户的情况提供足够的详细信息,例如与其他用户/公司共享资源或设置特定的访问控制和安全属性(ACSP)。在本文中,我们通过引入通用的需求规范语言(ACSP-RSL)来解决此问题,以使客户能够以ACSP的方式表达他们的需求。部分展示了基于RSL的基础形式模型。因此,我们的提案扩展了全球SecLA的定义和谈判过程。 RSL实际上也允许表达SecLA中当前存在的安全要求。讨论了CB和CP之间的协商阶段。我们展示了如何将客户表达的RSL规范投影到表达为RSL扩展的通用检测/保护策略中。给出了医疗系统的完整用例,该系统具有针对用户和已部署服务的多租户。分析,建模,表达和讨论其安全要求。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号