【24h】

Access control in probative value Cloud

机译:估算值云中的访问控制

获取原文

摘要

Access Control over large scale distributed system like Cloud computing are one of the most debated topics of computer security. Despite the common use and the popularity of the Cloud computing paradigm, significant risks and challenges are inherent to this new concept, especially when we talk about storage of sensitive data via insecure network. In this paper we look at the problem of protecting data from unauthorized access to the Cloud in the context of gSafe (government Safe) project. Indeed, gSafe project defines essential basic units for a probative storage Cloud. The cornerstone of the efficient cloud security architecture is a well-written access control policy. In today's information technology, many models of access control have been proposed like the Mandatory Access Control (MAC), Discretionary Access Control (DAC), Role-Based Access Control (RBAC) and the latest one Usage Control Authorization, oBligation and Condition (UCONABC). In this paper we use six entities proposed in the UCONABC: Object, Subject, Right, Authorization, oBligation and Condition to model the access control management in the gSafe project. Then we present the XML scheme containing metadata for stored files and users' access authorizations. The proposed solution is validated and implemented over Hadoop distributed file system.
机译:像云计算等大规模分布式系统的访问控制是计算机安全最讨论的主题之一。尽管云计算范式的常见使用和普及,但这种新概念的重大风险和挑战是固有的,特别是当我们通过不安全的网络谈论敏感数据的存储时。在本文中,我们在GSAFE(政府安全)项目的背景下,看看保护来自未经授权访问云的数据的问题。实际上,GSafe项目定义了遗嘱储存云的基本基本单位。高效云安全架构的基石是一个写得良好的访问控制策略。在今天的信息技术中,已经提出了许多型号的访问控制,如强制性访问控制(MAC),可自由裁量权访问控制(DAC),基于角色的访问控制(RBAC)以及最新的一个使用控制授权,义务和条件(UConabc )。在本文中,我们在UConabc中提出的六个实体:对象,主题,权利,授权,义务和条件来模拟GSAFE项目中的访问控制管理。然后我们介绍包含存储文件和用户访问授权元数据的XML方案。通过Hadoop分布式文件系统验证并实施了所提出的解决方案。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号