首页> 外文会议>International Conference on Collaborative Computing: Networking, Applications and Worksharing >Role and attribute based collaborative administration of intra-tenant cloud IaaS
【24h】

Role and attribute based collaborative administration of intra-tenant cloud IaaS

机译:租户内云IaaS的基于角色和属性的协同管理

获取原文

摘要

Cloud Infrastructure as a Service (IaaS), where traditional IT infrastructure resources such as compute, storage and networking are owned by a cloud service provider (CSP) and offered as on-demand virtual resources to customers (tenants), is the fastest maturing service model in cloud computing. The transformation of physical resources into virtual offers great flexibility to CSP customers including network based remote collaborative administration. This flexibility can be fully availed only if complemented by commensurately flexible access control to the customers remote IT resources by the customer's IT users. Since customer policies in this regard can vary greatly, the CSP needs a flexible model to accommodate diverse policy requirements. In this paper, we investigate attribute-based access control (ABAC) in cloud IaaS. In ABAC, access requests are evaluated based on the attributes of cloud tenant users and those of objects such as virtual machines, storage volumes, networks, etc. We investigate the access control models supported by commercial IaaS providers such as Amazon AWS and opensource OpenStack, as well as other models in the literature, which mostly use role-based access control (RBAC). We demonstrate their limitations and motivate the need for ABAC support to realize the true potential of IaaS. Building on prior published ABAC models we define a formal ABAC model suitable for IaaS. As proof-of-concept we implement this model in OpenStack, a widely-used open source cloud IaaS software platform. We discuss enforcement alternatives in this context and partially evaluate their performance.
机译:云基础架构即服务(IaaS)是成熟度最快的服务,其中计算,存储和网络等传统IT基础架构资源由云服务提供商(CSP)拥有,并作为按需虚拟资源提供给客户(租户)。云计算中的模型。将物理资源转换为虚拟资源可以为CSP客户提供极大的灵活性,包括基于网络的远程协作管理。只有通过客户IT用户对客户远程IT资源的相应灵活访问控制的补充,才能充分利用这种灵活性。由于这方面的客户策略可能会有很大差异,因此CSP需要一个灵活的模型来适应各种策略要求。在本文中,我们研究了云IaaS中基于属性的访问控制(ABAC)。在ABAC中,访问请求是根据云租户用户的属性以及对象(例如虚拟机,存储卷,网络等)的属性进行评估的。我们调查了商业IaaS提供商(例如Amazon AWS和开源OpenStack)支持的访问控制模型,以及文献中的其他模型,这些模型大多使用基于角色的访问控制(RBAC)。我们展示了它们的局限性,并激发了对ABAC支持的需求,以实现IaaS的真正潜力。在先前发布的ABAC模型的基础上,我们定义了适用于IaaS的正式ABAC模型。作为概念验证,我们在OpenStack(一个广泛使用的开源云IaaS软件平台)中实现此模型。我们将在这种情况下讨论执法替代方案,并部分评估其绩效。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号