首页> 外文会议>International conference on information and communications security >SDAC: A New Software-Defined Access Control Paradigm for Cloud-Based Systems
【24h】

SDAC: A New Software-Defined Access Control Paradigm for Cloud-Based Systems

机译:SDAC:用于基于云的系统的新的软件定义的访问控制范例

获取原文

摘要

A cloud-based system usually runs in multiple geographically distributed datacenters, making the deployment of effective access control models extremely challenging. This paper presents a novel software-defined paradigm, called SDAC, to achieve scoped, flexible and dynamic access control. In particular, SDAC enables the tenant-specific generation of access control model and policy (SMPolicy in short), as well as their dynamic configuration by the cloud-hosting applications. To achieve that, SDAC uses an access control meta-model to initiate and customize different SMPolicies. Also, SDAC is decoupled into control plane and policy plane, allowing the global SMPolicy generated at the control plane to be efficiently propagated to the policy plane and enforced locally in different datacenters. As such, the local SMPolicy of a tenant can be synchronized with its global SMPolicy only when it's necessary, e.g., a user or a role cannot be identified. To validate the feasibility and effectiveness of SDAC, we implement a prototype in a carrier grade datacenter. The experimental results demonstrate that SDAC can achieve the desirable properties, maintain the throughput at a reasonable level regardless of the varying number of tenants, users, and datacenters, highly preserving scalability and adaptability.
机译:基于云的系统通常在多个地理分布的数据中心中运行,这使得有效访问控制模型的部署极具挑战性。本文提出了一种新颖的软件定义范例,称为SDAC,以实现范围化,灵活和动态的访问控制。特别是,SDAC支持特定于租户的访问控制模型和策略(简称SMPolicy)的生成,以及由云托管应用程序进行的动态配置。为此,SDAC使用访问控制元模型来启动和定制不同的SMPolicies。而且,SDAC被分离到控制平面和策略平面,从而允许在控制平面上生成的全局SMPolicy有效地传播到策略平面,并在不同的数据中心本地实施。这样,仅在必要时(例如,无法识别用户或角色),才能将租户的本地SMPolicy与其全局SMPolicy同步。为了验证SDAC的可行性和有效性,我们在运营商级数据中心中实现了一个原型。实验结果表明,无论租户,用户和数据中心的数量如何变化,SDAC都能达到理想的性能,将吞吐量保持在合理的水平上,并高度保留了可伸缩性和适应性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号