首页> 外文会议>International computer science and engineering conference >A chain calling in coordination for multi-tenant collaborative cloud services
【24h】

A chain calling in coordination for multi-tenant collaborative cloud services

机译:一条链协调多租户协作云服务

获取原文
获取外文期刊封面目录资料

摘要

Currently, a cloud service is widely available but its access control is usually limited and tied only to its tenancy in isolation. To take full advantage from cloud services, multiple tenancies with some level of mutual trust would seek to collaborate and share their resources. However, building a collaborative application from inter-related chain callings to various services on a single or multiple cloud systems encounters an access control challenge and it becomes a big barrier to its adoption. To provide an appropriate fine grained chain calling authorization, this paper proposes an extension to Multi-Tenant Authorization System Model (MTAS), named “Chain Calling Coordination in MTAS” (C-MTAS). In the MTAS, a service with several chain callings would require the model to break a tenant's role into too many sub-roles with a limited trust scope. This would increase unintentional number of roles that could lead to breaches. It would be also hard to maintain. We, instead, propose to separate a tenant element to make a non-redundant, clear and simplified set of roles and permissions. The benefit of our model to the MTAS is shown by applying both models to the same concrete scenario. We found that our model gives a cleaner and smaller set of rules as compared to the MTAS's. We also illustrate how to use our model via a practically feasible example policy in the XACML format. The prototype system is built as an Authorization as a Service (AaaS) platform, a middle layer on the part of the cloud services, which can be used by the same or across providers. Finally, it is tested on different hardware sets. The results showed that the model could be scalable.
机译:当前,云服务是广泛可用的,但是其访问控制通常受到限制,并且仅独立于其租约。为了充分利用云服务,具有一定程度互信的多个租户将寻求协作并共享其资源。但是,从相互关联的链调用到单个或多个云系统上的各种服务构建协作应用程序会遇到访问控制挑战,这成为采用该应用程序的一大障碍。为了提供适当的细粒度链调用授权,本文提出了对多租户授权系统模型(MTAS)的扩展,称为“ MTAS链调用协调”(C-MTAS)。在MTAS中,具有多个链调用的服务将需要模型将租户的角色分解为信任范围有限的太多子角色。这将增加可能导致违规的角色数量。这也很难维护。相反,我们建议分离一个租户元素,以形成一组非冗余,清晰和简化的角色和权限。通过将两个模型应用于相同的具体场景,可以看出我们的模型对MTAS的好处。我们发现,与MTAS相比,我们的模型给出了更简洁,更小的规则集。我们还将说明如何通过XACML格式的实际可行示例策略来使用我们的模型。原型系统构建为授权服务(AaaS)平台,是云服务部分的中间层,可以由同一提供商或跨提供商使用。最后,它在不同的硬件上进行了测试。结果表明该模型是可扩展的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号