首页> 外文会议>International Conference on Information and Communications Security >SDAC: A New Software-Defined Access Control Paradigm for Cloud-Based Systems
【24h】

SDAC: A New Software-Defined Access Control Paradigm for Cloud-Based Systems

机译:SDAC:用于基于云系统的新软件定义的访问控制范例

获取原文

摘要

A cloud-based system usually runs in multiple geographically distributed datacenters, making the deployment of effective access control models extremely challenging. This paper presents a novel software-defined paradigm, called SDAC, to achieve scoped, flexible and dynamic access control. In particular, SDAC enables the tenant-specific generation of access control model and policy (SMPolicy in short), as well as their dynamic configuration by the cloud-hosting applications. To achieve that, SDAC uses an access control meta-model to initiate and customize different SMPolicies. Also, SDAC is decoupled into control plane and policy plane, allowing the global SMPolicy generated at the control plane to be efficiently propagated to the policy plane and enforced locally in different datacenters. As such, the local SMPolicy of a tenant can be synchronized with its global SMPolicy only when it's necessary, e.g., a user or a role cannot be identified. To validate the feasibility and effectiveness of SDAC, we implement a prototype in a carrier grade datacenter. The experimental results demonstrate that SDAC can achieve the desirable properties, maintain the throughput at a reasonable level regardless of the varying number of tenants, users, and datacenters, highly preserving scalability and adaptability.
机译:基于云的系统通常在多个地理上分布式数据中心运行,使有效访问控制模型的部署非常具有挑战性。本文介绍了一种名为SDAC的新型软件定义范例,以实现范围,灵活和动态访问控制。特别是,SDAC使得特定于租户的访问控制模型和策略(简称SMPolicy),以及云托管应用程序的动态配置。为此,SDAC使用访问控制元模型来启动和自定义不同的SMPolicies。此外,SDAC被解耦到控制平面和策略平面中,允许在控制平面上产生全局SMPolicy以有效地传播到策略平面并在不同的数据中心本地实施。因此,租户的本地SMPolicy才能与其全球SMPolicy同步,只有在必要时,例如,不能识别用户或角色。为了验证SDAC的可行性和有效性,我们在运营商级数据中心实现了原型。实验结果表明,SDAC可以达到所需的性质,无论不同数量的租户,用户和数据中心,高度保存可扩展性和适应性如何,保持吞吐量。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号