首页> 外文会议>National Conference on Information Assurance >User Centric Access control policy management framework for Cloud applications
【24h】

User Centric Access control policy management framework for Cloud applications

机译:云应用程序中心访问控制策略管理框架

获取原文

摘要

Cloud computing environment is a collection of various Cloud applications deployed by different Cloud service vendors for their customers. The online availability, variety and easy access of Cloud applications allow users to create, upload and store numerous resources across the Cloud. However, Protection of these resources from different security threats in Cloud environment is still a serious concern for the Cloud users. Cloud applications provide diverse and complex authorization and access control mechanisms to different Cloud users. Moreover, Access control is limited and tightly bound to the functionality of the applications and does not cater the access control requirements of individual users. Securing every resource with different, complex and limited access control solutions is a tedious task and results in poorly protected resources susceptible to unauthorized access and different other security threats. A new approach to access control in Cloud environment is presented in this paper. It externalizes access control from Cloud applications and enables users to create, and manage access control policies on their resources according to their own security and access control requirements. The framework also provides users with a central control point, standard policy definition language and easy to use interface to specify and manage access control on all their resources scattered across the Cloud. We presented the framework and described the protocol which defines the interaction between different components of the system to specify and enforce User-Centric policies using XACML standards.
机译:云计算环境是由不同云服务供应商为客户部署的各种云应用程序的集合。云应用程序的在线可用性,品种和轻松访问允许用户在云中创建,上传和存储众多资源。但是,保护这些资源来自云环境的不同安全威胁仍然是云用户的严重关注。云应用程序为不同的云用户提供多样化和复杂的授权和访问控制机制。此外,访问控制受到应用的有限且紧密绑定到应用程序的功能,并且不符合各个用户的访问控制要求。使用不同,复杂和有限的访问控制解决方案确保每个资源是一个繁琐的任务,导致保护不良的资源,易于未经授权的访问和不同的其他安全威胁。本文介绍了一种新的访问控制控制中的新方法。它将访问控制从云应用程序外,并使用户根据自己的安全性和访问控制要求创建和管理您的资源的访问控制策略。该框架还为用户提供中央控制点,标准策略定义语言,易于使用界面,以指定和管理跨越云分散的所有资源的访问控制。我们介绍了该框架并描述了定义了系统的不同组件之间的交互的协议,以指定和强制使用XACML标准来配置用户以用户为中心的策略。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号