首页> 外文学位 >A semantic based policy management framework for cloud computing environments.
【24h】

A semantic based policy management framework for cloud computing environments.

机译:用于云计算环境的基于语义的策略管理框架。

获取原文
获取原文并翻译 | 示例

摘要

Cloud computing paradigm has gained tremendous momentum and generated intensive interest. Although security issues are delaying its fast adoption, cloud computing is an unstoppable force and we need to provide security mechanisms to ensure its secure adoption.;In this dissertation, we mainly focus on issues related to policy management and access control in the cloud. Currently, users have to use diverse access control mechanisms to protect their data when stored on the cloud service providers (CSPs). Access control policies may be specified in different policy languages and heterogeneity of access policies pose significant problems. An ideal policy management system should be able to work with all data regardless of where they are stored. Semantic Web technologies when used for policy management, can help address the crucial issues of interoperability of heterogeneous CSPs.;In this dissertation, we propose a semantic based policy management framework for cloud computing environments which consists of two main components, namely policy management and specification component and policy evolution component. In the policy management and specification component, we first introduce policy management as a service (PMaaS), a cloud based policy management framework that give cloud users a unified control point for specifying authorization policies, regardless of where the data is stored. Then, we present semantic based policy management framework which enables users to specify access control policies using semantic web technologies and helps address heterogeneity issues of cloud computing environments. We also model temporal constraints and restrictions in GTRBAC using OWL and show how ontologies can be used to specify temporal constraints. We present a proof of concept implementation of the proposed framework and provide some performance evaluation.;In the policy evolution component, we propose to use role mining techniques to deal with policy evolution issues and present StateMiner, a heuristic algorithm to find an RBAC state as close as possible to both the deployed RBAC state and the optimal state. We also implement the proposed algorithm and perform some experiments to demonstrate its effectiveness.;Keywords: cloud computing, policy management, semantic web, access control, policy evolution, role mining.
机译:云计算范例获得了巨大的发展动力,并引起了广泛的关注。尽管安全问题正在阻碍其快速采用,但是云计算是不可阻挡的力量,我们需要提供安全机制来确保其安全采用。本文主要研究与云中的策略管理和访问控制有关的问题。当前,用户存储在云服务提供商(CSP)上时,必须使用各种访问控制机制来保护其数据。可以用不同的策略语言指定访问控制策略,并且访问策略的异构性带来了严重的问题。理想的策略管理系统应该能够处理所有数据,而不管它们存储在何处。语义Web技术用于策略管理时,可以帮助解决异构CSP的互操作性这一关键问题。本文针对云计算环境提出了一种基于语义的策略管理框架,该框架由策略管理和规范两大部分组成。组件和政策演变组件。在策略管理和规范组件中,我们首先介绍策略管理即服务(PMaaS),这是一种基于云的策略管理框架,可为云用户提供用于指定授权策略的统一控制点,而不管数据存储在何处。然后,我们提出了基于语义的策略管理框架,该框架使用户能够使用语义Web技术指定访问控制策略,并帮助解决云计算环境的异构性问题。我们还使用OWL对GTRBAC中的时间约束和约束建模,并展示了如何使用本体来指定时间约束。我们提出了所提出框架的概念实施证明,并提供了一些性能评估。在策略演化组件中,我们建议使用角色挖掘技术来处理政策演化问题,并提出StateMiner,一种启发式算法来查找RBAC状态为尽可能接近已部署的RBAC状态和最佳状态。关键字:云计算,策略管理,语义网,访问控制,策略演化,角色挖掘。

著录项

  • 作者

    Takabi, Hassan.;

  • 作者单位

    University of Pittsburgh.;

  • 授予单位 University of Pittsburgh.;
  • 学科 Information Technology.;Computer Science.;Web Studies.
  • 学位 Ph.D.
  • 年度 2013
  • 页码 124 p.
  • 总页数 124
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号