首页> 外文期刊>Cloud Computing, IEEE Transactions on >Camflow: Managed Data-Sharing for Cloud Services
【24h】

Camflow: Managed Data-Sharing for Cloud Services

机译:Camflow:云服务的托管数据共享

获取原文
获取原文并翻译 | 示例
           

摘要

A model of cloud services is emerging whereby a few trusted providers manage the underlying hardware and communications whereas many companies build on this infrastructure to offer higher level, cloud-hosted PaaS services and/or SaaS applications. From the start, strong isolation between cloud tenants was seen to be of paramount importance, provided first by virtual machines (VM) and later by containers, which share the operating system (OS) kernel. Increasingly it is the case that applications also require facilities to effect isolation and protection of data managed by those applications. They also require flexible data sharing with other applications, often across the traditional cloud-isolation boundaries; for example, when government, consisting of different departments, provides services to its citizens through a common platform. These concerns relate to the management of data. Traditional access control is application and principal/role specific, applied at policy enforcement points, after which there is no subsequent control over where data flows;a crucial issue once data has left its owner’s control by cloud-hosted applications andwithin cloud-services. Information Flow Control (IFC), in addition, offers system-wide, end-to-end, flow control based on the properties of the data. We discuss the potential of cloud-deployed IFC for enforcing owners’ data flow policy with regard to protection and sharing, aswell as safeguarding against malicious or buggy software. In addition, the audit log associated with IFC provides transparency and offers system-wide visibility over data flows. This helps those responsible to meet their data management obligations, providing evidence of compliance, and aids in the identification ofpolicy errors and misconfigurations. We present our IFC model and describe and evaluate our IFC architecture and implementation (CamFlow). This comprises an OS level implementation of IFC with support for application management, together with an IFC-enabled middleware.
机译:云服务的模型正在兴起,通过这种模型,一些受信任的提供商可以管理底层的硬件和通信,而许多公司则在此基础架构上构建以提供更高级别的,云托管的PaaS服务和/或SaaS应用程序。从一开始,就将云租户之间的强烈隔离视为最重要的,首先由虚拟机(VM)提供,然后由共享操作系统(OS)内核的容器提供。越来越多的情况是,应用程序还需要一些设施来实现对那些应用程序管理的数据的隔离和保护。他们还需要与其他应用程序灵活地共享数据,通常跨传统的云隔离边界。例如,由不同部门组成的政府通过一个公共平台为其公民提供服务。这些问题与数据管理有关。传统的访问控制是在策略执行点应用的,特定于应用程序和主体/角色,此后就无法对数据的流向进行后续控制;一旦数据由云托管的应用程序和云服务中的所有者控制,则是一个关键问题。此外,信息流控制(IFC)根据数据的属性提供系统范围的端到端流控制。我们讨论了部署了云的IFC在保护和共享以及防御恶意软件或Bug软件方面执行所有者数据流策略的潜力。此外,与IFC相关的审核日志提供了透明度,并提供了整个系统对数据流的可见性。这有助于责任人履行其数据管理义务,提供合规证据,并帮助识别策略错误和配置错误。我们将介绍我们的IFC模型,并描述和评估我们的IFC体系结构和实现(CamFlow)。这包括支持应用程序管理的IFC的OS级别实现以及支持IFC的中间件。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号