...
首页> 外文期刊>Computer networks >Consolidated Identity Management System for secure mobile cloud computing
【24h】

Consolidated Identity Management System for secure mobile cloud computing

机译:用于安全移动云计算的整合身份管理系统

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Security issues in cloud computing are shown to be the biggest obstacle that could lower the wide benefits of the cloud systems. This obstacle may be strengthened when cloud services are accessed by mobile devices. Mobile devices could be easily lost or stolen and hence, they are easy to compromise. Additionally, mobile users tend to store access credentials, passwords and other Personal Identifiable Information (PII) in an improperly protected way. We conduct a survey and found that more than 66% of the surveyed users store PIIs in unprotected text files, cookies, or applications. To strengthen the legitimate access process over the clouds and to facilitate authentication and authorization with multiple cloud service providers, third-party Identity Management Systems (IDMs) have been proposed and implemented. In this paper, we discuss the limitations of the state-of-the-art cloud IDMs with respect to mobile clients. Specifically, we show that the current IDMs are vulnerable to three attacks, namely - IDM server compromise, mobile device compromise, and network traffic interception. Most importantly, we propose and validate a new IDM architecture dubbed Consolidated IDM (CIDM) that countermeasures these attacks. We conduct experiments to evaluate the performance and the security guarantees of CIDM and compare them with those of current IDM systems. Our experiments show that CIDM provides its clients with better security guarantees and that it has less energy and communication overhead compared to the current IDM systems.
机译:事实证明,云计算中的安全性问题是最大的障碍,可能会降低云系统的广泛利益。当移动设备访问云服务时,这一障碍可能会得到加强。移动设备很容易丢失或被盗,因此很容易受到攻击。此外,移动用户倾向于以不适当的保护方式存储访问凭据,密码和其他个人身份信息(PII)。我们进行了一项调查,发现超过66%的被调查用户将PII存储在不受保护的文本文件,Cookie或应用程序中。为了加强云上的合法访问过程并促进与多个云服务提供商的身份验证和授权,已经提出并实施了第三方身份管理系统(IDM)。在本文中,我们讨论了有关移动客户端的最新云IDM的局限性。具体来说,我们显示出当前的IDM容易受到三种攻击,即-IDM服务器攻击,移动设备攻击和网络流量拦截。最重要的是,我们提出并验证了一种新的IDM体系结构,称为“综合IDM(CIDM)”,它可以对付这些攻击。我们进行实验以评估CIDM的性能和安全性,并将其与当前IDM系统的性能和安全性进行比较。我们的实验表明,与当前的IDM系统相比,CIDM为客户提供了更好的安全保证,并且具有更少的能源和通信开销。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号