...
首页> 外文期刊>Concurrency and computation: practice and experience >Multi-tenancy authorization models for collaborative cloud services
【24h】

Multi-tenancy authorization models for collaborative cloud services

机译:协作云服务的多租户授权模型

获取原文
获取原文并翻译 | 示例
           

摘要

The cloud service model intrinsically caters to multiple tenants, most obviously not only in public clouds butrnalso in private clouds for large organizations. Currently, most cloud service providers isolate user activitiesrnand data within a single tenant boundary with no or minimum cross-tenant interaction. It is anticipatedrnthat this situation will evolve soon to foster cross-tenant collaboration supported by Authorization as arnService. At present, there is no widely accepted model for cross-tenant authorization. Recently, Calerornet al. informally presented a multi-tenancy authorization system (MTAS), which extends the well-knownrnrole-based access control model by building trust relations among collaborating tenants. In this paper, wernformalize this MTAS model and propose extensions for finer-grained cross-tenant trust. We also develop anrnadministration model for MTAS. We demonstrate the utility and practical feasibility of MTAS by means ofrnan example policy specification in extensible access control markup language. To further test the metricsrnof the model, we develop a prototype system and conduct experiments on it. The result shows that thernprototype has 12-ms policy decision overhead on average and is scalable. We anticipate that researchersrnwill develop additional multi-tenant authorization models before eventual consolidation and convergence tornstandard industry practice.
机译:云服务模型从本质上迎合了多个租户,最明显的是,不仅在公共云中,而且在大型企业的私有云中。当前,大多数云服务提供商将用户活动和数据隔离在单个租户边界内,而没有或很少有跨租户交互。可以预见,这种情况将很快发展,以促进授权为arnService的跨租户协作。目前,还没有被广泛接受的跨租户授权模型。最近,Calerornet等人。非正式地提出了一个多租户授权系统(MTAS),该系统通过在协作租户之间建立信任关系来扩展基于已知角色的访问控制模型。在本文中,我们对该MTAS模型进行了形式化,并提出了扩展以实现更细粒度的跨租户信任。我们还为MTAS开发了anrnadministration模型。我们通过可扩展的访问控制标记语言中的示例策略规范,演示了MTAS的实用性和实践可行性。为了进一步测试该模型的度量标准,我们开发了一个原型系统并对其进行了实验。结果表明,该原型平均具有12毫秒的策略决策开销,并且具有可扩展性。我们预计研究人员将在最终合并和融合标准行业惯例之前开发更多的多租户授权模型。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号