...
首页> 外文期刊>Journal of network and computer applications >Interoperable, dynamic and privacy-preserving access control for cloud data storage when integrating heterogeneous organizations
【24h】

Interoperable, dynamic and privacy-preserving access control for cloud data storage when integrating heterogeneous organizations

机译:集成异构组织时,可互操作,动态且保留隐私的云数据访问控制

获取原文
获取原文并翻译 | 示例
           

摘要

Cloud computing is extensively used as an integration means in varies application domains, spanning from the healthcare to the manufacturing, aiming at achieving an easy-to-access and elastic data storage and exchange among heterogeneous and geographically sparse organizations. This cloud-based integration poses crucial security issues related to the data protection from unauthorized access to the outsourced data, which calls for a proper access control solution. However, the heterogeneity among the organizations exacerbates this problem, demanding an interoperable authorization scheme, where multiple access control models must co-exist. The current literature is rich of academic solutions and standards to have an interoperable exchange of security policies and definition of authorization rules, but lacks an effective support to let different access control models to fully coexist. Moreover, the possibility of stealing authentication credentials and authorization claims paves the way to conducting masquerading attacks that cannot be treated by traditional static authorization solutions, but more dynamic approaches are needed. Last but not least, the continuous interaction of users with the cloud over the time has the vulnerability of exposing personal information to malicious adversaries and to let them trace the user activities. In this work, we propose to solve these three issues by having an ontology-based access control solution, to encompass trust within the authorization process and to use pseudonyms to preserve the user privacy.
机译:从医疗保健到制造业,云计算被广泛用作各种应用领域中的集成手段,旨在实现易于访问的弹性数据存储以及异构组织和地理稀疏组织之间的交换。这种基于云的集成提出了与数据保护相关的关键安全问题,以防止未经授权访问外包数据,这需要适当的访问控制解决方案。但是,组织之间的异质性加剧了这个问题,因此需要一种可互操作的授权方案,其中必须共存多个访问控制模型。当前的文献丰富的学术解决方案和标准具有可互操作的安全策略交换和授权规则的定义,但是缺乏有效的支持来使不同的访问控制模型完全共存。此外,窃取身份验证凭证和授权声明的可能性为进行伪装攻击铺平了道路,而传统的静态授权解决方案则无法解决这种伪装攻击,但是需要更多的动态方法。最后但并非最不重要的一点是,随着时间的推移,用户与云的持续交互具有将个人信息暴露给恶意攻击者并让他们跟踪用户活动的漏洞。在这项工作中,我们建议通过使用基于本体的访问控制解决方案来解决这三个问题,将信任包含在授权过程中,并使用假名来保护用户隐私。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号