...
首页> 外文期刊>Cluster computing >SNUAGE: an efficient platform-as-a-service security framework for the cloud
【24h】

SNUAGE: an efficient platform-as-a-service security framework for the cloud

机译:SNUAGE:一种用于云的高效平台即服务安全框架

获取原文
获取原文并翻译 | 示例
           

摘要

In this paper we present SNUAGE, a platformas- a-service security framework for building secure and scalable multi-layered services based on the cloud computing model. SNUAGE ensures the authenticity, integrity, and confidentiality of data communication over the network links by creating a set of security associations between the data-bound components on the presentation layer and their respective data sources on the data persistence layer. SNUAGE encapsulates the security procedures, policies, and mechanisms in these security associations at the service development stage to form a collection of isolated and protected security domains. The secure communication among the entities in one security domain is governed and controlled by a standalone security processor and policy attached to this domain. This results into: (1) a safer data delivery mechanism that prevents security vulnerabilities in one domain from spreading to the other domains and controls the inter-domain information flow to protect the privacy of network data, (2) a reusable security framework that can be employed in existing platform-as-a-service environments and across diverse cloud computing service models, and (3) an increase in productivity and delivery of reliable and secure cloud computing services supported by a transparent programming model that relieves application developers from the intricate details of security programming. Last but not least, SNUAGE contributes to a major enhancement in the energy consumption and performance of supported cloud services by providing a suitable execution container in its protected security domains for a wide suite of energyand performance-efficient cryptographic constructs such as those adopted by policy-driven and content-based security protocols. An energy analysis of the system shows, via real energy measurements, major savings in energy consumption on the consumer devices as well as on the cloud servers. Moreover, a sample implementation of the presented security framework is developed using Java and deployed and tested in a real cloud computing infrastructure using the Google App Engine service platform. Performance benchmarks show that the proposed framework provides a significant throughput enhancement compared to traditional network security protocols such as the Secure Sockets Layer and the Transport Layer Security protocols.
机译:在本文中,我们介绍了SNUAGE,这是一种平台即服务安全框架,用于基于云计算模型构建安全且可扩展的多层服务。 SNUAGE通过在表示层上的数据绑定组件与数据持久层上的它们各自的数据源之间创建一组安全关联,来确保网络链路上数据通信的真实性,完整性和机密性。 SNUAGE在服务开发阶段将安全性过程,策略和机制封装在这些安全性关联中,以形成隔离和受保护的安全性域的集合。一个安全域中实体之间的安全通信由独立的安全处理器和附加到该域的策略控制和控制。这导致:(1)一种更安全的数据传递机制,可以防止一个域中的安全漏洞传播到其他域,并控制域间信息流以保护网络数据的隐私,(2)可重用的安全框架可以可以在现有的平台即服务环境中使用,并且可以跨多种云计算服务模型使用;(3)透明编程模型支持的生产率提高和可靠和安全的云计算服务的交付,从而使应用程序开发人员摆脱了复杂的工作安全编程的详细信息。最后但并非最不重要的一点是,SNUAGE通过在其受保护的安全域中提供合适的执行容器,以用于各种能源和性能高效的密码构造(例如,策略所采用的那些构造),从而大大提高了受支持的云服务的能耗和性能。驱动和基于内容的安全协议。该系统的能源分析通过真实的能源测量结果显示,在消费类设备以及云服务器上的能源消耗可大量节省。此外,使用Java开发了所提出的安全框架的示例实现,并使用Google App Engine服务平台在真实的云计算基础架构中对其进行了部署和测试。性能基准表明,与传统网络安全协议(如安全套接字层和传输层安全协议)相比,该框架可显着提高吞吐量。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号