首页> 外文OA文献 >A SEMANTIC BASED POLICY MANAGEMENT FRAMEWORK FOR CLOUD COMPUTING ENVIRONMENTS
【2h】

A SEMANTIC BASED POLICY MANAGEMENT FRAMEWORK FOR CLOUD COMPUTING ENVIRONMENTS

机译:基于语义的云计算环境策略管理框架

摘要

Cloud computing paradigm has gained tremendous momentum and generated intensive interest.udAlthough security issues are delaying its fast adoption, cloud computing is an unstoppable force and we need to provide security mechanisms to ensure its secure adoption.ududIn this dissertation, we mainly focus on issues related to policy management and access control in the cloud.udCurrently, users have to use diverse access control mechanisms to protect their data when stored on the cloud service providers (CSPs).udAccess control policies may be specified in different policy languages and heterogeneity of access policies pose significant problems.An ideal policy management system should be able to work with all data regardless of where they are stored.udSemantic Web technologies when used for policy management, can help address the crucial issues of interoperability of heterogeneous CSPs.ududIn this dissertation, we propose a semantic based policy management framework for cloud computing environments which consists of two main components, namely policy management and specification component and policy evolution component.udIn the policy management and specification component, we first introduce policy management as a service (PMaaS), a cloud based policy management framework that give cloud users a unified control point for specifying authorization policies, regardless of where the data is stored. Then, we present semantic based policy management framework which enables users to specify access control policies using semantic web technologies and helps address heterogeneity issues of cloud computing environments.udWe also model temporal constraints and restrictions in GTRBAC using OWL and show how ontologies can be used to specify temporal constraints.udWe present a proof of concept implementation of the proposed framework and provide some performance evaluation.ududIn the policy evolution component, we propose to use role mining techniques to deal with policy evolution issues and present StateMiner, a heuristic algorithm to find an RBAC state as close as possible to both the deployed RBAC state and the optimal state. We also implement the proposed algorithm and perform some experiments to demonstrate its effectiveness.
机译:尽管安全问题正在延迟其快速采用,但云计算是不可阻挡的力量,我们需要提供安全机制以确保其安全采用。 ud ud集中于与云中的策略管理和访问控制有关的问题。 ud当前,用户必须使用多种访问控制机制来保护存储在云服务提供商(CSP)上的数据。 ud访问控制策略可以在不同的策略中指定语言和访问策略的异构性带来了重大问题。理想的策略管理系统应该能够处理所有数据,无论它们存储在何处。 ud语义Web技术用于策略管理时,可以帮助解决异构的互操作性的关键问题CSP。 ud ud在本文中,我们提出了一种基于语义的云计算策略管理框架。 ng环境由两个主要组件组成,即策略管理和规范组件以及策略演化组件。 ud在策略管理和规范组件中,我们首先介绍策略管理即服务(PMaaS),这是一种基于云的策略管理框架,可为云提供用户可以使用统一的控制点来指定授权策略,而不管数据存储在何处。然后,我们提出了基于语义的策略管理框架,该框架使用户能够使用语义Web技术指定访问控制策略,并帮助解决云计算环境的异构性问题。 ud我们还使用OWL对GTRBAC中的时间约束和约束进行建模,并展示如何使用本体 ud ud在策略演化组件中,我们建议使用角色挖掘技术来处理策略演化问题,并提出StateMiner,这是一种确定性的框架。启发式算法,以找到尽可能接近已部署RBAC状态和最佳状态的RBAC状态。我们还实现了提出的算法并进行了一些实验以证明其有效性。

著录项

  • 作者

    Takabi Hassan;

  • 作者单位
  • 年度 2013
  • 总页数
  • 原文格式 PDF
  • 正文语种 {"code":"en","name":"English","id":9}
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号