会议论文详细信息
Doctoral Symposium of ESSoS 2012.
Federated authorization for SaaS applications
计算机科学;
Maarten Decat ; Bert Lagaisse ; Wouter Joosen
Others  :  http://ceur-ws.org/Vol-834/paper9_essosds2012.pdf
PID  :  33642
学科分类:计算机科学(综合)
来源: CEUR
PDF
【 摘 要 】

With Software-as-a-Service (SaaS), a centrally hosted web-based application is offered to a large number of customer organizations called tenants, each using multiple applications. The tenant and provider each work in their own authoritative and administrative domain, leading to a federated architecture and raising the bar for security and access control. Access control with SaaS applications is about protecting the tenant's data at the provider's side using the tenant's policies and user information. In current practice however, all access control policies are evaluated at the provider's side, distributing and fragmenting the ten- ant's policies over the multiple applications it uses. Moreover, all necessary user information now has to be shared with the provider, resulting in the disclosure of confidential tenant data. Therefore, we propose the concept of federated authorization, a combination of externalized authorization and federated access control techniques whereby the tenant's access control policies are evaluated at the tenat's side using loval data.

【 预 览 】
附件列表
Files Size Format View
Federated authorization for SaaS applications 149KB PDF download
  文献评价指标  
  下载次数:16次 浏览次数:25次