| Doctoral Symposium of ESSoS 2012. | |
| Federated authorization for SaaS applications | |
| 计算机科学; | |
| Maarten Decat ; Bert Lagaisse ; Wouter Joosen | |
| Others : http://ceur-ws.org/Vol-834/paper9_essosds2012.pdf PID : 33642 |
|
| 学科分类:计算机科学(综合) | |
| 来源: CEUR | |
PDF
|
|
【 摘 要 】
With Software-as-a-Service (SaaS), a centrally hosted web-based application is offered to a large number of customer organizations called tenants, each using multiple applications. The tenant and provider each work in their own authoritative and administrative domain, leading to a federated architecture and raising the bar for security and access control. Access control with SaaS applications is about protecting the tenant's data at the provider's side using the tenant's policies and user information. In current practice however, all access control policies are evaluated at the provider's side, distributing and fragmenting the ten- ant's policies over the multiple applications it uses. Moreover, all necessary user information now has to be shared with the provider, resulting in the disclosure of confidential tenant data. Therefore, we propose the concept of federated authorization, a combination of externalized authorization and federated access control techniques whereby the tenant's access control policies are evaluated at the tenat's side using loval data.
【 预 览 】
| Files | Size | Format | View |
|---|---|---|---|
| Federated authorization for SaaS applications | 149KB |
PDF