期刊论文详细信息
Frontiers in ICT
SAFAX – An Extensible Authorization Service for Cloud Environments
den Hartog, Jerry1  Egner, Alexandru Ionut1  Zannone, Nicola1  Kaluvuri, Samuel Paul1 
[1] Eindhoven University of Technology, Netherlands
关键词: Access control;    Clouds;    Security-as-a-service;    XACML;    Architectural framework;   
DOI  :  10.3389/fict.2015.00009
学科分类:计算机网络和通讯
来源: Frontiers
PDF
【 摘 要 】

Cloud storage services have become increasingly popular in recent years. Users are often registered to multiple cloud storage services that suit different needs. However, the ad-hoc manner in which data sharing between users is implemented leads to issues for these users. For instance, users are required to define different access control policies for each cloud service they use and are responsible for synchronizing their policies across different cloud providers. Users do not have access to a uniform and expressive method to deal with authorization. Current authorization solutions cannot be applied as-is, since they cannot cope with challenges specific to cloud environments. In this paper, we analyze the challenges of data sharing in multi-cloud environments and propose SAFAX, an XACML based authorization service designed to address these challenges. SAFAX's architecture allows users to deploy their access control policies in a standard format, in a single location, and augment policy evaluation with information from user selectable external trust services. We describe the architecture of SAFAX, a prototype implementation based on this architecture, illustrate the extensibility through external trust services and discuss the benefits of using SAFAX from both the user's and cloud provider's perspectives.

【 授权许可】

CC BY   

【 预 览 】
附件列表
Files Size Format View
RO201904029495801ZK.pdf 2979KB PDF download
  文献评价指标  
  下载次数:21次 浏览次数:59次