earticle

논문검색

Blacklisting and Forgiving Coarse-grained Access Control for Cloud Computing

원문정보

초록

영어

Cloud security is a shared responsibility between cloud providers and users. Reaching to an agreement about the dynamic policies considered for the access control decision-making process is not an easy task in cloud computing. Such dynamic policies can be built in a coarse-grained sharing manner between cloud providers and data owners. The trust notation can provide these dynamic policies, based on multiple factors that can accurately compute the user’s trust level for the granting access entity. In this paper, we have introduced the formal trust definition, which imports a novel method to provide the basis for granting access. It is based on two factors and their semantic relations which investigate important measures for the cloud environment. Also, a new Blacklisting and Forgiving Coarse-grained Access Control (BF-CAC) model has been proposed. The proposed model supports changing the user’s assigned permissions dynamically based on its trust level. In addition, BF-CAC ensures secure resource sharing between potential untrusted tenants. The proposed model has been implemented on our private cloud environment based on OpenStack. Finally, the experimental results have indicated that the trust level is decaying over time, thus no user can be trusted forever. Also, the number of assigned permissions for the same user is dynamically changing with the user’s final trust level.

목차

Abstract
 1. Introduction
 2. Formal Trust
  2.1. Trust Factors and Relations
  2.2. Trust Formula and Dynamics
 3. Blacklisting and Forgiving Coarse-grained Access Control (BF-CAC)
  3.1. Stage One: Computing Trust Level
  3.2. Stage Two: Adjusting ABAC Access Policies
  3.3. Stage Three: Blacklisting and Forgiving
  3.4. Stage Four: User/Subject Authorization
 4. Implementation and Analysis
  4.1. Implementation
  4.2. Experimental Verification
 5. Related Work
 6. Conclusion and Future Extensions
 References

저자정보

  • Khaled Riad School of Computer and Communication Engineering, University of Science and Technology Beijing, Beijing, China / Mathematics Department, Faculty of Science, Zagazig University, Zagazig, Egypt

참고문헌

자료제공 : 네이버학술정보

    함께 이용한 논문

      ※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

      0개의 논문이 장바구니에 담겼습니다.