A Usage Control Based Architecture for Cloud Environments

被引:13
|
作者
Tavizi, Tina [1 ]
Shajari, Mehdi [1 ]
Dodangeh, Peyman [2 ]
机构
[1] Amirkabir Univ Technol, Dept Comp Engn & IT, Tehran, Iran
[2] Sharif Univ Technol, Dept Comp Engn, Tehran, Iran
关键词
cloud computing; access control; usage control; UCON; Enforcement architecture; authorization; obligation; condition; XACML; ACCESS-CONTROL;
D O I
10.1109/IPDPSW.2012.193
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Today modern computing systems leverage distributed models such as cloud, grid, etc. One of the obstacles of wide spreading these distributed computing models is security challenges which includes access control problem. These computing models because of providing features like on-demand self-service, ubiquitous network access, rapid elasticity and scalability, having dynamic infrastructure and offering measured service, need a powerful and continuous control over access and usage session. Usage control (UCON) model is emerged to cover some drawbacks of traditional access control models with features like attribute mutability and continuity of control. Several recent works have been done to apply UCON for distributed computing environments, but none of them could cover all aspects of the model. In this paper we propose an architecture for applying UCON model in cloud environments. Moreover we present a new architecture for obligation handling. We also introduce a new approach to handle attribute mutability. For implementation we have extended XACML syntax and semantics as policy language and leveraged Sun's OASIS XACML implementation.
引用
下载
收藏
页码:1534 / 1539
页数:6
相关论文
共 50 条
  • [1] Architecture, Workflows, and Prototype for Stateful Data Usage Control in Cloud
    Lazouski, Aliaksandr
    Mancini, Gaetano
    Martinelli, Fabio
    Mori, Paolo
    2014 IEEE SECURITY AND PRIVACY WORKSHOPS (SPW 2014), 2014, : 23 - 30
  • [2] Data Usage Control: Introducing a New Framework for Cloud and Mobile Environments
    Mori, Paolo
    Saracino, Andrea
    Di Cerbo, Francesco
    ERCIM NEWS, 2016, (106): : 30 - +
  • [3] Service Usage Metering in Hybrid Cloud Environments
    Naik, Vijay K.
    Beaty, Kirk
    Kundu, Ashish
    2014 IEEE INTERNATIONAL CONFERENCE ON CLOUD ENGINEERING (IC2E), 2014, : 253 - 260
  • [4] Usage Control on Cloud systems
    Carniani, Enrico
    D'Arenzo, Davide
    Lazouski, Aliaksandr
    Martinelli, Fabio
    Mori, Paolo
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2016, 63 : 37 - 55
  • [5] Data Usage Control for the Cloud
    Kelbert, Florian
    PROCEEDINGS OF THE 2013 13TH IEEE/ACM INTERNATIONAL SYMPOSIUM ON CLUSTER, CLOUD AND GRID COMPUTING (CCGRID 2013), 2013, : 156 - 159
  • [6] Efficient Usage of Network Bandwidth in the Cloud Architecture
    Chen, Rick C. S.
    Kao, Chung-Ting
    Chung, Hui-Kuang
    2012 NINTH IEEE INTERNATIONAL CONFERENCE ON E-BUSINESS ENGINEERING (ICEBE), 2012, : 338 - 343
  • [7] Usage Control in Cloud Systems
    Lazouski, Aliaksandr
    Mancini, Gaetano
    Martinelli, Fabio
    Mori, Paolo
    2012 INTERNATIONAL CONFERENCE FOR INTERNET TECHNOLOGY AND SECURED TRANSACTIONS, 2012, : 202 - 207
  • [8] Usage Control in Cloud Federations
    Anastasi, Gaetano F.
    Carlini, Emanuele
    Coppola, Massimo
    Dazzi, Patrizio
    Lazouski, Aliaksandr
    Martinelli, Fabio
    Mancini, Gaetano
    Mori, Paolo
    2014 IEEE INTERNATIONAL CONFERENCE ON CLOUD ENGINEERING (IC2E), 2014, : 141 - 146
  • [9] Modeling Educational Usage of Cloud-Based Tools in Virtual Learning Environments
    Morales Chan, Miguel
    Barchino Plata, Roberto
    Amelio Medina, Jose
    Alario-Hoyos, Carlos
    Hernandez Rizzardini, Rocael
    IEEE ACCESS, 2019, 7 : 13347 - 13354
  • [10] Cloud-based control systems: towards the control architecture in cloud computing era
    Yuanqing XIA
    Science China(Information Sciences), 2024, 67 (10) : 386 - 388