A Metric-Based Approach to Assess Risk for "On Cloud" Federated Identity Management

被引:21
|
作者
Arias-Cabarcos, Patricia [1 ]
Almenarez-Mendoza, Florina [1 ]
Marin-Lopez, Andres [1 ]
Diaz-Sanchez, Daniel [1 ]
Sanchez-Guerrero, Rosa [1 ]
机构
[1] Univ Carlos III Madrid, Dept Telemat Engn, Madrid 28911, Spain
关键词
Trust management; Cloud computing; Risk assessment metrics; SAML; Federation; SECURITY ISSUES;
D O I
10.1007/s10922-012-9244-2
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The cloud computing paradigm is set to become the next explosive revolution on the Internet, but its adoption is still hindered by security problems. One of the fundamental issues is the need for better access control and identity management systems. In this context, Federated Identity Management (FIM) is identified by researchers and experts as an important security enabler, since it will play a vital role in allowing the global scalability that is required for the successful implantation of cloud technologies. However, current FIM frameworks are limited by the complexity of the underlying trust models that need to be put in place before inter-domain cooperation. Thus, the establishment of dynamic federations between the different cloud actors is still a major research challenge that remains unsolved. Here we show that risk evaluation must be considered as a key enabler in evidence-based trust management to foster collaboration between cloud providers that belong to unknown administrative domains in a secure manner. In this paper, we analyze the Federated Identity Management process and propose a taxonomy that helps in the classification of the involved risks in order to mitigate vulnerabilities and threats when decisions about collaboration are made. Moreover, a set of new metrics is defined to allow a novel form of risk quantification in these environments. Other contributions of the paper include the definition of a generic hierarchical risk aggregation system, and a descriptive use-case where the risk computation framework is applied to enhance cloud-based service provisioning.
引用
收藏
页码:513 / 533
页数:21
相关论文
共 50 条
  • [1] A Metric-Based Approach to Assess Risk for “On Cloud” Federated Identity Management
    Patricia Arias-Cabarcos
    Florina Almenárez-Mendoza
    Andrés Marín-López
    Daniel Díaz-Sánchez
    Rosa Sánchez-Guerrero
    [J]. Journal of Network and Systems Management, 2012, 20 : 513 - 533
  • [2] A metric-based approach to assess class testability
    Singh, Yogesh
    Saha, Anju
    [J]. AGILE PROCESSES IN SOFTWARE ENGINEERING AND EXTREME PROGRAMMING, PROCEEDINGS, 2008, 9 : 224 - 225
  • [3] A Dynamic Federated Identity Management Approach for Cloud-Based Environments
    Keltoum, Bendiab
    Samia, Boucherkha
    [J]. PROCEEDINGS OF THE SECOND INTERNATIONAL CONFERENCE ON INTERNET OF THINGS, DATA AND CLOUD COMPUTING (ICC 2017), 2017,
  • [4] Metric-based approach to assess sustainable manufacturing performance at manufacturing process levels
    Murad, Marcio de Queiroz
    Sales, Wisley Falco
    Feraressi, Valtair Antonio
    [J]. INTERNATIONAL JOURNAL OF SUSTAINABLE ENGINEERING, 2021, 14 (06) : 1342 - 1352
  • [5] A Review of Federated Identity Management of OpenStack Cloud
    Shere, Rohit
    Srivastava, Sonika
    Pateriya, R. K.
    [J]. 2017 INTERNATIONAL CONFERENCE ON RECENT INNOVATIONS IN SIGNAL PROCESSING AND EMBEDDED SYSTEMS (RISE), 2017, : 516 - 520
  • [6] A multichannel approach to metric-based SAR autofocus
    Morrison, RL
    Do, MN
    [J]. 2005 International Conference on Image Processing (ICIP), Vols 1-5, 2005, : 2441 - 2444
  • [7] An Authentication Trust Metric for Federated Identity Management Systems
    Gomi, Hidehito
    [J]. SECURITY AND TRUST MANAGEMENT, 2011, 6710 : 116 - 131
  • [8] Cloud bursting galaxy: federated identity and access management
    Jalili, Vahid
    Afgan, Enis
    Taylor, James
    Goecks, Jeremy
    [J]. BIOINFORMATICS, 2020, 36 (01) : 1 - 9
  • [9] Secure Identity Management System for Federated Cloud Environment
    Habiba, Umme
    Masood, Rahat
    Shibli, Muhammad Awais
    [J]. SOFTWARE ENGINEERING, ARTIFICIAL INTELLIGENCE, NETWORKING AND PARALLEL/DISTRIBUTED COMPUTING, 2015, 569 : 17 - 33
  • [10] A Metric-Based Validation Process to Assess the Realism of Synthetic Power Grids
    Birchfield, Adam B.
    Schweitzer, Eran
    Athari, Mir Hadi
    Xu, Ti
    Overbye, Thomas J.
    Scaglione, Anna
    Wang, Zhifang
    [J]. ENERGIES, 2017, 10 (08)