Fine-Grained Access Control for Microservices

被引:10
|
作者
Nehme, Antonio [1 ]
Jesus, Vitor [1 ]
Mahbub, Khaled [1 ]
Abdallah, Ali [1 ]
机构
[1] Birmingham City Univ, Sch Comp & Digital Technol, Birmingham, England
关键词
Microservices; Security; Confused deputy attack; Gateways; Access control;
D O I
10.1007/978-3-030-18419-3_19
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Microservices-based applications are considered to be a promising paradigm for building large-scale digital systems due to their flexibility, scalability, and agility of development. To achieve the adoption of digital services, applications holding personal data must be secure while giving end-users as much control as possible. On the other hand, for software developers, the adoption of a security solution for microservices requires it to be easily adaptable to the application context and requirements while fully exploiting reusability of security components. This paper proposes a solution that targets key security challenges of microservice-based applications. Our approach relies on a coordination of security components, and offers a fine-grained access control in order to minimise the risks of token theft, session manipulation, and a malicious insider; it also renders the system resilient against confused deputy attacks. This solution is based on a combination of OAuth 2 and XACML open standards, and achieved through reusable security components integrated with microservices.
引用
下载
收藏
页码:285 / 300
页数:16
相关论文
共 50 条
  • [1] Towards a fine-grained access control for Cloud
    Msahli, Mounira
    Chen, Xiuzhen
    Serhrouchni, Ahmed
    2014 IEEE 11TH INTERNATIONAL CONFERENCE ON E-BUSINESS ENGINEERING (ICEBE), 2014, : 286 - 291
  • [2] Delegatable access control for fine-grained XML
    Wu, J
    Seberry, J
    Mu, Y
    Ruan, C
    11TH INTERNATIONAL CONFERENCE ON PARALLEL AND DISTRIBUTED SYSTEMS WORKSHOPS, VOL II, PROCEEDINGS,, 2005, : 270 - 274
  • [3] Fine-grained integration of access control policies
    Rao, Prathima
    Lin, Dan
    Bertino, Elisa
    Li, Ninghui
    Lobo, Jorge
    COMPUTERS & SECURITY, 2011, 30 (2-3) : 91 - 107
  • [4] Fine-grained Access Control to Web Databases
    Roichman, Alex
    Gudes, Ehud
    SACMAT'07: PROCEEDINGS OF THE 12TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES, 2007, : 31 - 40
  • [5] A Fine-Grained Image Access Control Model
    Al Bouna, Bechara
    Chbeir, Richard
    Gabillon, Alban
    Capolsini, Patrick
    8TH INTERNATIONAL CONFERENCE ON SIGNAL IMAGE TECHNOLOGY & INTERNET BASED SYSTEMS (SITIS 2012), 2012, : 603 - 612
  • [6] Fine-grained access control of PDM and CAPP
    Feng, SH
    Jiang, ZL
    ADVANCES IN MATERIALS MANUFACTURING SCIENCE AND TECHNOLOGY, 2004, 471-472 : 573 - 576
  • [7] Fine-grained access control for cloud computing
    Ye, Xinfeng
    Khoussainov, Bakh
    INTERNATIONAL JOURNAL OF GRID AND UTILITY COMPUTING, 2013, 4 (2-3) : 160 - 168
  • [8] Access policy sheet for access control in fine-grained XML
    Wu, J
    Mu, Y
    Seberry, J
    Ruan, C
    EMBEDDED AND UBIQUITOUS COMPUTING - EUC 2005 WORKSHOPS, PROCEEDINGS, 2005, 3823 : 1273 - 1282
  • [9] Log2Policy: An Approach to Generate Fine-Grained Access Control Rules for Microservices from Scratch
    Xu, Shaowen
    Zhou, Qihang
    Huang, Heqing
    Jia, Xiaoqi
    Du, Haichao
    Chen, Yang
    Xie, Yamin
    39TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, ACSAC 2023, 2023, : 229 - 240
  • [10] The Fine-Grained Security Access Control of Spatial Data
    Ma, Fuguang
    Gao, Yong
    Yan, Menglong
    Xu, Fuchun
    Liu, Ding
    2010 18TH INTERNATIONAL CONFERENCE ON GEOINFORMATICS, 2010,