Fine-Grained Access Control for Microservices

被引:10
|
作者
Nehme, Antonio [1 ]
Jesus, Vitor [1 ]
Mahbub, Khaled [1 ]
Abdallah, Ali [1 ]
机构
[1] Birmingham City Univ, Sch Comp & Digital Technol, Birmingham, England
关键词
Microservices; Security; Confused deputy attack; Gateways; Access control;
D O I
10.1007/978-3-030-18419-3_19
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Microservices-based applications are considered to be a promising paradigm for building large-scale digital systems due to their flexibility, scalability, and agility of development. To achieve the adoption of digital services, applications holding personal data must be secure while giving end-users as much control as possible. On the other hand, for software developers, the adoption of a security solution for microservices requires it to be easily adaptable to the application context and requirements while fully exploiting reusability of security components. This paper proposes a solution that targets key security challenges of microservice-based applications. Our approach relies on a coordination of security components, and offers a fine-grained access control in order to minimise the risks of token theft, session manipulation, and a malicious insider; it also renders the system resilient against confused deputy attacks. This solution is based on a combination of OAuth 2 and XACML open standards, and achieved through reusable security components integrated with microservices.
引用
收藏
页码:285 / 300
页数:16
相关论文
共 50 条
  • [31] THE RESEARCH OF SPREADSHEET BASED ON FINE-GRAINED ACCESS CONTROL
    Zheng Yanwei
    Feng Zhiquan
    FIFTH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTER THEORY AND ENGINEERING (ICACTE 2012), 2012, : 245 - 251
  • [32] A Fine-grained Access Control Model for Knowledge Graphs
    Valzelli, Marco
    Maurino, Andrea
    Palmonari, Matteo
    PROCEEDINGS OF THE 17TH INTERNATIONAL JOINT CONFERENCE ON E-BUSINESS AND TELECOMMUNICATIONS (SECRYPT), VOL 1, 2020, : 595 - 601
  • [33] Fine-grained access control based on Trusted Execution Environment
    Fan, Yongkai
    Liu, Shengle
    Tan, Gang
    Qiao, Fei
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2020, 109 : 551 - 561
  • [34] Linkable and traceable anonymous authentication with fine-grained access control
    Peng Li
    Junzuo Lai
    Dehua Zhou
    Lianguan Huang
    Meng Sun
    Wei Wu
    Ye Yang
    Frontiers of Computer Science, 2025, 19 (2)
  • [35] Fine-grained Access Control Scheme Based on Cloud Storage
    Niu, Xiaojie
    2017 INTERNATIONAL CONFERENCE ON COMPUTER NETWORK, ELECTRONIC AND AUTOMATION (ICCNEA), 2017, : 512 - 515
  • [36] Bloccess: Enabling Fine-Grained Access Control Based on Blockchain
    Ding, Yepeng
    Sato, Hiroyuki
    JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2023, 31 (01)
  • [37] Bloccess: Enabling Fine-Grained Access Control Based on Blockchain
    Yepeng Ding
    Hiroyuki Sato
    Journal of Network and Systems Management, 2023, 31
  • [38] Automatic fine-grained access control in SCADA by machine learning
    Zhou, Lu
    Su, Chunhua
    Li, Zhen
    Liu, Zhe
    Hancke, Gerhard P.
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2019, 93 : 548 - 559
  • [39] Providing fine-grained access control for Java']Java programs
    Pandey, R
    Hashii, B
    ECOOP'99 - OBJECT-ORIENTED PROGRAMMING, 1999, 1628 : 449 - 473
  • [40] Fine-Grained Task Access Control System for Mobile Crowdsensing
    Wang, Jingwei
    Yin, Xinchun
    Ning, Jianting
    SECURITY AND COMMUNICATION NETWORKS, 2021, 2021