A Cloud-Oriented Cross-Domain Security Architecture

被引:6
|
作者
Nguyen, Thuy D. [1 ]
Gondree, Mark A. [1 ]
Shifflett, David J. [1 ]
Khosalim, Jean [1 ]
Levin, Timothy E. [1 ]
Irvine, Cynthia E. [1 ]
机构
[1] USN, Postgrad Sch, Dept Comp Sci, Monterey, CA 93943 USA
关键词
cloud computing; cross-domain services; collaborative applications; quality of security services;
D O I
10.1109/MILCOM.2010.5680360
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
The Monterey Security Architecture addresses the need to share high-value data across multiple domains of different classification levels while enforcing information flow policies. The architecture allows users with different security authorizations to securely collaborate and exchange information using commodity computers and familiar commercial client software that generally lack the prerequisite assurance and functional security protections. MYSEA seeks to meet two compelling requirements, often assumed to be at odds: enforcing critical, mandatory security policies, and allowing access and collaboration in a familiar work environment. Recent additions to the MYSEA design expand the architecture to support a cloud of cross-domain services, hosted within a federation of multilevel secure (MLS) MYSEA servers. The MYSEA cloud supports single-sign on, service replication, and network-layer quality of security service. This new cross-domain, distributed architecture follows the consumption and delivery model for cloud services, while maintaining the federated control model necessary to support and protect cross-domain collaboration within the enterprise. The resulting architecture shows the feasibility of high-assurance, cross-domain services hosted within a community cloud suitable for interagency, or joint, collaboration. This paper summarizes the MYSEA architecture and discusses MYSEA's approach to provide an MLS-constrained cloud computing environment.
引用
收藏
页码:441 / 447
页数:7
相关论文
共 50 条
  • [1] A SOUND Approach to Security in Mobile and Cloud-Oriented Environments
    Figueroa, Michael
    Uttecht, Karen
    Rosenberg, Jothy
    2015 IEEE INTERNATIONAL SYMPOSIUM ON TECHNOLOGIES FOR HOMELAND SECURITY (HST), 2015,
  • [2] MMBIP: Biofeedback System Design on Cloud-Oriented Architecture
    Alhamid, Mohammed F.
    Eid, Mohamad
    Alshareef, Abdulrhman
    El Saddik, Abdulmotaleb
    2012 IEEE INTERNATIONAL SYMPOSIUM ON ROBOTIC AND SENSORS ENVIRONMENTS (ROSE 2012), 2012, : 79 - 84
  • [3] Understanding Software Reengineering Requirements for Cloud-Oriented Service Architecture
    Zheng, Shang
    Yang, Hongji
    Zuo, Xin
    Yu, Hualong
    Shen, Jifeng
    2016 22ND INTERNATIONAL CONFERENCE ON AUTOMATION AND COMPUTING (ICAC), 2016, : 48 - 53
  • [4] A Proposal of a Cloud-Oriented Security and Performance Simulator Provided as-a-Service
    Casola, Valentina
    De Benedictis, Alessandra
    Rak, Massimiliano
    Villano, Umberto
    COMPLEX, INTELLIGENT, AND SOFTWARE INTENSIVE SYSTEMS, 2019, 772 : 1002 - 1011
  • [5] Evaluation on the Cross-Domain Cloud Databases
    Zhang, Zhong
    Li, Donghong
    Xiao, Wen
    Liu, Shuang
    COMMUNICATIONS, SIGNAL PROCESSING, AND SYSTEMS, 2019, 463 : 2229 - 2234
  • [6] Cloud Computing: Several Cloud-oriented Solutions
    Haji, Amel
    Ben Letaifa, Asma
    Tabbane, Sami
    PROCEEDINGS OF THE FOURTH INTERNATIONAL CONFERENCE ON ADVANCED ENGINEERING COMPUTING AND APPLICATIONS IN SCIENCES (ADVCOMP 2010), 2010, : 137 - 141
  • [7] A Cloud-oriented Algorithm for Virtual Network Embedding Over Multi-Domain
    Li, Shuopeng
    Saidi, Mohand Yazid
    Chen, Ken
    PROCEEDINGS OF THE 2016 IEEE 41ST CONFERENCE ON LOCAL COMPUTER NETWORKS - LCN WORKSHOPS 2016, 2016, : 50 - 57
  • [8] AIRPHANT: Cloud-oriented Document Indexing
    Chockchowwat, Supawit
    Sood, Chaitanya
    Park, Yongjoo
    2022 IEEE 38TH INTERNATIONAL CONFERENCE ON DATA ENGINEERING (ICDE 2022), 2022, : 1368 - 1381
  • [9] CloudAC: a cloud-oriented multilayer access control system for logic virtual domain
    Qiang, Weizhong
    Zou, Deqing
    Wang, Shenglan
    Yang, Laurence Tianruo
    Jin, Hai
    Shi, Lei
    IET INFORMATION SECURITY, 2013, 7 (01) : 51 - 59
  • [10] SMEF: An Entropy-based Security Framework for Cloud-oriented Service Mashup
    Li, Ruixuan
    Nie, Li
    Ma, Xiaopu
    Dong, Meng
    Wang, Wei
    TRUSTCOM 2011: 2011 INTERNATIONAL JOINT CONFERENCE OF IEEE TRUSTCOM-11/IEEE ICESS-11/FCST-11, 2011, : 304 - 311