SignedQuery: Protecting Users Data in Multi-tenant SaaS Environments

被引:0
|
作者
Saleh, Eyad [1 ]
Takouna, Ibrahim [1 ]
Meinel, Christoph [1 ]
机构
[1] Univ Potsdam, Hasso Plattner Inst, Potsdam, Germany
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Software-as-a-Service (SaaS) is emerging as a new software delivery model, where the application and its associated data are hosted in the cloud. Due to the nature of SaaS and the cloud in general, where the data and the computation are beyond the control of the user, data privacy and security becomes a vital factor in this new paradigm. Several research studies reported that security and privacy are cited as the biggest concerns in adopting cloud computing. In multi-tenant SaaS applications, the tenants become concerned about the confidentiality of their data since several tenants are consolidated onto a shared infrastructure. Consequently, several questions raise, such as, how to ensure that tenant's data are only available to authenticated users? How to prohibit a tenant from accessing other's data? To address these concerns, we present SignedQuery, a mechanism designed to facilitate the process of securing data stored on the cloud. SignedQuery ensures data confidentiality by preventing any tenant from accidentally or maliciously accessing other tenants' data without breaking the functionality of the application. SignedQuery utilizes the usage of a signature to sign the tenant's request, so the server can recognize the requesting tenant and ensure that the data to be accessed is belonging to this tenant. SignedQuery intercepts the HTTP request objects at the tenant's internal network, create the signature and attach it to the request headers, then send the request to the SaaS provider where the signature is validated. We have successfully tested SignedQuery against OrangeHRM. The results showed that our approach is feasible, and incur a negligible overhead.
引用
收藏
页码:213 / 218
页数:6
相关论文
共 50 条
  • [1] Multi-tenant data authentication model for SaaS
    Li, Lin
    Kong, Lanju
    Li, Qingzhong
    Yan, Zhongmin
    Li, Hui
    [J]. Open Cybernetics and Systemics Journal, 2014, 8 (01): : 322 - 329
  • [3] Multi-tenant data authentication model for SaaS
    [J]. Li, Qingzhong (lqz@sdu.edu.cn), 1600, Bentham Science Publishers B.V., P.O. Box 294, Bussum, 1400 AG, Netherlands (08):
  • [4] Data isolation in multi-tenant SaaS environment
    Gupta, Keshav
    Kumar, Sandeep
    Agnihotri, Ojaswi
    [J]. 2016 IEEE INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION AND AUTOMATION (ICCCA), 2016, : 1290 - 1292
  • [5] Multi-tenant SaaS Cloud
    Kulkarni, Gurudatt
    Shelke, Rupali
    Palwe, Rajnikant
    Khatawkar, Prasad
    Bhuse, Sadanand
    Bankar, Hemant
    [J]. 2013 FOURTH INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATIONS AND NETWORKING TECHNOLOGIES (ICCCNT), 2013,
  • [6] Multi-tenant SaaS Cloud
    Kulkarni, Gurudatt
    Khatawkar, Prasad
    Shelke, Rupali
    Solanke, Vikas
    Waghmare, Rani
    [J]. AFRICON, 2013, 2013,
  • [7] SaaS Multi-Tenant Application Customization
    Tsai, Wei-Tek
    Sun, Xin
    [J]. 2013 IEEE SEVENTH INTERNATIONAL SYMPOSIUM ON SERVICE-ORIENTED SYSTEM ENGINEERING (SOSE 2013), 2013, : 1 - 12
  • [8] SecPlace: A Security-Aware Placement Model for Multi-tenant SaaS Environments
    Saleh, Eyad
    Sianipar, Johannes
    Takouna, Ibrahim
    Meinel, Christoph
    [J]. 2014 IEEE 11TH INTL CONF ON UBIQUITOUS INTELLIGENCE AND COMPUTING AND 2014 IEEE 11TH INTL CONF ON AUTONOMIC AND TRUSTED COMPUTING AND 2014 IEEE 14TH INTL CONF ON SCALABLE COMPUTING AND COMMUNICATIONS AND ITS ASSOCIATED WORKSHOPS, 2014, : 596 - 602
  • [9] Modeling and Analysis of Availability in Multi-tenant SaaS
    Su, Wenbo
    Liu, Qu
    Lin, Chuang
    Shen, Sherman
    [J]. 24TH INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS AND NETWORKS ICCCN 2015, 2015,
  • [10] Research on Optimization Adjustment Strategy for SaaS Multi-tenant Data Placement
    Li Xiaona
    Li Qingzhong
    Zhu Weiyi
    Li Hui
    [J]. INTERNATIONAL JOURNAL OF GRID AND DISTRIBUTED COMPUTING, 2015, 8 (02): : 319 - 330