SignedQuery: Protecting Users Data in Multi-tenant SaaS Environments

被引:0
|
作者
Saleh, Eyad [1 ]
Takouna, Ibrahim [1 ]
Meinel, Christoph [1 ]
机构
[1] Univ Potsdam, Hasso Plattner Inst, Potsdam, Germany
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Software-as-a-Service (SaaS) is emerging as a new software delivery model, where the application and its associated data are hosted in the cloud. Due to the nature of SaaS and the cloud in general, where the data and the computation are beyond the control of the user, data privacy and security becomes a vital factor in this new paradigm. Several research studies reported that security and privacy are cited as the biggest concerns in adopting cloud computing. In multi-tenant SaaS applications, the tenants become concerned about the confidentiality of their data since several tenants are consolidated onto a shared infrastructure. Consequently, several questions raise, such as, how to ensure that tenant's data are only available to authenticated users? How to prohibit a tenant from accessing other's data? To address these concerns, we present SignedQuery, a mechanism designed to facilitate the process of securing data stored on the cloud. SignedQuery ensures data confidentiality by preventing any tenant from accidentally or maliciously accessing other tenants' data without breaking the functionality of the application. SignedQuery utilizes the usage of a signature to sign the tenant's request, so the server can recognize the requesting tenant and ensure that the data to be accessed is belonging to this tenant. SignedQuery intercepts the HTTP request objects at the tenant's internal network, create the signature and attach it to the request headers, then send the request to the SaaS provider where the signature is validated. We have successfully tested SignedQuery against OrangeHRM. The results showed that our approach is feasible, and incur a negligible overhead.
引用
收藏
页码:213 / 218
页数:6
相关论文
共 50 条
  • [31] Deep Customization of Multi-Tenant SaaS Using Intrusive Microservices
    Song, Hui
    Chauvel, Franck
    Solberg, Arnor
    2018 IEEE/ACM 40TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING: NEW IDEAS AND EMERGING TECHNOLOGIES RESULTS (ICSE-NIER), 2018, : 97 - 100
  • [32] Dynamic Provisioning of Service Composition in a Multi-Tenant SaaS Environment
    Sellami, Wael
    Kacem, Hatem
    Kacem, Ahmed
    JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2020, 28 (02) : 367 - 397
  • [33] Middleware for Dynamic Upgrade Activation and Compensations in Multi-tenant SaaS
    Van Landuyt, Dimitri
    Gey, Fatih
    Truyen, Eddy
    Joosen, Wouter
    SERVICE-ORIENTED COMPUTING, ICSOC 2017, 2017, 10601 : 340 - 348
  • [34] ITADP: An inter-tenant attack detection and prevention framework for multi-tenant SaaS
    Yassin, Mohamed
    Talhi, Chamseddine
    Boucheneb, Hanifa
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2019, 49
  • [35] Replica Placement in Multi-Tenant Database Environments
    Floratou, Avrilia
    Patel, Jignesh M.
    2015 IEEE INTERNATIONAL CONGRESS ON BIG DATA - BIGDATA CONGRESS 2015, 2015, : 246 - 253
  • [36] Framework for Management of Multi-tenant Cloud Environments
    Beranek, Marek
    Kovar, Vladimir
    Feuerlicht, George
    CLOUD COMPUTING - CLOUD 2018, 2018, 10967 : 309 - 322
  • [37] Policy-Driven Data Management Middleware for Multi-Cloud Storage in Multi-Tenant SaaS
    Rafique, Ansar
    Van Landuyt, Dimitri
    Lagaisse, Bert
    Joosen, Wouter
    2015 IEEE/ACM 2ND INTERNATIONAL SYMPOSIUM ON BIG DATA COMPUTING (BDC), 2015, : 78 - 84
  • [38] Using Intrusive Microservices to Enable Deep Customization of Multi-Tenant SaaS
    Chauvel, Franck
    Solberg, Arnor
    2018 11TH INTERNATIONAL CONFERENCE ON THE QUALITY OF INFORMATION AND COMMUNICATIONS TECHNOLOGY (QUATIC), 2018, : 30 - 37
  • [39] Event-Based Customization of Multi-tenant SaaS Using Microservices
    Nordli, Espen Tonnessen
    Nguyen, Phu H.
    Chauvel, Franck
    Song, Hui
    COORDINATION MODELS AND LANGUAGES, COORDINATION 2020, 2020, 12134 : 171 - 180
  • [40] A partition model and strategy based on the Stoer-Wagner algorithm for SaaS multi-tenant data
    Li, Xiaona
    Zhao, Junli
    Ma, Yumei
    Wang, Pingping
    Sun, Hongyi
    Tang, Yi
    SOFT COMPUTING, 2017, 21 (20) : 6121 - 6132