A Multi-Tenant RBAC Model for Collaborative Cloud Services

被引:0
|
作者
Tang, Bo [1 ]
Li, Qi [1 ]
Sandhu, Ravi [1 ]
机构
[1] Univ Texas San Antonio, Inst Cyber Secur, San Antonio, TX 78249 USA
关键词
cloud computing; multi-tenancy; trust; collaboration; fine-grained authorization; GRAINED ACCESS-CONTROL; MANAGEMENT; AUTHORIZATION;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Most cloud services are built with multi-tenancy which enables data and configuration segregation upon shared infrastructures. In this setting, a tenant temporarily uses a piece of virtually dedicated software, platform, or infrastructure. To fully benefit from the cloud, tenants are seeking to build controlled and secure collaboration with each other. In this paper, we propose a Multi-Tenant Role-Based Access Control (MT-RBAC) model family which aims to provide fine-grained authorization in collaborative cloud environments by building trust relations among tenants. With an established trust relation in MT-RBAC, the trustee can precisely authorize cross-tenant accesses to the truster's resources consistent with constraints over the trust relation and other components designated by the truster. The users in the trustee may restrictively inherit permissions from the truster so that multi-tenant collaboration is securely enabled. Using SUN's XACML library, we prototype MT-RBAC models on a novel Authorization as a Service (AaaS) platform with the Joyent commercial cloud system. The performance and scalability metrics are evaluated with respect to an open source cloud storage system. The results show that our prototype incurs only 0.016 second authorization delay for end users on average and is scalable in cloud environments.
引用
收藏
页码:229 / 238
页数:10
相关论文
共 50 条
  • [1] A Temporal Multi-Tenant BRAC Model for Collaborative Cloud Services
    Liu, Zhengtao
    Ying, Yi
    Peng, Yaqin
    Xia, Jinyue
    [J]. CMC-COMPUTERS MATERIALS & CONTINUA, 2020, 63 (02): : 861 - 871
  • [2] A Cross-Tenant RBAC Model for Collaborative Cloud Services
    Liu, Zhengtao
    Xia, Jinyue
    [J]. CMC-COMPUTERS MATERIALS & CONTINUA, 2019, 60 (01): : 395 - 408
  • [3] Analyzing Multi-Tenant Cloud Services' Accountability
    Masmoudi, Fatma
    Sellami, Mohamed
    Loulou, Monia
    Kacem, Ahmed Hadj
    [J]. 2015 IEEE 12TH INTERNATIONAL CONFERENCE ON E-BUSINESS ENGINEERING (ICEBE), 2015, : 239 - 244
  • [4] Accountability management for multi-tenant cloud services
    Masmoudi, Fatma
    Sellami, Mohamed
    Loulou, Monia
    Kacem, Ahmed Hadj
    [J]. INTERNATIONAL JOURNAL OF GRID AND UTILITY COMPUTING, 2019, 10 (02) : 141 - 158
  • [5] A Multi-Tenant Framework for Cloud Container Services
    Zheng, Chao
    Zhuang, Qinghui
    Guo, Fei
    [J]. 2021 IEEE 41ST INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS (ICDCS 2021), 2021, : 359 - 369
  • [6] Multi-Tenant services Monitoring for Accountability in Cloud Computing
    Masmoudi, Fatma
    Loulou, Monia
    Kacem, Ahmed Hadj
    [J]. 2014 IEEE 6TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING TECHNOLOGY AND SCIENCE (CLOUDCOM), 2014, : 620 - 625
  • [7] Addressing security compatibility for multi-tenant cloud services
    Khan, Khaled M.
    Erradi, Abdelkarim
    Alhazbi, Saleh
    Han, Jun
    [J]. INTERNATIONAL JOURNAL OF COMPUTER APPLICATIONS IN TECHNOLOGY, 2013, 47 (04) : 370 - 378
  • [8] Personalized Cache Management for Multi-Tenant Cloud Services
    Yuan, Yigui
    Jin, Peiquan
    Wan, Shouhong
    [J]. 2022 IEEE 42ND INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS (ICDCS 2022), 2022, : 1326 - 1327
  • [9] A Scalable VPN Gateway for Multi-Tenant Cloud Services
    Arashloo, Mina Tahmasbi
    Shirshov, Pavel
    Gandhi, Rohan
    Lu, Guohan
    Yuan, Lihua
    Rexford, Jennifer
    [J]. ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2018, 48 (01) : 49 - 55
  • [10] Dependable Multi-Tenant Infrastructures Supporting Cloud and Mobile Cloud Services
    Anastasopoulos, Markos. P.
    Tzanakaki, Anna
    Simeonidou, Dimitra
    [J]. 2014 GLOBECOM WORKSHOPS (GC WKSHPS), 2014, : 1511 - 1516