A Multi-Tenant RBAC Model for Collaborative Cloud Services

被引:0
|
作者
Tang, Bo [1 ]
Li, Qi [1 ]
Sandhu, Ravi [1 ]
机构
[1] Univ Texas San Antonio, Inst Cyber Secur, San Antonio, TX 78249 USA
关键词
cloud computing; multi-tenancy; trust; collaboration; fine-grained authorization; GRAINED ACCESS-CONTROL; MANAGEMENT; AUTHORIZATION;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Most cloud services are built with multi-tenancy which enables data and configuration segregation upon shared infrastructures. In this setting, a tenant temporarily uses a piece of virtually dedicated software, platform, or infrastructure. To fully benefit from the cloud, tenants are seeking to build controlled and secure collaboration with each other. In this paper, we propose a Multi-Tenant Role-Based Access Control (MT-RBAC) model family which aims to provide fine-grained authorization in collaborative cloud environments by building trust relations among tenants. With an established trust relation in MT-RBAC, the trustee can precisely authorize cross-tenant accesses to the truster's resources consistent with constraints over the trust relation and other components designated by the truster. The users in the trustee may restrictively inherit permissions from the truster so that multi-tenant collaboration is securely enabled. Using SUN's XACML library, we prototype MT-RBAC models on a novel Authorization as a Service (AaaS) platform with the Joyent commercial cloud system. The performance and scalability metrics are evaluated with respect to an open source cloud storage system. The results show that our prototype incurs only 0.016 second authorization delay for end users on average and is scalable in cloud environments.
引用
收藏
页码:229 / 238
页数:10
相关论文
共 50 条
  • [31] A probabilistic multi-tenant model for virtual machine mapping in cloud systems
    Wang, Zhuoyao
    Hayat, Majeed M.
    Ghani, Nasir
    Shaban, Khaled Bashir
    [J]. 2014 IEEE 3RD INTERNATIONAL CONFERENCE ON CLOUD NETWORKING (CLOUDNET), 2014, : 339 - 343
  • [32] EdgeNet: A Multi-Tenant and Multi-Provider Edge Cloud
    Senel, Berat Can
    Mouchet, Maxime
    Cappos, Justin
    Fourmaux, Olivier
    Friedman, Timur
    McGeer, Rick
    [J]. PROCEEDINGS OF THE 4TH INTERNATIONAL WORKSHOP ON EDGE SYSTEMS, ANALYTICS AND NETWORKING (EDGESYS'21), 2021, : 49 - 54
  • [33] Multipath Bandwidth Guarantees for Multi-Tenant Cloud Networking
    Wang, Wei
    Sun, Yi
    Uhlig, Steve
    Fang, Gengfa
    Wang, Nanshu
    Li, Zhongcheng
    [J]. 2016 IEEE 41ST CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN), 2016, : 442 - 450
  • [34] Deadline Guaranteed Service for Multi-Tenant Cloud Storage
    Liu, Guoxin
    Shen, Haiying
    Wang, Haoyu
    [J]. IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2016, 27 (10) : 2851 - 2865
  • [35] Cloud Computing Architectures Based Multi-Tenant IDS
    Khalil, Elmahdi
    Enniari, Saad
    Zbakh, Mostapha
    [J]. 2013 NATIONAL SECURITY DAYS (JNS3), 2013,
  • [36] Multi-tenant Verification-as-a-Service (VaaS) in a cloud
    Hu, Kai
    Lei, Lei
    Tsai, Wei-Tek
    [J]. SIMULATION MODELLING PRACTICE AND THEORY, 2016, 60 : 122 - 143
  • [37] A multi-tenant hierarchical modeling for cloud computing workload
    An, Chunyan
    Zhou, Jiantao
    Liu, Shuai
    Geihs, Kurt
    [J]. INTELLIGENT AUTOMATION AND SOFT COMPUTING, 2016, 22 (04): : 579 - 586
  • [38] Multi-Tenant Data Center and Cloud Networking Evolution
    Bitar, Nabil
    [J]. 2013 OPTICAL FIBER COMMUNICATION CONFERENCE AND EXPOSITION AND THE NATIONAL FIBER OPTIC ENGINEERS CONFERENCE (OFC/NFOEC), 2013,
  • [39] Predictive elastic replication for multi-tenant databases in the cloud
    Sousa, Flavio R. C.
    Moreira, Leonardo O.
    Costa Filho, Jose S.
    Machado, Javam C.
    [J]. CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2018, 30 (16):
  • [40] Deadline Guaranteed Service for Multi-Tenant Cloud Storage
    Liu, Guoxin
    Shen, Haiying
    [J]. 2015 IEEE INTERNATIONAL CONFERENCE ON PEER-TO-PEER COMPUTING (P2P), 2015,