SNUAGE: an efficient platform-as-a-service security framework for the cloud

被引:0
|
作者
Wassim Itani
Ayman Kayssi
Ali Chehab
机构
[1] Beirut Arab University,Department of Electrical and Computer Engineering
[2] American University of Beirut,Department of Electrical and Computer Engineering
来源
Cluster Computing | 2013年 / 16卷
关键词
Cloud computing security; Platform-as-a-Service security; Data confidentiality; Integrity; Policy-based security;
D O I
暂无
中图分类号
学科分类号
摘要
In this paper we present SNUAGE, a platform-as-a-service security framework for building secure and scalable multi-layered services based on the cloud computing model. SNUAGE ensures the authenticity, integrity, and confidentiality of data communication over the network links by creating a set of security associations between the data-bound components on the presentation layer and their respective data sources on the data persistence layer. SNUAGE encapsulates the security procedures, policies, and mechanisms in these security associations at the service development stage to form a collection of isolated and protected security domains. The secure communication among the entities in one security domain is governed and controlled by a standalone security processor and policy attached to this domain. This results into: (1) a safer data delivery mechanism that prevents security vulnerabilities in one domain from spreading to the other domains and controls the inter-domain information flow to protect the privacy of network data, (2) a reusable security framework that can be employed in existing platform-as-a-service environments and across diverse cloud computing service models, and (3) an increase in productivity and delivery of reliable and secure cloud computing services supported by a transparent programming model that relieves application developers from the intricate details of security programming. Last but not least, SNUAGE contributes to a major enhancement in the energy consumption and performance of supported cloud services by providing a suitable execution container in its protected security domains for a wide suite of energy- and performance-efficient cryptographic constructs such as those adopted by policy-driven and content-based security protocols. An energy analysis of the system shows, via real energy measurements, major savings in energy consumption on the consumer devices as well as on the cloud servers. Moreover, a sample implementation of the presented security framework is developed using Java and deployed and tested in a real cloud computing infrastructure using the Google App Engine service platform. Performance benchmarks show that the proposed framework provides a significant throughput enhancement compared to traditional network security protocols such as the Secure Sockets Layer and the Transport Layer Security protocols.
引用
收藏
页码:707 / 724
页数:17
相关论文
共 50 条
  • [21] A Cloud Based Framework for Platform as a Service
    Farouk, Mohamed
    Yousif, Adil
    Bashir, Mohammed Bakri
    2015 International Conference on Cloud Computing (ICCC), 2015, : 6 - 10
  • [22] Business process oriented platform-as-a-service framework for process instances intensive applications
    School of Computer Science and Technology, Shandong University, Shandong Provincial Key Laboratory of Software Engineering, China
    Proc. IEEE Int. Parallel Distrib. Process. Symp. Workshops, IPDPSW, (2320-2327):
  • [23] A Vision for the Next Generation Platform-as-a-Service
    Van Rossem, Steven
    Sayadi, Bessem
    Roullet, Laurent
    Mimidis, Angelos
    Paolino, Michele
    Veitch, Paul
    Berde, Bela
    Labrador, Ignacio
    Ramos, Aurora
    Tavernier, Wouter
    Ollora, Eder
    Soler, Jose
    2018 IEEE 5G WORLD FORUM (5GWF), 2018, : 14 - 19
  • [24] Building an Open-source Platform-as-a-Service with Intelligent Management of Multiple Cloud Resources
    Sandru, Calin
    Petcu, Dana
    Munteanu, Victor Ion
    2012 IEEE/ACM FIFTH INTERNATIONAL CONFERENCE ON UTILITY AND CLOUD COMPUTING (UCC 2012), 2012, : 333 - 338
  • [25] Globus platform-as-a-service for collaborative science applications
    Ananthakrishnan, Rachana
    Chard, Kyle
    Foster, Ian
    Tuecke, Steven
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2015, 27 (02): : 290 - 305
  • [26] A Platform-as-a-Service System for FPGA Education and Development
    Zhao, Qian
    Yoshida, Takaichi
    PROCEEDINGS OF THE ACM CONFERENCE ON GLOBAL COMPUTING EDUCATION (COMPED '19), 2019, : 243 - 243
  • [27] On Autonomic Platform-as-a-Service: Characterisation and Conceptual Model
    Tolosana-Calasanz, Rafael
    Angel Baares, Jose
    Colom, Jose-Manuel
    AGENT AND MULTI-AGENT SYSTEMS: TECHNOLOGIES AND APPLICATIONS, 2015, 38 : 217 - 226
  • [28] Developing software online with platform-as-a-service technology
    Lawton, George
    COMPUTER, 2008, 41 (06) : 13 - 15
  • [29] Towards a Full-Stack DevOps Environment (Platform-as-a-Service) for Cloud-Hosted Applications
    Li, Zhenhua
    Zhang, Yun
    Liu, Yunhao
    TSINGHUA SCIENCE AND TECHNOLOGY, 2017, 22 (01) : 1 - 9
  • [30] A Service Provisioning and Managing Framework for Platform as a Service in Educational Cloud
    Ameen, Mohd Noorul
    Sanjay, H. A.
    Patel, Yasser
    2012 2ND IEEE INTERNATIONAL CONFERENCE ON PARALLEL, DISTRIBUTED AND GRID COMPUTING (PDGC), 2012, : 262 - 267