SNUAGE: an efficient platform-as-a-service security framework for the cloud

被引:0
|
作者
Wassim Itani
Ayman Kayssi
Ali Chehab
机构
[1] Beirut Arab University,Department of Electrical and Computer Engineering
[2] American University of Beirut,Department of Electrical and Computer Engineering
来源
Cluster Computing | 2013年 / 16卷
关键词
Cloud computing security; Platform-as-a-Service security; Data confidentiality; Integrity; Policy-based security;
D O I
暂无
中图分类号
学科分类号
摘要
In this paper we present SNUAGE, a platform-as-a-service security framework for building secure and scalable multi-layered services based on the cloud computing model. SNUAGE ensures the authenticity, integrity, and confidentiality of data communication over the network links by creating a set of security associations between the data-bound components on the presentation layer and their respective data sources on the data persistence layer. SNUAGE encapsulates the security procedures, policies, and mechanisms in these security associations at the service development stage to form a collection of isolated and protected security domains. The secure communication among the entities in one security domain is governed and controlled by a standalone security processor and policy attached to this domain. This results into: (1) a safer data delivery mechanism that prevents security vulnerabilities in one domain from spreading to the other domains and controls the inter-domain information flow to protect the privacy of network data, (2) a reusable security framework that can be employed in existing platform-as-a-service environments and across diverse cloud computing service models, and (3) an increase in productivity and delivery of reliable and secure cloud computing services supported by a transparent programming model that relieves application developers from the intricate details of security programming. Last but not least, SNUAGE contributes to a major enhancement in the energy consumption and performance of supported cloud services by providing a suitable execution container in its protected security domains for a wide suite of energy- and performance-efficient cryptographic constructs such as those adopted by policy-driven and content-based security protocols. An energy analysis of the system shows, via real energy measurements, major savings in energy consumption on the consumer devices as well as on the cloud servers. Moreover, a sample implementation of the presented security framework is developed using Java and deployed and tested in a real cloud computing infrastructure using the Google App Engine service platform. Performance benchmarks show that the proposed framework provides a significant throughput enhancement compared to traditional network security protocols such as the Secure Sockets Layer and the Transport Layer Security protocols.
引用
收藏
页码:707 / 724
页数:17
相关论文
共 50 条
  • [31] Platform-as-a-Service Architecture for Parallel Video Analysis in Clouds
    Chen, Tse-Shih
    Huang, Tsiao-Wen
    Yin, Liang-Chun
    Chen, Yi-Ling
    Ciou, Yi-Fu
    Smart Innovation, Systems and Technologies, 2013, 21 : 619 - 626
  • [32] Information of Public Security Traffic cloud platform framework
    Sang XueKun
    Ma WeiWei
    PROCEEDINGS OF THE 2014 INTERNATIONAL CONFERENCE ON MECHATRONICS, CONTROL AND ELECTRONIC ENGINEERING, 2014, 113 : 199 - 202
  • [33] Campus cloud QoS security mechanism research and service energy-efficient platform design
    Li, Dongmei
    Zhao, Huanping
    Yang, Xinfeng
    Energy Education Science and Technology Part A: Energy Science and Research, 2013, 31 (01): : 541 - 544
  • [34] Model Based Monitoring and Controlling for Platform-as-a-Service (PaaS)
    Shao, Jin
    Wang, Qianxiang
    Mei, Hong
    INTERNATIONAL JOURNAL OF CLOUD APPLICATIONS AND COMPUTING, 2012, 2 (01) : 1 - 15
  • [35] Multi-Tenant Servitization Platform-as-a-Service Model
    Gadebe, Moses L.
    Onumanyi, Adeiza J.
    Mkhize, Buhle
    SOFT COMPUTING AND ITS ENGINEERING APPLICATIONS, PT 1, ICSOFTCOMP 2023, 2024, 2030 : 117 - 128
  • [36] The Platform-as-a-Service paradigm meets ATLAS: developing an automated analysis workflow on the newly established INFN CLOUD
    Marcon, Caterina
    Carminati, Leonardo
    Rebatto, David
    Turra, Ruggero
    26TH INTERNATIONAL CONFERENCE ON COMPUTING IN HIGH ENERGY AND NUCLEAR PHYSICS, CHEP 2023, 2024, 295
  • [37] A semantic recommendation algorithm for the PaaSport platform-as-a-service marketplace
    Bassiliades, Nick
    Symeonidis, Moisis
    Meditskos, Georgios
    Kontopoulos, Efstratios
    Gouvas, Panagiotis
    Vlahavas, Ioannis
    EXPERT SYSTEMS WITH APPLICATIONS, 2017, 67 : 203 - 227
  • [38] CARL: A Complex Applications Interoperability Language based on Semantic Technologies for Platform-as-a-Service Integration and Cloud Computing
    Jimenez-Domingo, Enrique
    Miguel Gomez-Berbis, Juan
    Colomo-Palacios, Ricardo
    Garcia-Crespo, Angel
    JOURNAL OF RESEARCH AND PRACTICE IN INFORMATION TECHNOLOGY, 2011, 43 (03): : 226 - 245
  • [39] Towards a Full-Stack Dev Ops Environment (Platform-as-a-Service) for Cloud-Hosted Applications
    Zhenhua Li
    Yun Zhang
    Yunhao Liu
    TsinghuaScienceandTechnology, 2017, 22 (01) : 1 - 9
  • [40] Survey on Open Source Platform-as-a-Service Solutions for Education
    Kriz, Pavel
    PROCEEDINGS OF THE 18TH INTERNATIONAL DATABASE ENGINEERING AND APPLICATIONS SYMPOSIUM (IDEAS14), 2014, : 176 - 184