A Metric-Based Approach to Assess Risk for “On Cloud” Federated Identity Management

被引:0
|
作者
Patricia Arias-Cabarcos
Florina Almenárez-Mendoza
Andrés Marín-López
Daniel Díaz-Sánchez
Rosa Sánchez-Guerrero
机构
[1] University Carlos III of Madrid,Department of Telematics Engineering
关键词
Trust management; Cloud computing; Risk assessment metrics; SAML; Federation;
D O I
暂无
中图分类号
学科分类号
摘要
The cloud computing paradigm is set to become the next explosive revolution on the Internet, but its adoption is still hindered by security problems. One of the fundamental issues is the need for better access control and identity management systems. In this context, Federated Identity Management (FIM) is identified by researchers and experts as an important security enabler, since it will play a vital role in allowing the global scalability that is required for the successful implantation of cloud technologies. However, current FIM frameworks are limited by the complexity of the underlying trust models that need to be put in place before inter-domain cooperation. Thus, the establishment of dynamic federations between the different cloud actors is still a major research challenge that remains unsolved. Here we show that risk evaluation must be considered as a key enabler in evidence-based trust management to foster collaboration between cloud providers that belong to unknown administrative domains in a secure manner. In this paper, we analyze the Federated Identity Management process and propose a taxonomy that helps in the classification of the involved risks in order to mitigate vulnerabilities and threats when decisions about collaboration are made. Moreover, a set of new metrics is defined to allow a novel form of risk quantification in these environments. Other contributions of the paper include the definition of a generic hierarchical risk aggregation system, and a descriptive use-case where the risk computation framework is applied to enhance cloud-based service provisioning.
引用
收藏
页码:513 / 533
页数:20
相关论文
共 50 条
  • [21] Federated Identity Management and Interoperability for Heterogeneous Cloud Platform Ecosystems
    Selvanathan, Nirojan
    Jayakody, Dileepa
    Damjanovic-Behrendt, Violeta
    14TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY (ARES 2019), 2019,
  • [22] A New Dynamic Trust Model for "On Cloud" Federated Identity Management
    Bendiab, Keltoum
    Shiaeles, Stavros
    Boucherkha, Samia
    2018 9TH IFIP INTERNATIONAL CONFERENCE ON NEW TECHNOLOGIES, MOBILITY AND SECURITY (NTMS), 2018,
  • [23] A Novel Metric-Based Geometric Parameterization Approach with Performance Filtration
    Zhang, Hao
    Wang, Shuyue
    Jiang, Ying
    Yuan, Zizhao
    Yang, Yingjie
    Sun, Gang
    JOURNAL OF AEROSPACE ENGINEERING, 2024, 37 (04)
  • [24] Metric-Based Approach for Selecting the Game Genre to Model Personality
    Tlili, Ahmed
    Essalmi, Fathi
    Jemni, Mohamed
    STATE-OF-THE-ART AND FUTURE DIRECTIONS OF SMART LEARNING, 2016, : 275 - 279
  • [25] Cloud-based federated identity for the Internet of Things
    Paul Fremantle
    Benjamin Aziz
    Annals of Telecommunications, 2018, 73 : 415 - 427
  • [26] Cloud-based federated identity for the Internet of Things
    Fremantle, Paul
    Aziz, Benjamin
    ANNALS OF TELECOMMUNICATIONS, 2018, 73 (7-8) : 415 - 427
  • [27] Basic statistics for distributional symbolic variables: a new metric-based approach
    Irpino, Antonio
    Verde, Rosanna
    ADVANCES IN DATA ANALYSIS AND CLASSIFICATION, 2015, 9 (02) : 143 - 175
  • [28] Learnable Cost Metric-Based Multi-View Stereo for Point Cloud Reconstruction
    Yang, Guidong
    Zhou, Xunkuai
    Gao, Chuanxiang
    Chen, Xi
    Chen, Ben M.
    IEEE TRANSACTIONS ON INDUSTRIAL ELECTRONICS, 2024, 71 (09) : 11519 - 11528
  • [29] A Metric-Based Multi-Agent System for Software Project Management
    Wu, Ching-seh
    Chang, Wei-chun
    Sethi, Ishwar K.
    PROCEEDINGS OF THE 8TH IEEE/ACIS INTERNATIONAL CONFERENCE ON COMPUTER AND INFORMATION SCIENCE, 2009, : 3 - +
  • [30] Cloud-Based Utility Service Framework for Trust Negotiations Using Federated Identity Management
    Premarathne, Uthpala Subodhani
    Khalil, Ibrahim
    Tari, Zahir
    Zomaya, Albert
    IEEE TRANSACTIONS ON CLOUD COMPUTING, 2017, 5 (02) : 290 - 302