A Metric-Based Approach to Assess Risk for “On Cloud” Federated Identity Management

被引:0
|
作者
Patricia Arias-Cabarcos
Florina Almenárez-Mendoza
Andrés Marín-López
Daniel Díaz-Sánchez
Rosa Sánchez-Guerrero
机构
[1] University Carlos III of Madrid,Department of Telematics Engineering
关键词
Trust management; Cloud computing; Risk assessment metrics; SAML; Federation;
D O I
暂无
中图分类号
学科分类号
摘要
The cloud computing paradigm is set to become the next explosive revolution on the Internet, but its adoption is still hindered by security problems. One of the fundamental issues is the need for better access control and identity management systems. In this context, Federated Identity Management (FIM) is identified by researchers and experts as an important security enabler, since it will play a vital role in allowing the global scalability that is required for the successful implantation of cloud technologies. However, current FIM frameworks are limited by the complexity of the underlying trust models that need to be put in place before inter-domain cooperation. Thus, the establishment of dynamic federations between the different cloud actors is still a major research challenge that remains unsolved. Here we show that risk evaluation must be considered as a key enabler in evidence-based trust management to foster collaboration between cloud providers that belong to unknown administrative domains in a secure manner. In this paper, we analyze the Federated Identity Management process and propose a taxonomy that helps in the classification of the involved risks in order to mitigate vulnerabilities and threats when decisions about collaboration are made. Moreover, a set of new metrics is defined to allow a novel form of risk quantification in these environments. Other contributions of the paper include the definition of a generic hierarchical risk aggregation system, and a descriptive use-case where the risk computation framework is applied to enhance cloud-based service provisioning.
引用
收藏
页码:513 / 533
页数:20
相关论文
共 50 条
  • [31] A Federated Digital Identity Management Approach for Business Processes
    Bertino, Elisa
    Ferrini, Rodolfo
    Musci, Andrea
    Paci, Federica
    Steuer, Kevin J.
    COLLABORATIVE COMPUTING: NETWORKING, APPLICATIONS AND WORKSHARING, 2009, 10 : 194 - +
  • [32] A USER-CENTRIC APPROACH FOR FEDERATED IDENTITY MANAGEMENT
    Bergadano, Francesco
    Accornero, Renato
    Lucisano, Giovanna
    Rispoli, Daniele
    INTERNATIONAL JOURNAL ON INFORMATION TECHNOLOGIES AND SECURITY, 2013, 5 (01): : 3 - 18
  • [33] Metric-based approach to detect abstract data types and state encapsulations
    Girard J.-F.
    Koschke R.
    Schied G.
    Automated Software Engineering, 1999, 6 (4) : 357 - 386
  • [34] A metric-based approach to detect abstract data types and state encapsulations
    Girard, JF
    Koschke, R
    Scheid, G
    AUTOMATED SOFTWARE ENGINEERING, 12TH IEEE INTERNATIONAL CONFERENCE, PROCEEDINGS, 1997, : 82 - 89
  • [35] A Temporal Metric-Based Efficient Approach to Predict Citation Counts of Scientists
    Dewangan, Saumya Kumar
    Bhattacharjee, Shrutilipi
    Shetty, Ramya D.
    ARTIFICIAL INTELLIGENCE APPLICATIONS AND INNOVATIONS, AIAI 2023, PT I, 2023, 675 : 343 - 355
  • [36] ICEMAN: An Architecture for Secure Federated Inter-Cloud Identity Management
    Dreo, Gabi
    Golling, Mario
    Hommel, Wolfgang
    Tietze, Frank
    2013 IFIP/IEEE INTERNATIONAL SYMPOSIUM ON INTEGRATED NETWORK MANAGEMENT (IM 2013), 2013, : 1207 - 1210
  • [37] A Metric-Based Approach for Anti-pattern Detection in UML Designs
    Fourati, Rahma
    Bouassida, Nadia
    Ben Abdallah, Hanene
    COMPUTER AND INFORMATION SCIENCE 2011, 2011, 364 : 17 - 33
  • [38] Basic statistics for distributional symbolic variables: a new metric-based approach
    Antonio Irpino
    Rosanna Verde
    Advances in Data Analysis and Classification, 2015, 9 : 143 - 175
  • [39] Studying the Evolution of Library Utilization in Maven Projects: A Metric-Based Approach
    Kolyda, Maria
    Kostoglou, Eirini
    Nikolaidis, Nikolaos
    Ampatzoglou, Apostolos
    Chatzigeorgiou, Alexander
    SOFTWARE ARCHITECTURE: ECSA 2023 TRACKS, WORKSHOPS, AND DOCTORAL SYMPOSIUM, ECSA 2023, CASA 2023, AMP 2023, FAACS 2023, DEMESSA 2023, QUALIFIER 2023, TWINARCH 2023, 2024, 14590 : 359 - 374
  • [40] A Metric-Based Approach to Modelling a Virtual Machine for Smart Contract Execution
    Luca, Spataru Alexe
    Pungila, Ciprian
    2020 22ND INTERNATIONAL SYMPOSIUM ON SYMBOLIC AND NUMERIC ALGORITHMS FOR SCIENTIFIC COMPUTING (SYNASC 2020), 2020, : 302 - 309