Adding Federated Identity Management to OpenStack

被引:0
|
作者
David W. Chadwick
Kristy Siu
Craig Lee
Yann Fouillat
Damien Germonville
机构
[1] University of Kent,
[2] The Aerospace Corporation,undefined
来源
Journal of Grid Computing | 2014年 / 12卷
关键词
Federated identity management; Federated access; OpenStack; Cloud;
D O I
暂无
中图分类号
学科分类号
摘要
OpenStack is an open source cloud computing project that is enjoying wide. While many cloud deployments may be stand-alone, it is clear that secure federated community clouds, i.e., inter-clouds, are needed. Hence, there must be methods for federated identity management (FIM) that enable authentication and authorisation to be flexibly enforced across federated environments. Since there are many different FIM protocols either in use or in development today, this paper addresses the goal of adding protocol independent federated identity management to the OpenStack services. After giving a motivating example for secure cloud federation, and describing the conceptual design for protocol independent federated access, a detailed federated identity protocol sequence is presented. The paper then describes the implementation of the protocol independent system components, along with the incorporation of two different FIM protocols, namely SAML and Keystone proprietary. Finally performance measurements of the protocol independent components, and the two different protocols dependent components are presented, before the paper concludes with the current limitations.
引用
收藏
页码:3 / 27
页数:24
相关论文
共 50 条
  • [1] Adding Federated Identity Management to OpenStack
    Chadwick, David W.
    Siu, Kristy
    Lee, Craig
    Fouillat, Yann
    Germonville, Damien
    [J]. JOURNAL OF GRID COMPUTING, 2014, 12 (01) : 3 - 27
  • [2] A Review of Federated Identity Management of OpenStack Cloud
    Shere, Rohit
    Srivastava, Sonika
    Pateriya, R. K.
    [J]. 2017 INTERNATIONAL CONFERENCE ON RECENT INNOVATIONS IN SIGNAL PROCESSING AND EMBEDDED SYSTEMS (RISE), 2017, : 516 - 520
  • [3] Federated identity management
    Shim, SSY
    Bhalla, G
    Pendyala, V
    [J]. COMPUTER, 2005, 38 (12) : 120 - 122
  • [4] Assurance for federated identity management
    Baldwin, Adrian
    Casassa Mont, Marco
    Beres, Yolanta
    Shiu, Simon
    [J]. JOURNAL OF COMPUTER SECURITY, 2010, 18 (04) : 541 - 572
  • [5] Federated Identity Management for Research
    Barton, Thomas
    Gietz, Peter
    Kelsey, David
    Koranda, Scott
    Short, Hannah
    Stevanovic, Uros
    [J]. 23RD INTERNATIONAL CONFERENCE ON COMPUTING IN HIGH ENERGY AND NUCLEAR PHYSICS (CHEP 2018), 2019, 214
  • [6] Federated Identity Management Challenges
    Jensen, Jostein
    [J]. 2012 SEVENTH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY (ARES), 2012, : 230 - 235
  • [7] Federated Identity Management for Android
    Fongen, Anders
    [J]. PROCEEDINGS OF THE FIFTH INTERNATIONAL CONFERENCE ON EMERGING SECURITY INFORMATION, SYSTEMS AND TECHNOLOGIES (SECURWARE 2011), 2011, : 77 - 82
  • [8] Adding Energy Efficiency To Openstack
    Cima, Vojtech
    Grazioli, Bruno
    Murphy, Sean
    Bohnert, Thomas Michael
    [J]. 2015 SUSTAINABLE INTERNET AND ICT FOR SUSTAINABILITY (SUSTAINIT), 2015,
  • [9] On Identity Assurance in the Presence of Federated Identity Management Systems
    Baldwin, Adrian
    Mont, Marco Casassa
    Beres, Yolanta
    Shiu, Simon
    [J]. DIM'07: PROCEEDINGS OF THE 2007 ACM WORKSHOP ON DIGITAL IDENTITY MANAGEMENT, 2007, : 27 - 35
  • [10] The Venn of identity - Options and issues in federated identity management
    Maler, Eve
    Reed, Drummond
    [J]. IEEE SECURITY & PRIVACY, 2008, 6 (02) : 16 - 23