Loading...

A usage control based architecture for cloud environments

Tavizi, T ; Sharif University of Technology | 2012

505 Viewed
  1. Type of Document: Article
  2. DOI: 10.1109/IPDPSW.2012.193
  3. Publisher: 2012
  4. Abstract:
  5. Today modern computing systems leverage distributed models such as cloud, grid, etc. One of the obstacles of wide spreading these distributed computing models is security challenges which includes access control problem. These computing models because of providing features like on-demand self-service, ubiquitous network access, rapid elasticity and scalability, having dynamic infrastructure and offering measured service, need a powerful and continuous control over access and usage session. Usage control (UCON) model is emerged to cover some drawbacks of traditional access control models with features like attribute mutability and continuity of control. Several recent works have been done to apply UCON for distributed computing environments, but none of them could cover all aspects of the model. In this paper we propose an architecture for applying UCON model in cloud environments. Moreover we present a new architecture for obligation handling. We also introduce a new approach to handle attribute mutability. For implementation we have extended XACML syntax and semantics as policy language and leveraged Sun's OASIS XACML implementation
  6. Keywords:
  7. Enforcement architecture ; Authorization ; Condition ; Obligation ; UCON ; Usage control ; XACML ; Cloud computing ; Distributed computer systems ; Distributed parameter networks ; Elasticity ; Semantics ; Access control
  8. Source: Proceedings of the 2012 IEEE 26th International Parallel and Distributed Processing Symposium Workshops, IPDPSW 2012, 21 May 2012 through 25 May 2012 ; 2012 , Pages 1534-1539 ; 9780769546766 (ISBN)
  9. URL: http://ieeexplore.ieee.org/xpl/articleDetails.jsp?arnumber=6270824