Towards a fine-grained access control for cloud

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

The centerpiece of an efficient Cloud security architecture is a well-defined access control policy. In literature we can find several access control models such as the Mandatory Access Control (MAC), Discretionary Access Control (DAC), Role-Based Access Control (RBAC) and the latest one Usage Control Authorization, oBligation and Condition (UCONABC). The UCONABC is very suitable for the context of distributed systems like cloud computing but it doesn't give any implementation method. In this paper we define the profile centric model using graph formalism and its implementation using matrix. We define the profile as the combination of all possible authorization, obligation, condition, role, etc... and other access parameters like attributes that we can found in Cloud system. We discuss its application using three matrixes (profile definition, profile inheritance and user assignment). Profile centric modeling is an optimum paradigm to define access control policy in complex distributed and elastic system like cloud computing. The proposed solution is validated and implemented over Hadoop distributed file system in the context of Safe Box as a service.

Original languageEnglish
Title of host publicationProceedings - 11th IEEE International Conference on E-Business Engineering, ICEBE 2014 - Including 10th Workshop on Service-Oriented Applications, Integration and Collaboration, SOAIC 2014 and 1st Workshop on E-Commerce Engineering, ECE 2014
EditorsYinsheng Li, Xiang Fei, Kuo-Ming Chao, Jen-Yao Chung
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages286-291
Number of pages6
ISBN (Electronic)9781479965632
DOIs
Publication statusPublished - 10 Dec 2014
Event11th IEEE International Conference on E-Business Engineering, ICEBE 2014 - Guangzhou, China
Duration: 5 Nov 20147 Nov 2014

Publication series

NameProceedings - 11th IEEE International Conference on E-Business Engineering, ICEBE 2014 - Including 10th Workshop on Service-Oriented Applications, Integration and Collaboration, SOAIC 2014 and 1st Workshop on E-Commerce Engineering, ECE 2014

Conference

Conference11th IEEE International Conference on E-Business Engineering, ICEBE 2014
Country/TerritoryChina
CityGuangzhou
Period5/11/147/11/14

Keywords

  • Cloud
  • Profile centric model
  • Safe Box
  • access control
  • graph
  • security

Fingerprint

Dive into the research topics of 'Towards a fine-grained access control for cloud'. Together they form a unique fingerprint.

Cite this