• DocumentCode
    3000724
  • Title

    A Usage Control Based Architecture for Cloud Environments

  • Author

    Tavizi, Tina ; Shajari, Mehdi ; Dodangeh, Peyman

  • Author_Institution
    Dept. of Comput. Eng. & IT, Amirkabir Univ. of Technol., Tehran, Iran
  • fYear
    2012
  • fDate
    21-25 May 2012
  • Firstpage
    1534
  • Lastpage
    1539
  • Abstract
    Today modern computing systems leverage distributed models such as cloud, grid, etc. One of the obstacles of wide spreading these distributed computing models is security challenges which includes access control problem. These computing models because of providing features like on-demand self-service, ubiquitous network access, rapid elasticity and scalability, having dynamic infrastructure and offering measured service, need a powerful and continuous control over access and usage session. Usage control (UCON) model is emerged to cover some drawbacks of traditional access control models with features like attribute mutability and continuity of control. Several recent works have been done to apply UCON for distributed computing environments, but none of them could cover all aspects of the model. In this paper we propose an architecture for applying UCON model in cloud environments. Moreover we present a new architecture for obligation handling. We also introduce a new approach to handle attribute mutability. For implementation we have extended XACML syntax and semantics as policy language and leveraged Sun´s OASIS XACML implementation.
  • Keywords
    XML; authorisation; cloud computing; Sun OASIS XACML implementation; UCON model; XACML semantics; XACML syntax; access control problem; attribute mutability; cloud environment; continuous access control; control continuity; distributed computing environment; distributed computing model; dynamic infrastructure; measured service; obligation handling; on-demand self-service; policy language; rapid elasticity; scalability; security challenge; ubiquitous network access; usage control based architecture; usage session; Authorization; Cloud computing; Computational modeling; Computer architecture; Databases; Enforcement architecture; UCON; XACML; access control; authorization; cloud computing; condition; obligation; usage control;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Parallel and Distributed Processing Symposium Workshops & PhD Forum (IPDPSW), 2012 IEEE 26th International
  • Conference_Location
    Shanghai
  • Print_ISBN
    978-1-4673-0974-5
  • Type

    conf

  • DOI
    10.1109/IPDPSW.2012.193
  • Filename
    6270824