DocumentCode
3000724
Title
A Usage Control Based Architecture for Cloud Environments
Author
Tavizi, Tina ; Shajari, Mehdi ; Dodangeh, Peyman
Author_Institution
Dept. of Comput. Eng. & IT, Amirkabir Univ. of Technol., Tehran, Iran
fYear
2012
fDate
21-25 May 2012
Firstpage
1534
Lastpage
1539
Abstract
Today modern computing systems leverage distributed models such as cloud, grid, etc. One of the obstacles of wide spreading these distributed computing models is security challenges which includes access control problem. These computing models because of providing features like on-demand self-service, ubiquitous network access, rapid elasticity and scalability, having dynamic infrastructure and offering measured service, need a powerful and continuous control over access and usage session. Usage control (UCON) model is emerged to cover some drawbacks of traditional access control models with features like attribute mutability and continuity of control. Several recent works have been done to apply UCON for distributed computing environments, but none of them could cover all aspects of the model. In this paper we propose an architecture for applying UCON model in cloud environments. Moreover we present a new architecture for obligation handling. We also introduce a new approach to handle attribute mutability. For implementation we have extended XACML syntax and semantics as policy language and leveraged Sun´s OASIS XACML implementation.
Keywords
XML; authorisation; cloud computing; Sun OASIS XACML implementation; UCON model; XACML semantics; XACML syntax; access control problem; attribute mutability; cloud environment; continuous access control; control continuity; distributed computing environment; distributed computing model; dynamic infrastructure; measured service; obligation handling; on-demand self-service; policy language; rapid elasticity; scalability; security challenge; ubiquitous network access; usage control based architecture; usage session; Authorization; Cloud computing; Computational modeling; Computer architecture; Databases; Enforcement architecture; UCON; XACML; access control; authorization; cloud computing; condition; obligation; usage control;
fLanguage
English
Publisher
ieee
Conference_Titel
Parallel and Distributed Processing Symposium Workshops & PhD Forum (IPDPSW), 2012 IEEE 26th International
Conference_Location
Shanghai
Print_ISBN
978-1-4673-0974-5
Type
conf
DOI
10.1109/IPDPSW.2012.193
Filename
6270824
Link To Document