• DocumentCode
    1726542
  • Title

    Policy and Context Management in Dynamically Provisioned Access Control Service for Virtualized Cloud Infrastructures

  • Author

    Ngo, Canh ; Membrey, Peter ; Demchenko, Yuri ; De Laat, Cees

  • Author_Institution
    Univ. of Amsterdam, Amsterdam, Netherlands
  • fYear
    2012
  • Firstpage
    343
  • Lastpage
    349
  • Abstract
    Cloud computing is developing as a new wave of ICT technologies, offering a common approach to on-demand provisioning of computation, storage and network resources which are generally referred to as infrastructure services. Most of currently available commercial Cloud services are built and organized reflecting simple relations between a single provider and multiple customers with simple security and trust model. New architectural models should allow multi-provider heterogeneous service environment that can be delivered to organizational customers representing multiple user groups. These models should be supported by new security approaches for multi-provider, multi-tenant environment crossing multiple security domains to create consistent and dynamically configurable security services for virtualized infrastructures. This paper proposes an on-demand provisioned access control infrastructure with dynamic trust establishment for entities in a Cloud IaaS architecture model. It applies XACML-based RBAC model for the flexible authorization policy configuration and management. It uses authorization ticket as a security session management mechanism to solve the security context synchronization and exchange between multiple Cloud providers. The paper describes practical implementation of the proposed Dynamic Access Control Infrastructure as the part of a complex infrastructure services provisioning system.
  • Keywords
    XML; authorisation; cloud computing; software architecture; software management; virtualisation; ICT technologies; XACML-based RBAC model; authorization ticket; cloud IaaS architecture model; cloud computing; cloud services; complex infrastructure services provisioning system; computation resources; context management; dynamic trust establishment; dynamically provisioned access control service; flexible authorization policy configuration; flexible authorization policy management; infrastructure services; network resources; policy management; security context synchronization; security model; security session management mechanism; storage resources; trust model; virtualized cloud infrastructures; Authentication; Authorization; Cloud computing; Computational modeling; Context; Dynamic Access Control Infrastructure; Dynamic Trust Establishment; Policy Generation; RBAC; Security Context Management; XACML;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Availability, Reliability and Security (ARES), 2012 Seventh International Conference on
  • Conference_Location
    Prague
  • Print_ISBN
    978-1-4673-2244-7
  • Type

    conf

  • DOI
    10.1109/ARES.2012.81
  • Filename
    6329203