DocumentCode :
3000724
Title :
A Usage Control Based Architecture for Cloud Environments
Author :
Tavizi, Tina ; Shajari, Mehdi ; Dodangeh, Peyman
Author_Institution :
Dept. of Comput. Eng. & IT, Amirkabir Univ. of Technol., Tehran, Iran
fYear :
2012
fDate :
21-25 May 2012
Firstpage :
1534
Lastpage :
1539
Abstract :
Today modern computing systems leverage distributed models such as cloud, grid, etc. One of the obstacles of wide spreading these distributed computing models is security challenges which includes access control problem. These computing models because of providing features like on-demand self-service, ubiquitous network access, rapid elasticity and scalability, having dynamic infrastructure and offering measured service, need a powerful and continuous control over access and usage session. Usage control (UCON) model is emerged to cover some drawbacks of traditional access control models with features like attribute mutability and continuity of control. Several recent works have been done to apply UCON for distributed computing environments, but none of them could cover all aspects of the model. In this paper we propose an architecture for applying UCON model in cloud environments. Moreover we present a new architecture for obligation handling. We also introduce a new approach to handle attribute mutability. For implementation we have extended XACML syntax and semantics as policy language and leveraged Sun´s OASIS XACML implementation.
Keywords :
XML; authorisation; cloud computing; Sun OASIS XACML implementation; UCON model; XACML semantics; XACML syntax; access control problem; attribute mutability; cloud environment; continuous access control; control continuity; distributed computing environment; distributed computing model; dynamic infrastructure; measured service; obligation handling; on-demand self-service; policy language; rapid elasticity; scalability; security challenge; ubiquitous network access; usage control based architecture; usage session; Authorization; Cloud computing; Computational modeling; Computer architecture; Databases; Enforcement architecture; UCON; XACML; access control; authorization; cloud computing; condition; obligation; usage control;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Parallel and Distributed Processing Symposium Workshops & PhD Forum (IPDPSW), 2012 IEEE 26th International
Conference_Location :
Shanghai
Print_ISBN :
978-1-4673-0974-5
Type :
conf
DOI :
10.1109/IPDPSW.2012.193
Filename :
6270824
Link To Document :
بازگشت