DocumentCode :
624010
Title :
Multi-tenancy authorization models for collaborative cloud services
Author :
Bo Tang ; Sandhu, Ravi ; Qi Li
Author_Institution :
Inst. for Cyber Security, Univ. of Texas at San Antonio, San Antonio, TX, USA
fYear :
2013
fDate :
20-24 May 2013
Firstpage :
132
Lastpage :
138
Abstract :
The cloud service model intrinsically caters to multiple tenants, most obviously in public clouds but also in private clouds for large organizations. Currently most cloud service providers (CSPs) isolate user activities and data within a single tenant boundary with no or minimum cross-tenant interaction. It is anticipated that this situation will evolve soon to foster cross-tenant collaboration supported by Authorization as a Service (AaaS). At present there is no widely accepted model for cross-tenant authorization. Recently, Calero et al [12] informally presented a multi-tenancy authorization system (MTAS) which extends the well-known role-based access control (RBAC) model by building trust relations among collaborating tenants. In this paper we formalize this MTAS model and propose extensions for finer-grained cross-tenant trust. We also develop an administration model for MTAS (AMTAS). We demonstrate the utility and practical feasibility of MTAS by means of an example policy specification in XACML. We anticipate researchers will develop additional multi-tenant authorization models before eventual consolidation and unification.
Keywords :
authorisation; cloud computing; groupware; trusted computing; AMTAS; AaaS; CSP; MTAS model; RBAC model; XACML; administration model for MTAS; authorization as a service; cloud service model; cloud service providers; collaborative cloud services; cross-tenant collaboration; finer-grained cross-tenant trust; minimum cross-tenant interaction; multitenancy authorization model; multitenancy authorization system; policy specification; private clouds; public clouds; role-based access control; trust relations; user activities; user data; Authorization; Cloud computing; Collaboration; Computational modeling; Organizations; Software as a service; Access Control in Collaboration Environments; Fundamentals and Frameworks for Security in Collaboration Systems; Privacy Protection for Collaboration Systems; Role Based Access Control, Reputation, and Trust; Security Models for Cloud Computing;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Collaboration Technologies and Systems (CTS), 2013 International Conference on
Conference_Location :
San Diego, CA
Print_ISBN :
978-1-4673-6403-4
Type :
conf
DOI :
10.1109/CTS.2013.6567218
Filename :
6567218
Link To Document :
بازگشت