Skip to main navigation Skip to search Skip to main content

VRBAC: An extended RBAC model for virtualized environment and its conflict checking approach

  • Yang Luo
  • , Yazhuo Li
  • , Qing Tang
  • , Zhao Wei
  • , Chunhe Xia
  • Beihang University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

This paper extends RBAC's authorizing ability via adding domain and virtual machine features aiming at applying in the virtu-alized scenarios. We define a new model named VRBAC in which authorized users can migrate or copy virtual machines from one domain to another without causing a conflict. Subjects can also share permissions of not only resources but also virtual machines with other subjects from the same or different domains. Three types of conflicts in VRBAC policies are discussed and described in form of description logic, which provides extra access to reasoning engines and facilitates the conflict checking procedure. Based on Active Directory and Xen Cloud Platform, VRBAC model visualization and its conflict checking can be enforced within the prototype system. The experimental results indicate that all conflicts can be effectively detected and the literal report generated can provide conflict details such as conflict types, positions and causes as guidance for further conflict resolution.

Original languageEnglish
Title of host publicationFrontiers in Internet Technologies - Second CCF Internet Conference of China, ICoC 2013, Revised Selected Papers
PublisherSpringer Verlag
Pages194-205
Number of pages12
ISBN (Print)9783642539589
DOIs
StatePublished - 2013
Event2nd CCF Internet Conference of China, ICoC 2013 - Zhangjiajie, China
Duration: 10 Jul 201310 Jul 2013

Publication series

NameCommunications in Computer and Information Science
Volume401
ISSN (Print)1865-0929

Conference

Conference2nd CCF Internet Conference of China, ICoC 2013
Country/TerritoryChina
CityZhangjiajie
Period10/07/1310/07/13

Keywords

  • Description logic
  • Policy conflict
  • RBAC
  • Virtualization

Fingerprint

Dive into the research topics of 'VRBAC: An extended RBAC model for virtualized environment and its conflict checking approach'. Together they form a unique fingerprint.

Cite this