跳到主要导航 跳到搜索 跳到主要内容

Toward a flexible and fine-grained access control framework for infrastructure as a service clouds

  • Bo Li
  • , Jianxin Li
  • , Lu Liu*
  • , Chao Zhou
  • *此作品的通讯作者
  • Beihang University
  • University of Derby

科研成果: 期刊稿件文章同行评审

摘要

Cloud computing, as an emerging computing paradigm, greatly facilitates resource sharing and enables providing computing power as services over the Internet. However, it also brings new challenges for security and access control, especially in infrastructure as a service clouds. The introduction of virtualization layer increases new security risks, which should be restricted and confined by more stringent access control techniques. In this paper, we propose a flexible and fine-grained access control framework, named IaaS-oriented Hybrid Access Control (iHAC), which combines the advantages of both the role-based access control and type enforcement model. We consider access control issues from the perspective of virtual machines. A permission transition model is designed to dynamically assign permissions to virtual machines. A Virtual Machine Monitor (VMM)-based access control mechanism is presented to confine the virtual machine's behaviors in a fine-grained manner. A VMM-enabled network access control approach is proposed to regulate the communication among virtual machines. iHAC is successfully implemented in the Internet based Virtual Computing Infrastructure (iVIC) platform, and several experiments are conducted to evaluate its effectiveness and efficiency. The results show that iHAC can make correct access control decisions with low performance overhead.

源语言英语
页(从-至)2730-2743
页数14
期刊Security and Communication Networks
9
15
DOI
出版状态已出版 - 1 10月 2016

指纹

探究 'Toward a flexible and fine-grained access control framework for infrastructure as a service clouds' 的科研主题。它们共同构成独一无二的指纹。

引用此