Sette, Ioram S., Chadwick, David W., Ferraz, Carlos A. G. (2017) Authorization Policy Federation in Heterogeneous Multicloud Environments. IEEE Cloud Computing, 4 (4). pp. 38-47. ISSN 2325-6095. (doi:10.1109/MCC.2017.3791018) (KAR id:64214)
PDF
Author's Accepted Manuscript
Language: English |
|
Download this file (PDF/542kB) |
Preview |
Request a format suitable for use with assistive technology e.g. a screenreader | |
Official URL: http://dx.doi.org/10.1109/MCC.2017.3791018 |
Abstract
Current Infrastructure as a Service (IaaS) cloud platforms have their own authorisation system, containing different access control policies and models. Clients with accounts in multiple cloud providers struggle to manage their rules in order to provide a homogeneous access control experience to users. This work proposes a solution: an Authorisation Policy Federation (APF) of heterogeneous cloud accounts. These federated accounts share a centrally managed policy written in Disjunctive Normal Form (DNF) using a cloud-independent ontology. This shared abstract policy can be translated to local cloud formats, and back again. Prototypes were implemented for OpenStack and Amazon Web Services (AWS) cloud formats, and rules were successfully translated with a Level of Semantic Equivalence (LSE) higher than 80.
Item Type: | Article |
---|---|
DOI/Identification number: | 10.1109/MCC.2017.3791018 |
Subjects: |
Q Science T Technology |
Divisions: | Divisions > Division of Computing, Engineering and Mathematical Sciences > School of Computing |
Depositing User: | David Chadwick |
Date Deposited: | 02 Nov 2017 08:50 UTC |
Last Modified: | 05 Nov 2024 11:00 UTC |
Resource URI: | https://kar.kent.ac.uk/id/eprint/64214 (The current URI for this page, for reference purposes) |
- Link to SensusAccess
- Export to:
- RefWorks
- EPrints3 XML
- BibTeX
- CSV
- Depositors only (login required):