Back to Search Start Over

A Secure Access Control Framework for Cloud Management.

Authors :
Zhang, Jiawei
Lu, Ning
Ma, Jianfeng
Wang, Ruixiao
Shi, Wenbo
Source :
Mobile Networks & Applications. Feb2022, Vol. 27 Issue 1, p404-416. 13p.
Publication Year :
2022

Abstract

Cloud operating system (Cloud OS) is the heart of cloud management platform that takes control of various cloud resources. Therefore, it attracts numerous attacks, especially unauthorized access. Many existing works adopt role-based access control (RBAC) model for Cloud OS access control and token-based approaches as user credentials of sessions or transactions between users and cloud, but they fail to resist privilege abuse caused by RBAC policy rules tampering or token hijacking. To addresses this challenging problem, we propose a secure access control framework suitable for resource-centric Cloud OS. For one thing, we propose a new authorization model with cryptographically protected RBAC policy rules. To solve the policy decision problem caused by encrypted policy rules in this model, an approach is developed to transform it into permission searching problem and we further propose a policy decision scheme based on this. For another thing, we achieve user token unlinkability and token-replay-attack resistance by introducing randomization mechanism and leveraging one-show token technique. A proof of concept implementation has been developed and the proposed scheme is proven secure and efficient by security analysis and the performance evaluation. [ABSTRACT FROM AUTHOR]

Details

Language :
English
ISSN :
1383469X
Volume :
27
Issue :
1
Database :
Academic Search Index
Journal :
Mobile Networks & Applications
Publication Type :
Academic Journal
Accession number :
155954866
Full Text :
https://doi.org/10.1007/s11036-021-01839-w