Towards Multi-party Policy-based Access Control in Federations of Cloud and Edge Microservices
Towards Multi-party Policy-based Access Control in Federations of Cloud and Edge Microservices
复制标题
云和边缘微服务联合中的多方基于策略的访问控制
DOI:
10.1109/eurospw.2019.00010
复制
发表时间:
2019
期刊:
影响因子:
--
通讯作者:
W. Joosen
中科院分区:
文献类型:
--
作者:
Davy Preuveneers;W. Joosen
The development and deployment of microservices and containers come with a promise of flexibility by embracing heterogeneity and reducing the amount of communication and coordination between service teams. However, when such software ecosystems are developed in large organizations with a high degree of independence, and deployed in the cloud and at the edge, security becomes a non-trivial concern. The challenge that we address in this work is the delegated management of access control decisions to multiple stakeholders in continuously evolving federations of cloud and edge microservices. To ensure that user-centric access control remains sustainable in such complex service delivery models, we present a dynamic granular access control solution on top of different authorization frameworks. By leveraging microservice technologies, our solution is flexible, scalable, and contextual, and can adhere to the security needs of different stakeholders in microservice federations - from DevOps teams to common end-users - with the necessary agility to respond to exceptional security circumstances.