Towards Multi-party Policy-based Access Control in Federations of Cloud and Edge Microservices

Towards Multi-party Policy-based Access Control in Federations of Cloud and Edge Microservices
复制标题

云和边缘微服务联合中的多方基于策略的访问控制

DOI:
10.1109/eurospw.2019.00010
复制
发表时间:
2019
期刊:
2019 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)
影响因子:
--
通讯作者:
W. Joosen
W. Joosen
中科院分区:
--
文献类型:
--
作者:
Davy Preuveneers;W. Joosen

文献摘要

被引文献

相似文献

微服务和容器的开发和部署承诺了灵活性,因为它接受了异构性,并减少了服务团队之间的通信和协调量。然而,当这种软件生态系统在具有高度独立性的大型组织中开发,并部署在云中和边缘时,安全就成了一个不容忽视的问题。我们在这项工作中解决的挑战是,在不断发展的云和边缘微服务联合中,将访问控制决策委托给多个利益相关者进行管理。为了确保以用户为中心的访问控制在这种复杂的服务交付模型中保持可持续,我们提出了一种基于不同授权框架的动态粒度访问控制解决方案。通过利用微服务技术,我们的解决方案具有灵活性、可扩展性和上下文相关性,并且可以满足微服务联盟中不同利益相关者-从DevOps团队到普通最终用户-的安全需求,并具有必要的敏捷性来响应特殊的安全环境。
The development and deployment of microservices and containers come with a promise of flexibility by embracing heterogeneity and reducing the amount of communication and coordination between service teams. However, when such software ecosystems are developed in large organizations with a high degree of independence, and deployed in the cloud and at the edge, security becomes a non-trivial concern. The challenge that we address in this work is the delegated management of access control decisions to multiple stakeholders in continuously evolving federations of cloud and edge microservices. To ensure that user-centric access control remains sustainable in such complex service delivery models, we present a dynamic granular access control solution on top of different authorization frameworks. By leveraging microservice technologies, our solution is flexible, scalable, and contextual, and can adhere to the security needs of different stakeholders in microservice federations - from DevOps teams to common end-users - with the necessary agility to respond to exceptional security circumstances.