Information Flow Control for Secure Cloud Computing

Information Flow Control for Secure Cloud Computing
复制标题

DOI:
10.1109/tnsm.2013.122313.130423
复制
发表时间:
2014-01
影响因子:
5.3
通讯作者:
J. Bacon;D. Eyers;Thomas Pasquier;Jatinder Singh;I. Papagiannis;P. Pietzuch
J. Bacon;D. Eyers;Thomas Pasquier;Jatinder Singh;I. Papagiannis;P. Pietzuch
中科院分区:
计算机科学2区
文献类型:
--
作者:
J. Bacon;D. Eyers;Thomas Pasquier;Jatinder Singh;I. Papagiannis;P. Pietzuch

文献摘要

被引文献

相似文献

安全问题被广泛视为采用云计算解决方案的障碍。信息流控制(IFC)是一种很好理解的强制访问控制方法。最早的IFC模型针对集中式环境中的安全性,但分散式形式的IFC已被设计和实施,通常在学术研究项目中。因此,分散的IFC有可能实现比目前更好的云安全性。在本文中,我们描述了云计算的属性,特别是平台即服务云,并回顾了一系列IFC模型和实施,以确定在云计算环境中使用IFC的机会。由于IFC安全与其保护的数据相关联,云服务的租户和提供商可以就安全政策达成一致,而不需要他们理解和依赖云软件堆栈的细节来实施。
Security concerns are widely seen as an obstacle to the adoption of cloud computing solutions. Information Flow Control (IFC) is a well understood Mandatory Access Control methodology. The earliest IFC models targeted security in a centralised environment, but decentralised forms of IFC have been designed and implemented, often within academic research projects. As a result, there is potential for decentralised IFC to achieve better cloud security than is available today. In this paper we describe the properties of cloud computing-Platform-as-a-Service clouds in particular-and review a range of IFC models and implementations to identify opportunities for using IFC within a cloud computing context. Since IFC security is linked to the data that it protects, both tenants and providers of cloud services can agree on security policy, in a manner that does not require them to understand and rely on the particulars of the cloud software stack in order to effect enforcement.