CloudPolice: taking access control out of the network

CloudPolice: taking access control out of the network
复制标题

DOI:
10.1145/1868447.1868454
复制
发表时间:
2010-10
期刊:
--
影响因子:
--
通讯作者:
L. Popa;Minlan Yu;Steven Y. Ko;Sylvia Ratnasamy;I. Stoica
L. Popa;Minlan Yu;Steven Y. Ko;Sylvia Ratnasamy;I. Stoica
中科院分区:
其他
文献类型:
--
作者:
L. Popa;Minlan Yu;Steven Y. Ko;Sylvia Ratnasamy;I. Stoica

文献摘要

被引文献

相似文献

由于多租户、云基础设施内主机的规模和动态性不断增长以及云网络架构的多样性不断增加,云计算环境对访问控制技术提出了新的挑战。大多数现有的访问控制技术最初是为不面临这些挑战的企业环境设计的,因此不太适合云环境。在本文中,我们认为仅在终端主机的虚拟机管理程序内实现访问控制既充分又有利。因此,我们提出了 Cloud-Police,一个实现基于管理程序的访问控制机制的系统。我们认为,CloudPolice 不仅可以支持更复杂的访问控制策略,而且可以以比现有基于网络的技术更简单、更可扩展和更强大的方式实现这一点。
Cloud computing environments impose new challenges on access control techniques due to multi-tenancy, the growing scale and dynamicity of hosts within the cloud infrastructure, and the increasing diversity of cloud network architectures. The majority of existing access control techniques were originally designed for enterprise environments that do not share these challenges and, as such, are poorly suited for cloud environments. In this paper, we argue that it is both sufficient and advantageous to implement access control only within the hypervisors at the end-hosts. We thus propose Cloud-Police, a system that implements a hypervisor-based access control mechanism. We argue that, not only can CloudPolice support more sophisticated access control policies, it can do so in a manner that is simpler, more scalable and more robust than existing network-based techniques.