CloudPolice: taking access control out of the network
CloudPolice: taking access control out of the network
复制标题
DOI:
10.1145/1868447.1868454
复制
发表时间:
2010-10
期刊:
影响因子:
--
通讯作者:
L. Popa;Minlan Yu;Steven Y. Ko;Sylvia Ratnasamy;I. Stoica
中科院分区:
文献类型:
--
作者:
L. Popa;Minlan Yu;Steven Y. Ko;Sylvia Ratnasamy;I. Stoica
Cloud computing environments impose new challenges on access control techniques due to multi-tenancy, the growing scale and dynamicity of hosts within the cloud infrastructure, and the increasing diversity of cloud network architectures. The majority of existing access control techniques were originally designed for enterprise environments that do not share these challenges and, as such, are poorly suited for cloud environments. In this paper, we argue that it is both sufficient and advantageous to implement access control only within the hypervisors at the end-hosts. We thus propose Cloud-Police, a system that implements a hypervisor-based access control mechanism. We argue that, not only can CloudPolice support more sophisticated access control policies, it can do so in a manner that is simpler, more scalable and more robust than existing network-based techniques.