Sticky Policy Based Open Source Security APIs for the Cloud

基于粘性策略的云开源安全 API

基本信息

  • 批准号:
    EP/J020354/1
  • 负责人:
  • 金额:
    $ 16.17万
  • 依托单位:
  • 依托单位国家:
    英国
  • 项目类别:
    Research Grant
  • 财政年份:
    2012
  • 资助国家:
    英国
  • 起止时间:
    2012 至 无数据
  • 项目状态:
    已结题

项目摘要

The Internet and telephone are successful because they use open protocols and open interfaces, allowing users to communicate, innovate and share at will. We propose to facilitate this process in cloud computing, by developing a set of open security services, protocols and interfaces (APIs) that will allow cloud resource owners to be able to specify their policies for fine grained access control to their cloud resources, and have these enforced everywhere at all times, regardless of the subsequent location or data processing that has ensued. The ability to securely share data with anyone, anywhere, at any time, will facilitate spontaneous collaborations and ensure confidence in collaborative working. This will be achieved by using "sticky policies", delegation of authority, federated access and attribute based access controls. Sticky policies are policies which are cryptographically linked or "stuck" to the data and meta-data they control, so that access to the data is only granted if the policy is honoured. In order to cater for Internet scale cloud usage, federated access and attribute based access controls are needed. Federated access allows users to identify themselves to a cloud service using their existing credentials, without having to first obtain new ones from the cloud service itself. Attribute based access controls allows access to be specified based on a user's identity attributes rather than simply an identifier, which is typically used today. In order to achieve Internet scale in identifying users and data resources, an ontology is needed that will classify both the data and the users who wish to access it. The authorities who issue identity attributes will also need to be classified. The characteristics of any particular set of data will be held in meta-data that describes or identifies the data, and conforms to the ontology. The meta-data itself will be stuck to the data in a similar way to the sticky policy.When data is merged or fused with other data, or is split, filtered or reduced, then its meta-data will need to change accordingly, in order to describe the new data. Similarly the sticky policy that controls access to the new data will need to be derived from the original sticky policy(ies). This project will develop a new algebra and algorithms for deriving the new sticky policy from the old, using the ontology and meta-data as a guide. (Note that this project will not be performing the actual data merging or splitting, but simply assumes that trustworthy services are available to do this.)The protocols and APIs specified in this project will be standardised through an organisation already well versed in cloud APIs, such as the Open Grid Forum or OASIS.In order to ensure the widest take up of the services and APIs specified in this project, pilot implementations will be developed in Python and distributed as part of the OpenStack suite of software. OpenStack is a community project involving over 135 organisations, ranging from multi-nationals such as HP, Cisco and Intel, to specialist SMEs such as Cloudscaling. This project proposes to harness the energies of the OpenStack community by acting in a leading role to facilitate others in contributing to the development effort.
互联网和电话之所以成功,是因为它们使用开放协议和开放接口,允许用户随意交流、创新和分享。我们建议通过开发一组开放的安全服务,协议和接口(API)来促进云计算中的这一过程,这些服务,协议和接口(API)将允许云资源所有者能够指定其策略,以便对其云资源进行细粒度的访问控制,并随时随地执行这些策略,而不管随后的位置或数据处理如何。与任何人、任何地方、任何时间安全共享数据的能力将促进自发协作,并确保协作工作的信心。这将通过使用“粘性政策”、授权、联合访问和基于属性的访问控制来实现。粘性策略是以加密方式链接或“粘”到它们所控制的数据和元数据的策略,因此只有在遵守策略的情况下才授予对数据的访问。为了满足互联网规模的云使用,需要联合访问和基于属性的访问控制。联合访问允许用户使用其现有凭证向云服务标识自己,而不必首先从云服务本身获取新凭证。基于属性的访问控制允许基于用户的身份属性而不是简单地基于标识符来指定访问,这通常是当今使用的。为了在互联网范围内识别用户和数据资源,需要一个本体,对数据和希望访问数据的用户进行分类,还需要对发布身份属性的机构进行分类。任何特定数据集的特征都将保存在描述或标识数据的元数据中,并符合本体。元数据本身将以类似于粘性策略的方式被粘在数据上。当数据与其他数据合并或融合时,或者被拆分,过滤或缩减时,其元数据将需要相应地改变,以便描述新数据。类似地,控制对新数据的访问的粘性策略将需要从原始粘性策略导出。这个项目将开发一个新的代数和算法,用于从旧的粘性策略中导出新的粘性策略,使用本体和元数据作为指导。(Note该项目不会执行实际的数据合并或拆分,而只是假设有值得信赖的服务可用于执行此操作。)该项目中指定的协议和API将通过一个已经精通云API的组织进行标准化,例如开放网格论坛或OASIS。为了确保该项目中指定的服务和API得到最广泛的采用,将使用Python开发试点实现,并作为OpenStack软件套件的一部分分发。OpenStack是一个社区项目,涉及超过135个组织,从惠普、思科和英特尔等跨国公司到Cloudscaling等专业中小企业。该项目旨在通过发挥领导作用来利用OpenStack社区的能量,以促进其他人为开发工作做出贡献。

项目成果

期刊论文数量(1)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Adding Federated Identity Management to OpenStack
向 OpenStack 添加联合身份管理
  • DOI:
    10.1007/s10723-013-9283-2
  • 发表时间:
    2013
  • 期刊:
  • 影响因子:
    5.5
  • 作者:
    Chadwick D
  • 通讯作者:
    Chadwick D
{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

David Chadwick其他文献

New variant Creutzfeldt–Jakob disease presenting as localization-related epilepsy
新变异型克雅氏病表现为定位相关性癫痫
  • DOI:
    10.1212/wnl.54.11.2188
  • 发表时间:
    2000
  • 期刊:
  • 影响因子:
    9.9
  • 作者:
    M. Silverdale;John Paul Leach;David Chadwick
  • 通讯作者:
    David Chadwick
Parathyroidecomy in a district general hospital: outcomes and evolution in the era of minimally invasive surgery
  • DOI:
    10.1016/j.ijsu.2012.06.166
  • 发表时间:
    2012-01-01
  • 期刊:
  • 影响因子:
  • 作者:
    Sharath Paravastu;David Chadwick
  • 通讯作者:
    David Chadwick
Syphilis and HIV co-infection in Ghana
  • DOI:
    10.1016/j.jinf.2010.09.015
  • 发表时间:
    2010-12-01
  • 期刊:
  • 影响因子:
  • 作者:
    Yaasir Mamoojee;Grace Tan;Stephen Sarfo;Richard Phillips;David Chadwick
  • 通讯作者:
    David Chadwick
Use of combined radioisotope and patent blue v dye versus radioisotope alone in sentinel node biopsy for breast cancer axillary staging
  • DOI:
    10.1016/j.ijsu.2015.04.006
  • 发表时间:
    2015-06-01
  • 期刊:
  • 影响因子:
  • 作者:
    Sarah Butcher;Stephen Holt;David Chadwick
  • 通讯作者:
    David Chadwick
Drug Withdrawal and Epilepsy
  • DOI:
    10.2165/00003495-198835050-00005
  • 发表时间:
    1988-05-01
  • 期刊:
  • 影响因子:
    14.400
  • 作者:
    David Chadwick
  • 通讯作者:
    David Chadwick

David Chadwick的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('David Chadwick', 18)}}的其他基金

Sustainable futures for the Costa Rica dairy sector: optimising environmental and economic outcomes
哥斯达黎加乳制品行业的可持续未来:优化环境和经济成果
  • 批准号:
    BB/P023150/1
  • 财政年份:
    2017
  • 资助金额:
    $ 16.17万
  • 项目类别:
    Research Grant
Grazing behaviour, urine composition and soil properties are key drivers of nitrous oxide emissions from livestock urine in the uplands (Uplands-N2O)
放牧行为、尿液成分和土壤特性是高地牲畜尿液一氧化二氮排放的关键驱动因素(Uplands-N2O)
  • 批准号:
    NE/M015351/1
  • 财政年份:
    2015
  • 资助金额:
    $ 16.17万
  • 项目类别:
    Research Grant
Catalytic Routes to Intermediates for Sustainable Processes
可持续工艺中间体的催化途径
  • 批准号:
    EP/K014749/1
  • 财政年份:
    2013
  • 资助金额:
    $ 16.17万
  • 项目类别:
    Research Grant
Novel Catalytic Membrane Micro-reactors for CO2 Capture via Pre-combustion Decarbonisation Route
通过预燃烧脱碳路线捕获二氧化碳的新型催化膜微反应器
  • 批准号:
    EP/I010947/1
  • 财政年份:
    2011
  • 资助金额:
    $ 16.17万
  • 项目类别:
    Research Grant
My Private Cloud
我的私有云
  • 批准号:
    EP/I034181/1
  • 财政年份:
    2011
  • 资助金额:
    $ 16.17万
  • 项目类别:
    Research Grant
DESIGNING GOLD CATALYSTS FOR THE UTILISATION OF BIO-RENEWABLE FEEDSTOCKS
设计用于生物可再生原料利用的金催化剂
  • 批准号:
    EP/E009999/1
  • 财政年份:
    2007
  • 资助金额:
    $ 16.17万
  • 项目类别:
    Research Grant
Easy Expression of Authorisation Policies
授权策略轻松表达
  • 批准号:
    EP/D052181/1
  • 财政年份:
    2006
  • 资助金额:
    $ 16.17万
  • 项目类别:
    Research Grant

相似国自然基金

The Heterogenous Impact of Monetary Policy on Firms' Risk and Fundamentals
  • 批准号:
  • 批准年份:
    2024
  • 资助金额:
    万元
  • 项目类别:
    外国学者研究基金项目
Financial Constraints in China and Their Policy Implications
  • 批准号:
  • 批准年份:
    2024
  • 资助金额:
    万元
  • 项目类别:
    外国优秀青年学 者研究基金项目

相似海外基金

Strengthening Evidence-Based Policy Practice for Sustainable Food Systems under the EU-AU Partnership
在欧盟-非盟伙伴关系下加强可持续粮食系统的循证政策实践
  • 批准号:
    10101252
  • 财政年份:
    2024
  • 资助金额:
    $ 16.17万
  • 项目类别:
    EU-Funded
Transforming Autism Research and Policy at the National Level: A Program for Evidence-Based Solutions and Inclusive Research
国家层面自闭症研究和政策的转变:循证解决方案和包容性研究计划
  • 批准号:
    487457
  • 财政年份:
    2023
  • 资助金额:
    $ 16.17万
  • 项目类别:
    Salary Programs
BEIS Nature based Anaerobic Digester Solutions UKRI Policy Fellowship
BEIS 基于自然的厌氧消化器解决方案 UKRI 政策奖学金
  • 批准号:
    ES/Y004981/1
  • 财政年份:
    2023
  • 资助金额:
    $ 16.17万
  • 项目类别:
    Fellowship
Informing alcohol policy: The impact of evidence-based alcohol warnings on consumption
告知酒精政策:基于证据的酒精警告对消费的影响
  • 批准号:
    10565120
  • 财政年份:
    2023
  • 资助金额:
    $ 16.17万
  • 项目类别:
Introduction and Review of Risk Management Policy Based on Comparative Study of Political and Administrative Systems
基于政治与行政制度比较研究的风险管理政策介绍与审视
  • 批准号:
    23K12420
  • 财政年份:
    2023
  • 资助金额:
    $ 16.17万
  • 项目类别:
    Grant-in-Aid for Early-Career Scientists
Attack-resistant security infrastructure with security policy based on CPS model
基于CPS模型的安全策略的抗攻击安全基础设施
  • 批准号:
    23K16872
  • 财政年份:
    2023
  • 资助金额:
    $ 16.17万
  • 项目类别:
    Grant-in-Aid for Early-Career Scientists
Proposal for a regional hospital reorganisation policy using patients' records of transportation for emergency - based on operational records of medical helicopters
利用患者紧急运输记录的区域医院重组政策提案——基于医疗直升机的运行记录
  • 批准号:
    23H03133
  • 财政年份:
    2023
  • 资助金额:
    $ 16.17万
  • 项目类别:
    Grant-in-Aid for Scientific Research (B)
Securing Web-based Services by Policy Coherence and Proof-checking
通过策略一致性和验证检查来保护基于 Web 的服务
  • 批准号:
    DP230102828
  • 财政年份:
    2023
  • 资助金额:
    $ 16.17万
  • 项目类别:
    Discovery Projects
Developing a policy tool to promote residents' malaria control: an experimental intervention based on Medical Science and Economics knowledge
开发促进居民疟疾控制的政策工具:基于医学和经济学知识的实验干预
  • 批准号:
    23KK0024
  • 财政年份:
    2023
  • 资助金额:
    $ 16.17万
  • 项目类别:
    Fund for the Promotion of Joint International Research (International Collaborative Research)
NetworkNature+ - Scaling up nature-based solutions to achieve 2030 policy goals
NetworkNature - 扩大基于自然的解决方案以实现 2030 年政策目标
  • 批准号:
    10064784
  • 财政年份:
    2023
  • 资助金额:
    $ 16.17万
  • 项目类别:
    EU-Funded
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了