课题基金 / 基金详情

My Private Cloud

My Private Cloud
我的私有云
批准号:
EP/I034181/1
负责人:
David Chadwick
金额:
$7.37万
依托单位:
依托单位国家:
英国
项目类别:
Research Grant
财政年份:
2011
资助国家:
英国
项目状态:
已结题
起止时间:
2011 至 --
关键词:

项目摘要

项目成果

David Chadwick的其他基金

相似基金

相关文献

中文摘要
翻译
这项研究旨在增加-a)用户可能对云提供商的信任,以及-b)当数据存储在云中时,用户将对其数据进行控制。它的目标是通过多种方式做到这一点。首先,现有的云用户可以将他们对现有云服务提供商的反馈提供给云信誉服务。这将计算各种云提供商的声誉,以便新的潜在云用户可以查询它,以确定哪些云提供商最有信誉。然后,当用户选择了他认为值得信赖的云提供商(S)时,用户可以对他们提交到云中的数据设置自己的细粒度隐私策略。这一政策将坚持他们的数据,以便它始终由云基础设施执行。通过这种方式,用户可以完全控制对其(可能非常敏感的)数据的所有访问和处理。如果他们的数据在云提供商之间移动,那么粘性策略将与数据一起移动,从而确保他们的策略继续进行控制。隐私保护基础设施内置了审计支持,允许云提供商向用户发送摘要审计信息,这些信息将详细说明谁在什么时间、出于什么目的访问了用户的数据。这为用户提供了对云的可见性,并向他们保证他们的数据是安全的。如果用户认为隐私政策太严或太松,他们可以随时改变他们的隐私政策。最后,用户将能够将对其数据的访问委托给其他用户或进程,以便提供工作流和其他数据访问场景中有时需要的灵活性。基础设施支持的细粒度隐私策略和协议允许请求者从多个颁发机构收集他们的各种属性和角色(称为属性聚合的过程),即使他们被不同机构的不同身份所知道。这反映了当今塑料卡凭证的现实,并允许创建新一代虚拟卡。云提供商得到加密保证,所有这些不同的属性和角色确实属于同一个请求者,而不要求请求者透露他的真实姓名。细粒度策略还支持紧急覆盖,即所谓的破玻璃策略。这允许最初被拒绝访问云中数据的负责任的请求者打破玻璃,并被授予紧急访问权限,因为他们完全知道他们将被追究责任,并在以后不得不向他们的部门管理层负责。这是通过拥有义务服务来实现的,该服务可以在做出授权决策时执行预定义的操作。在打碎玻璃的情况下,这些义务可能是向请求者的部门经理发送电子邮件,并在安全的审计跟踪中记录事件。打破玻璃使用的一个例子是在医疗应用中,例如它允许急救人员访问患者的医疗记录,否则他们不会被允许查看这些记录。
英文摘要
This research is designed to increase - a) the trust that users may have in cloud providers, as well as - b) the control that users will have over their data when it is stored in the cloud. It aims to do this in a number of ways. Firstly existing cloud users can provide their feedback about their existing cloud service providers to a cloud reputation service. This will compute the reputations of the various cloud providers, so that new potential cloud users can query it in order to determine which cloud providers are the most reputable. Then, when a user has chosen a cloud provider that (s)he believes to be trustworthy, the user can set their own fine grained privacy policy on the data that they submit to the cloud. This policy will be stuck to their data so that it is always enforced by the cloud infrastructure. In this way the user has full control over all accesses to and processing of their (possibly very sensitive) data. If their data is moved between cloud providers, then the sticky policy will move with the data, thereby ensuring continuing control by their policy. The privacy protecting infrastructure has built in audit support to allow the cloud provider to send the user summary audit information which will detail who has accessed the user's data, at what time and for what purposes. This provides users with visibility into the cloud, and reassures them that their data is safe. Users may alter their privacy policy at any time, should they decide it is too strict or too lax. Finally, users will be able to delegate access to their data to other users or processes, in order to provide the flexibility that is sometimes needed in workflows and other data access scenarios.The fine grained privacy policies and protocols that are supported by the infrastructure allow requestors to collect their various attributes and roles from multiple issuing authorities (a process termed attribute aggregation), even when they are known by different identities at the different authorities. This mirrors the reality of today's plastic card credentials and allows a new generation of virtual cards to be created. The cloud provider is cryptographically assured that all these different attributes and roles do indeed belong to the same requestor, without the requestor being required to reveal his real name.The fine grained policies also support emergency over-rides, so called Break-The-Glass policies. These allow responsible requestors, who are initially denied access to the data in the cloud, to break the glass and be granted emergency access, in the full knowledge that they will be held accountable and have to answer to their line management at a later time. This is achieved by having an obligation service that can perform pre-defined actions when an authorization decision is made. In the case of break the glass, these obligations might be to email the requestor's line manager, and record the incident in a secure audit trail. One example of Break the glass use is in medical applications, e.g. it allows accident and emergency staff to access a patient's medical records that they otherwise would not be allowed to see.
期刊论文(4)
专著(0)
科研奖励(0)
会议论文
My private cloud - granting federated access to cloud resources
我的私有云 - 授予对云资源的联合访问
DOI: 10.1186/2192-113x-2-3
发表时间: 2013
期刊: Advances, Systems and Applications
影响因子: --
作者: [Chadwick D]
通讯作者: Chadwick D
DOI: --
发表时间:
期刊:
影响因子: --
作者: [David Chadwick (Co-Author)]
通讯作者: David Chadwick (Co-Author)
Sustainable futures for the Costa Rica dairy sector: optimising environmental and economic outcomes
  • 批准号:
    BB/P023150/1
  • 项目类别:
    Research Grant
  • 资助金额:
    $56.07万
  • 财政年份:
    2017
  • 负责人:
    David Chadwick
  • 依托单位:
Grazing behaviour, urine composition and soil properties are key drivers of nitrous oxide emissions from livestock urine in the uplands (Uplands-N2O)
  • 批准号:
    NE/M015351/1
  • 项目类别:
    Research Grant
  • 资助金额:
    $80.28万
  • 财政年份:
    2015
  • 负责人:
    David Chadwick
  • 依托单位:
Catalytic Routes to Intermediates for Sustainable Processes
  • 批准号:
    EP/K014749/1
  • 项目类别:
    Research Grant
  • 资助金额:
    $306.08万
  • 财政年份:
    2013
  • 负责人:
    David Chadwick
  • 依托单位:
Sticky Policy Based Open Source Security APIs for the Cloud
  • 批准号:
    EP/J020354/1
  • 项目类别:
    Research Grant
  • 资助金额:
    $16.17万
  • 财政年份:
    2012
  • 负责人:
    David Chadwick
  • 依托单位:
海外基金