Sticky Policy Based Open Source Security APIs for the Cloud
Sticky Policy Based Open Source Security APIs for the Cloud
批准号:
EP/J020354/1
负责人:
David Chadwick
金额:
$16.17万
依托单位:
依托单位国家:
英国
项目类别:
Research Grant
财政年份:
2012
资助国家:
英国
项目状态:
已结题
起止时间:
2012 至 --
中文摘要
互联网和电话之所以成功,是因为它们使用了开放的协议和开放的接口,允许用户随意交流、创新和共享。我们建议通过开发一组开放的安全服务、协议和接口(api)来促进云计算中的这一过程,这些服务、协议和接口将允许云资源所有者能够指定对其云资源进行细粒度访问控制的策略,并且无论后续位置或随后的数据处理如何,都可以随时随地执行这些策略。随时随地与任何人安全地共享数据的能力将促进自发协作,并确保协作工作的信心。这将通过使用“粘性策略”、授权、联合访问和基于属性的访问控制来实现。粘接策略是加密链接或“粘接”到它们控制的数据和元数据的策略,因此只有在策略被遵守时才授予对数据的访问权限。为了满足互联网规模的云使用,需要联邦访问和基于属性的访问控制。联邦访问允许用户使用现有凭据向云服务表明自己的身份,而无需首先从云服务本身获取新的凭据。基于属性的访问控制允许根据用户的标识属性(而不是当前通常使用的标识符)指定访问。为了在识别用户和数据资源方面达到互联网规模,需要一个本体来对数据和希望访问它的用户进行分类。颁发身份属性的机构也需要进行分类。任何特定数据集的特征将保存在描述或标识数据的元数据中,并符合本体。元数据本身将以与粘接策略类似的方式粘接在数据上。当数据与其他数据合并或融合,或被分割、过滤或缩减时,其元数据将需要相应更改,以描述新数据。类似地,控制对新数据访问的保持策略将需要从原始保持策略派生出来。本项目将以本体和元数据为指导,开发一种新的代数和算法,用于从旧的粘性策略中派生出新的粘性策略。(请注意,这个项目不会执行实际的数据合并或拆分,而只是假设有可靠的服务可用于执行此操作。)这个项目中指定的协议和api将通过一个已经精通云api的组织进行标准化,比如开放网格论坛或OASIS。为了确保最广泛地使用本项目中指定的服务和api,将在Python中开发试点实现,并作为OpenStack软件套件的一部分分发。OpenStack是一个社区项目,涉及超过135个组织,从惠普、思科和英特尔等跨国公司到Cloudscaling等专业中小企业。该项目建议通过发挥领导作用来利用OpenStack社区的能量,以促进其他人为开发工作做出贡献。
英文摘要
The Internet and telephone are successful because they use open protocols and open interfaces, allowing users to communicate, innovate and share at will. We propose to facilitate this process in cloud computing, by developing a set of open security services, protocols and interfaces (APIs) that will allow cloud resource owners to be able to specify their policies for fine grained access control to their cloud resources, and have these enforced everywhere at all times, regardless of the subsequent location or data processing that has ensued. The ability to securely share data with anyone, anywhere, at any time, will facilitate spontaneous collaborations and ensure confidence in collaborative working. This will be achieved by using "sticky policies", delegation of authority, federated access and attribute based access controls. Sticky policies are policies which are cryptographically linked or "stuck" to the data and meta-data they control, so that access to the data is only granted if the policy is honoured. In order to cater for Internet scale cloud usage, federated access and attribute based access controls are needed. Federated access allows users to identify themselves to a cloud service using their existing credentials, without having to first obtain new ones from the cloud service itself. Attribute based access controls allows access to be specified based on a user's identity attributes rather than simply an identifier, which is typically used today. In order to achieve Internet scale in identifying users and data resources, an ontology is needed that will classify both the data and the users who wish to access it. The authorities who issue identity attributes will also need to be classified. The characteristics of any particular set of data will be held in meta-data that describes or identifies the data, and conforms to the ontology. The meta-data itself will be stuck to the data in a similar way to the sticky policy.When data is merged or fused with other data, or is split, filtered or reduced, then its meta-data will need to change accordingly, in order to describe the new data. Similarly the sticky policy that controls access to the new data will need to be derived from the original sticky policy(ies). This project will develop a new algebra and algorithms for deriving the new sticky policy from the old, using the ontology and meta-data as a guide. (Note that this project will not be performing the actual data merging or splitting, but simply assumes that trustworthy services are available to do this.)The protocols and APIs specified in this project will be standardised through an organisation already well versed in cloud APIs, such as the Open Grid Forum or OASIS.In order to ensure the widest take up of the services and APIs specified in this project, pilot implementations will be developed in Python and distributed as part of the OpenStack suite of software. OpenStack is a community project involving over 135 organisations, ranging from multi-nationals such as HP, Cisco and Intel, to specialist SMEs such as Cloudscaling. This project proposes to harness the energies of the OpenStack community by acting in a leading role to facilitate others in contributing to the development effort.
期刊论文(1)
专著(0)
科研奖励(0)
会议论文
Adding Federated Identity Management to OpenStack
向 OpenStack 添加联合身份管理
DOI:
10.1007/s10723-013-9283-2
发表时间:
2013
期刊:
Journal of Grid Computing
影响因子:
5.5
作者:
[Chadwick D]
通讯作者:
Chadwick D
Sustainable futures for the Costa Rica dairy sector: optimising environmental and economic outcomes
-
批准号:BB/P023150/1
-
项目类别:Research Grant
-
资助金额:$56.07万
-
财政年份:2017
-
负责人:David Chadwick
-
依托单位:
Grazing behaviour, urine composition and soil properties are key drivers of nitrous oxide emissions from livestock urine in the uplands (Uplands-N2O)
-
批准号:NE/M015351/1
-
项目类别:Research Grant
-
资助金额:$80.28万
-
财政年份:2015
-
负责人:David Chadwick
-
依托单位:
Catalytic Routes to Intermediates for Sustainable Processes
-
批准号:EP/K014749/1
-
项目类别:Research Grant
-
资助金额:$306.08万
-
财政年份:2013
-
负责人:David Chadwick
-
依托单位:
Novel Catalytic Membrane Micro-reactors for CO2 Capture via Pre-combustion Decarbonisation Route
-
批准号:EP/I010947/1
-
项目类别:Research Grant
-
资助金额:$58.44万
-
财政年份:2011
-
负责人:David Chadwick
-
依托单位:
My Private Cloud
-
批准号:EP/I034181/1
-
项目类别:Research Grant
-
资助金额:$7.37万
-
财政年份:2011
-
负责人:David Chadwick
-
依托单位:
DESIGNING GOLD CATALYSTS FOR THE UTILISATION OF BIO-RENEWABLE FEEDSTOCKS
-
批准号:EP/E009999/1
-
项目类别:Research Grant
-
资助金额:$14.78万
-
财政年份:2007
-
负责人:David Chadwick
-
依托单位:
Easy Expression of Authorisation Policies
-
批准号:EP/D052181/1
-
项目类别:Research Grant
-
资助金额:$13.94万
-
财政年份:2006
-
负责人:David Chadwick
-
依托单位:
国内基金
海外基金
The Heterogenous Impact of Monetary Policy on Firms' Risk and Fundamentals
-
批准号:--
-
项目类别:外国学者研究基金项目
-
资助金额:--
-
批准年份:2024
-
负责人:潘军
-
依托单位:
Financial Constraints in China
and Their Policy Implications
-
批准号:--
-
项目类别:外国优秀青年学 者研究基金项目
-
资助金额:--
-
批准年份:2024
-
负责人:Jake Zhao
-
依托单位: