Access control in a distributed micro-cloud environment

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Ranković, Tamara, Simić, Miloš, Stojkov, Milan, Sladić, Goran
Natura: Preprint
Pubblicazione: 2024
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866913564908847104
author Ranković, Tamara
Simić, Miloš
Stojkov, Milan
Sladić, Goran
author_facet Ranković, Tamara
Simić, Miloš
Stojkov, Milan
Sladić, Goran
contents Proliferation of systems that generate enormous amounts of data and operate in real time has led researchers to rethink the current organization of the cloud. Many proposed solutions consist of a number of small data centers in the vicinity of data sources. That creates a highly complex environment, where strict access control is essential. Recommended access control models frequently belong to the Attribute-Based Access Control (ABAC) family. Flexibility and dynamic nature of these models come at the cost of high policy management complexity. In this paper, we explore whether the administrative overhead can be lowered with resource hierarchies. We propose an ABAC model that incorporates user and object hierarchies. We develop a policy engine that supports the model and present a distributed cloud use case. Findings in this paper suggest that resource hierarchies simplify the administration of ABAC models, which is a necessary step towards their further inclusion in real-world systems.
format Preprint
id arxiv_https___arxiv_org_abs_2410_20278
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Access control in a distributed micro-cloud environment
Ranković, Tamara
Simić, Miloš
Stojkov, Milan
Sladić, Goran
Cryptography and Security
Proliferation of systems that generate enormous amounts of data and operate in real time has led researchers to rethink the current organization of the cloud. Many proposed solutions consist of a number of small data centers in the vicinity of data sources. That creates a highly complex environment, where strict access control is essential. Recommended access control models frequently belong to the Attribute-Based Access Control (ABAC) family. Flexibility and dynamic nature of these models come at the cost of high policy management complexity. In this paper, we explore whether the administrative overhead can be lowered with resource hierarchies. We propose an ABAC model that incorporates user and object hierarchies. We develop a policy engine that supports the model and present a distributed cloud use case. Findings in this paper suggest that resource hierarchies simplify the administration of ABAC models, which is a necessary step towards their further inclusion in real-world systems.
title Access control in a distributed micro-cloud environment
topic Cryptography and Security
url https://arxiv.org/abs/2410.20278