Computer Engineering & Science
Previous Articles Next Articles
CAI Ting1,NIE Qing-bin1,OUYANG Kai2,ZHOU Jing-li2
Received:
Revised:
Online:
Published:
Abstract:
We propose an enhanced role-based access control (ERBAC) model to solve the shortcomings of the RBAC’s resource usage constraints, policy management and interoperability security in multi-domain cloud systems. Firstly, we introduce elements of containers and two role cardinality constraints into the RBAC, and establish the containers + dynamic role cardinality constraints based resource usage policy. Secondly, we study the role inheritance management for multi-domains in depth and present an inter-domain policy management function, whose objective is to check for the number of violations before committing an inter-domain role inheritance relation. Then, various security detection algorithms for policy conflict are given. Analysis results show that the ERBAC model can improve the security of inter-domain interoperation, enforce usage constraints upon resources and manage the security policies in an easy and effective way, which proves to be feasible and applicable for multi-domain cloud systems.
Key words: ERBAC, multi-domain cloud, secure inter-operation, resource usage, policy management
CAI Ting1,NIE Qing-bin1,OUYANG Kai2,ZHOU Jing-li2.
0 / / Recommend
Add to citation manager EndNote|Ris|BibTeX
URL: http://joces.nudt.edu.cn/EN/
http://joces.nudt.edu.cn/EN/Y2017/V39/I04/689