• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

Computer Engineering & Science

Previous Articles     Next Articles

An enhanced role-based access control model
for multi-domains in cloud systems

CAI Ting1,NIE Qing-bin1,OUYANG Kai2,ZHOU Jing-li2   

  1. (1.Department of Computer,College of Mobile Telecommunications,
    Chongqing University of Posts and Telecommunications,Chongqing 401520;
    2.College of Computer,Huazhong University of Science and Technology,Wuhan 430074,China)
  • Received:2015-12-14 Revised:2016-05-10 Online:2017-04-25 Published:2017-04-25

Abstract:

We propose an enhanced role-based access control (ERBAC) model to solve the shortcomings of the RBAC’s resource usage constraints, policy management and interoperability security in multi-domain cloud systems. Firstly, we introduce elements of containers and two role cardinality constraints into the RBAC, and establish the containers + dynamic role cardinality constraints based resource usage policy. Secondly, we study the role inheritance management for multi-domains in depth and present an inter-domain policy management function, whose objective is to check for the number of violations before committing an inter-domain role inheritance relation. Then, various security detection algorithms for policy conflict are given. Analysis results show that the ERBAC model can improve the security of inter-domain interoperation, enforce usage constraints upon resources and manage the security policies in an easy and effective way, which proves to be feasible and applicable for multi-domain cloud systems.

Key words: ERBAC, multi-domain cloud, secure inter-operation, resource usage, policy management