DocumentCode
1879597
Title
Access control infrastructure for on-demand provisioned virtualised infrastructure services
Author
Demchenko, Yuri ; Ngo, Canh ; De Laat, Cees
Author_Institution
Univ. of Amsterdam, Amsterdam, Netherlands
fYear
2011
fDate
23-27 May 2011
Firstpage
466
Lastpage
475
Abstract
Cloud technologies are emerging as a new way of provisioning virtualised computing and infrastructure services on-demand for collaborative projects and groups. Security in provisioning virtual infrastructure services should address two general aspects: supporting secure operation of the provisioning infrastructure, and provisioning a dynamic access control infrastructure as part of the provisioned on-demand virtual infrastructure. The paper refers to the architectural framework for on-demand infrastructure services provisioning and defines the general security requirements to the security infrastructure. Dynamically provisioned access control infrastructure (DACI) reveals a wide spectrum of problems related to the distributed access control, policy and related security context management. Consistent security services design, deployment and operation require continuous security context management during the whole security services lifecycle, which is aligned to the main provisioned services lifecycle. The paper discusses conceptual issues, basic requirements and practical suggestions for provisioning dynamically configured access control services. The paper discusses security mechanisms that are required for consistent DACI operation, in particular use of authorisation tokens for access control and authorisation session context exchange between infrastructure services and providers. The proposed security infrastructure implementation is based on the GAAA-Toolkit that provides rich security session context management functionality with authorisation tickets and tokens. The defined Common Security Services Interface (CSSI) allows uniform call to security services both in the provisioning and virtual infrastructures.
Keywords
authorisation; cloud computing; authorisation token; cloud technology; common security services interface; distributed access control; dynamically provisioned access control infrastructure; infrastructure service; on-demand virtual infrastructure; security context management; virtualised computing; Authorization; Computational modeling; Computer architecture; Context; Synchronization; Dynamic Access Control Infrastructure; On-Demand Infrastructure Services Provisioning; Security Context Management; Security Service Life-cycle Management;
fLanguage
English
Publisher
ieee
Conference_Titel
Collaboration Technologies and Systems (CTS), 2011 International Conference on
Conference_Location
Philadelphia, PA
Print_ISBN
978-1-61284-638-5
Type
conf
DOI
10.1109/CTS.2011.5928725
Filename
5928725
Link To Document