• DocumentCode
    244168
  • Title

    Federated Access Control in Heterogeneous Intercloud Environment: Basic Models and Architecture Patterns

  • Author

    Demchenko, Y. ; Canh Ngo ; de Laat, Cees ; Lee, Chi-Kwan

  • Author_Institution
    Syst. & Network Eng., Univ. of Amsterdam, Amsterdam, Netherlands
  • fYear
    2014
  • fDate
    11-14 March 2014
  • Firstpage
    439
  • Lastpage
    445
  • Abstract
    This paper presents on-going research to define the basic models and architecture patterns for federated access control in heterogeneous (multi-provider) multi-cloud and inter-cloud environment. The proposed research contributes to the further definition of Intercloud Federation Framework (ICFF) which is a part of the general Intercloud Architecture Framework (ICAF) proposed by authors in earlier works. ICFF attempts to address the interoperability and integration issues in provisioning on-demand multi-provider multi-domain heterogeneous cloud infrastructure services. The paper describes the major inter-cloud federation scenarios that in general involve two types of federations: customer-side federation that includes federation between cloud based services and customer campus or enterprise infrastructure, and provider-side federation that is created by a group of cloud providers to outsource or broker their resources when provisioning services to customers. The proposed federated access control model uses Federated Identity Management (FIDM) model that can be also supported by the trusted third party entities such as Cloud Service Broker (CSB) and/or trust broker to establish dynamic trust relations between entities without previously existing trust. The research analyses different federated identity management scenarios, defines the basic architecture patterns and the main components of the distributed federated multi-domain Authentication and Authorisation infrastructure.
  • Keywords
    authorisation; cloud computing; operating systems (computers); outsourcing; software architecture; trusted computing; CSB; FIDM model; ICAF; ICFF; architecture patterns; authorisation infrastructure; cloud based services; cloud service broker; customer campus; customer-side federation; distributed federated multidomain authentication; dynamic trust relations; enterprise infrastructure; federated access control model; federated identity management model; federated identity management scenarios; heterogeneous intercloud environment; heterogeneous multiprovider intercloud environment; heterogeneous multiprovider multicloud environment; integration issue; intercloud architecture framework; intercloud federation framework; intercloud federation scenarios; interoperability issue; on-demand multiprovider multidomain heterogeneous cloud infrastructure services; provider-side federation; resource brokering; resource outsourcing; trusted third party entities; Authorization; Cloud computing; Computer architecture; Dynamic scheduling; Organizations; Authorisation; Cloud Security infrastructure; Federated Identity Management; Federated Intercloud Access Control Infrastructure; Intercloud Architecture Framework; Intercloud Federations Framework;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Cloud Engineering (IC2E), 2014 IEEE International Conference on
  • Conference_Location
    Boston, MA
  • Type

    conf

  • DOI
    10.1109/IC2E.2014.84
  • Filename
    6903508