• DocumentCode
    3436247
  • Title

    Access Control and Security Properties Requirements Specification for Clouds´ SecLAs

  • Author

    Guesmi, Aoues ; Clemente, P.

  • Author_Institution
    LIFO, Univ. Orleans, Orleans, France
  • Volume
    1
  • fYear
    2013
  • fDate
    2-5 Dec. 2013
  • Firstpage
    723
  • Lastpage
    729
  • Abstract
    Current Cloud Service Level Agreements (SLAs) do not cover security requirements. Some consortiums have proposed standards for the evaluation of security offered by the Cloud Providers (CP). Cloud Brokers (CB) can then generate Security Level Agreement (SecLA) contracts between customers and providers to fit users´ requirements. However, the SecLAs do not provide enough details for complex customers´ situations, such as sharing resources with other users/companies, or set up specific Access Controls and Security Properties (ACSP). In this paper, we tackle this issue, by introducing a general Requirement Specification Language (ACSP-RSL) to allow the customers to express their needs in term of ACSP. The underlying formal model, on which is based RSL, is partially presented. The global SecLA definition and negotiation process is thus extended with our proposal. RSL indeed also allows to express Security Requirements currently existing in SecLAs. The negotiation phase between CB and the CPs is discussed. We show how the RSL specifications expressed by the customer can be projected into a generic detection/protection policy expressed as an extension of RSL. A complete use-case for a healthcare system with multitenancy for users and services deployed is given. Its security requirements are analyzed, modeled, expressed and discussed.
  • Keywords
    Web services; authorisation; cloud computing; contracts; formal specification; specification languages; ACSP-RSL; Cloud SecLA; RSL specifications; access control and security property requirement specification; cloud brokers; cloud providers; cloud service level agreements; complex customer situations; formal model; generic detection-protection policy; global SecLA definition and negotiation process; healthcare system; requirement specification language; resource sharing; security level agreement contracts; user requirements; Access control; Cloud computing; Computational modeling; Context; Medical services; Standards; Access Control; Cloud Broker; Cloud Computing; Security Level Agreement; Security Properties; Security Requirements;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Cloud Computing Technology and Science (CloudCom), 2013 IEEE 5th International Conference on
  • Conference_Location
    Bristol
  • Type

    conf

  • DOI
    10.1109/CloudCom.2013.133
  • Filename
    6753867