DocumentCode :
3436247
Title :
Access Control and Security Properties Requirements Specification for Clouds´ SecLAs
Author :
Guesmi, Aoues ; Clemente, P.
Author_Institution :
LIFO, Univ. Orleans, Orleans, France
Volume :
1
fYear :
2013
fDate :
2-5 Dec. 2013
Firstpage :
723
Lastpage :
729
Abstract :
Current Cloud Service Level Agreements (SLAs) do not cover security requirements. Some consortiums have proposed standards for the evaluation of security offered by the Cloud Providers (CP). Cloud Brokers (CB) can then generate Security Level Agreement (SecLA) contracts between customers and providers to fit users´ requirements. However, the SecLAs do not provide enough details for complex customers´ situations, such as sharing resources with other users/companies, or set up specific Access Controls and Security Properties (ACSP). In this paper, we tackle this issue, by introducing a general Requirement Specification Language (ACSP-RSL) to allow the customers to express their needs in term of ACSP. The underlying formal model, on which is based RSL, is partially presented. The global SecLA definition and negotiation process is thus extended with our proposal. RSL indeed also allows to express Security Requirements currently existing in SecLAs. The negotiation phase between CB and the CPs is discussed. We show how the RSL specifications expressed by the customer can be projected into a generic detection/protection policy expressed as an extension of RSL. A complete use-case for a healthcare system with multitenancy for users and services deployed is given. Its security requirements are analyzed, modeled, expressed and discussed.
Keywords :
Web services; authorisation; cloud computing; contracts; formal specification; specification languages; ACSP-RSL; Cloud SecLA; RSL specifications; access control and security property requirement specification; cloud brokers; cloud providers; cloud service level agreements; complex customer situations; formal model; generic detection-protection policy; global SecLA definition and negotiation process; healthcare system; requirement specification language; resource sharing; security level agreement contracts; user requirements; Access control; Cloud computing; Computational modeling; Context; Medical services; Standards; Access Control; Cloud Broker; Cloud Computing; Security Level Agreement; Security Properties; Security Requirements;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Cloud Computing Technology and Science (CloudCom), 2013 IEEE 5th International Conference on
Conference_Location :
Bristol
Type :
conf
DOI :
10.1109/CloudCom.2013.133
Filename :
6753867
Link To Document :
بازگشت