• DocumentCode
    632756
  • Title

    A multi-tenant RBAC model for collaborative cloud services

  • Author

    Bo Tang ; Qi Li ; Sandhu, Ravi

  • Author_Institution
    Inst. for Cyber Security, Univ. of Texas at San Antonio One UTSA Circle, San Antonio, TX, USA
  • fYear
    2013
  • fDate
    10-12 July 2013
  • Firstpage
    229
  • Lastpage
    238
  • Abstract
    Most cloud services are built with multi-tenancy which enables data and configuration segregation upon shared infrastructures. In this setting, a tenant temporarily uses a piece of virtually dedicated software, platform, or infrastructure. To fully benefit from the cloud, tenants are seeking to build controlled and secure collaboration with each other. In this paper, we propose a Multi-Tenant Role-Based Access Control (MT-RBAC) model family which aims to provide fine-grained authorization in collaborative cloud environments by building trust relations among tenants. With an established trust relation in MT-RBAC, the trustee can precisely authorize cross-tenant accesses to the truster´s resources consistent with constraints over the trust relation and other components designated by the truster. The users in the trustee may restrictively inherit permissions from the truster so that multi-tenant collaboration is securely enabled. Using SUN´s XACML library, we prototype MT-RBAC models on a novel Authorization as a Service (AaaS) platform with the Joyent commercial cloud system. The performance and scalability metrics are evaluated with respect to an open source cloud storage system. The results show that our prototype incurs only 0.016 second authorization delay for end users on average and is scalable in cloud environments.
  • Keywords
    authorisation; cloud computing; groupware; software metrics; storage management; AaaS; MT-RBAC models; SUN XACML library; authorization delay; authorization-as-a-service platform; collaborative cloud services; configuration segregation; data segregation; fine-grained authorization; multitenant RBAC model; multitenant role-based access control model; open source cloud storage system; performance metrics; scalability metrics; trust relations; Authorization; Cloud computing; Collaboration; Organizations; Prototypes; cloud computing; collaboration; fine-grained authorization; multi-tenancy; trust;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Privacy, Security and Trust (PST), 2013 Eleventh Annual International Conference on
  • Conference_Location
    Tarragona
  • Type

    conf

  • DOI
    10.1109/PST.2013.6596058
  • Filename
    6596058