• DocumentCode
    545565
  • Title

    Information flow control in cloud computing

  • Author

    Wu, Ruoyu ; Gail-Joon Ahn ; Hongxin Hu ; Singhal, Mukesh

  • Author_Institution
    Lab. of Security Eng. for Future Comput. (SEFCOM), Arizona State Univ., Tempe, AZ, USA
  • fYear
    2010
  • fDate
    9-12 Oct. 2010
  • Firstpage
    1
  • Lastpage
    7
  • Abstract
    Cloud computing is an emerging computing paradigm where computing resources are provided as services over Internet while residing in a large data center. Even though it enables us to dynamically provide servers with the ability to address a wide range of needs, this paradigm brings forth many new challenges for the data security and access control as users outsource their sensitive data to clouds, which are beyond the same trusted domain as data owners. A fundamental problem is the existence of insecure information flows due to the fact that a service provider can access multiple virtual machines in clouds. Sensitive information may be leaked to unauthorized customers and such critical information flows could raise conflict-of-interest issues in cloud computing. In this paper, we propose an approach to enforce the information flow policies at Infrastructure-as-a-Service (IaaS) layer in a cloud computing environment. Especially, we adopt Chinese Wall policies to address the problems of insecure information flow. We implement a proof-of-concept prototype system based on Eucalyptus open source packages to show the feasibility of our approach. This system facilitates the cloud management modules to resolve the conflict-of-interest issues for service providers in clouds.
  • Keywords
    authorisation; cloud computing; Chinese wall policy; Eucalyptus open source package; IaaS layer; Internet; access control; cloud computing; cloud management module; computing resource; conflict-of-interest issue; data center; data owner; data security; information flow control; information flow policy; infrastructure-as-a-service; insecure information flow; sensitive data; sensitive information; service provider; trusted domain; unauthorized customer; virtual machine; Authentication; Cloud computing; Companies; Computational modeling; Contracts; Databases;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Collaborative Computing: Networking, Applications and Worksharing (CollaborateCom), 2010 6th International Conference on
  • Conference_Location
    Chicago, IL
  • Print_ISBN
    978-963-9995-24-6
  • Type

    conf

  • Filename
    5767047