Resource management and authorization for cloud services

Alexander Lawall, D. Reichelt, Thomas W. Schaller
{"title":"Resource management and authorization for cloud services","authors":"Alexander Lawall, D. Reichelt, Thomas W. Schaller","doi":"10.1145/2723839.2723864","DOIUrl":null,"url":null,"abstract":"In the age of cloud computing, companies still have the problem to manage access rights for resources. This is especially true, if companies are combined to virtual organizations and want to share resources that are located at cloud providers. For a consistent authorization model, an up to date knowledge about partner organizations is indispensable. This contribution proposes an approach to request the automatic deployment of resources from a cloud provider. The access rights to the resources are managed and administered by the proprietary company, even if partner organizations are involved. They are not published to the cloud provider, but remain in the owning company. This establishes a separation of resources (i.a. systems) and authorization, which alleviates security risks. Attackers of resources can not access them because the authorization model is not implemented on the same location as the resources. This makes the intrusion much more complex.","PeriodicalId":311009,"journal":{"name":"Proceedings of the 7th International Conference on Subject-Oriented Business Process Management","volume":"7 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2015-04-23","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"18","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the 7th International Conference on Subject-Oriented Business Process Management","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/2723839.2723864","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 18

Abstract

In the age of cloud computing, companies still have the problem to manage access rights for resources. This is especially true, if companies are combined to virtual organizations and want to share resources that are located at cloud providers. For a consistent authorization model, an up to date knowledge about partner organizations is indispensable. This contribution proposes an approach to request the automatic deployment of resources from a cloud provider. The access rights to the resources are managed and administered by the proprietary company, even if partner organizations are involved. They are not published to the cloud provider, but remain in the owning company. This establishes a separation of resources (i.a. systems) and authorization, which alleviates security risks. Attackers of resources can not access them because the authorization model is not implemented on the same location as the resources. This makes the intrusion much more complex.
云服务的资源管理和授权
在云计算时代,企业仍然存在管理资源访问权限的问题。如果公司合并为虚拟组织,并希望共享位于云提供商处的资源,则尤其如此。对于一致的授权模型,有关合作伙伴组织的最新知识是必不可少的。该贡献提出了一种从云提供商请求自动部署资源的方法。对资源的访问权由专有公司管理和管理,即使涉及到合作伙伴组织。它们不会发布给云提供商,而是保留在自己的公司中。这建立了资源(即系统)和授权的分离,从而减轻了安全风险。资源的攻击者无法访问它们,因为授权模型不是在与资源相同的位置上实现的。这使得入侵更加复杂。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信