Multi-Tenant Access and Information Flow Control for SaaS

被引:5
|
作者
Solanki, Nidhiben [1 ]
Zhu, Wei [1 ]
Yen, I-Ling [1 ]
Bastani, Farokh [1 ]
Rezvani, Elham [2 ]
机构
[1] Univ Texas Dallas, Richardson, TX 75083 USA
[2] Microsoft Corp, Redmond, WA 98052 USA
关键词
SaaS; access control; information flow control; RBAC; role hierarchy and resource hierarchy based access control; data dependency; data dependency based information flow control;
D O I
10.1109/ICWS.2016.21
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Due to multi-tenancy, access control is a very important component in SaaS (Software as a Service), especially for controlling cross-tenant accesses. Due to the potential information flow among multiple tenants, information flow control should also be carefully addressed. Existing models for SaaS access control have some limitations, especially in information flow control. In this paper, we define a new SaaS-AIFC model to provide comprehensive and improved access and information flow control in SaaS. SaaS-AIFC incorporates two advanced features. First, SaaS-AIFC integrates the advanced role mapping technique to govern the cross-tenant accesses. Role mapping is very flexible and can be very efficient for SaaS with a large number of tenants. We integrate role mapping in SaaS by developing a detailed process for mapping establishment and retrieval during validation. Second, we propose a new IFC model in SaaS-AIFC, which tracks the dependency of data objects and uses the dependency information to achieve flexible information flow control. An architecture design for realizing the SaaS-AIFC model is also proposed.
引用
收藏
页码:99 / 106
页数:8
相关论文
共 50 条
  • [1] Amusa: middleware for efficient access control management of multi-tenant SaaS applications
    Decat, Maarten
    Bogaerts, Jasper
    Lagaisse, Bert
    Joosen, Wouter
    30TH ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING, VOLS I AND II, 2015, : 2141 - 2148
  • [2] Multi-tenant SaaS Cloud
    Kulkarni, Gurudatt
    Khatawkar, Prasad
    Shelke, Rupali
    Solanke, Vikas
    Waghmare, Rani
    AFRICON, 2013, 2013,
  • [3] Multi-tenant SaaS Cloud
    Kulkarni, Gurudatt
    Shelke, Rupali
    Palwe, Rajnikant
    Khatawkar, Prasad
    Bhuse, Sadanand
    Bankar, Hemant
    2013 FOURTH INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATIONS AND NETWORKING TECHNOLOGIES (ICCCNT), 2013,
  • [4] Analysis of Access Control Model for Data Security and Privacy on Multi-Tenant SaaS
    Duraisamy, Gunavathi
    Abd Ghani, Abdul Azim
    Zulzalil, Hazura
    Abdullah, Azizol
    ADVANCED SCIENCE LETTERS, 2018, 24 (03) : 1619 - 1622
  • [5] Multi-tenant Database Access Control
    Yaish, Haitham
    Goyal, Madhu
    2013 IEEE 16TH INTERNATIONAL CONFERENCE ON COMPUTATIONAL SCIENCE AND ENGINEERING (CSE 2013), 2013, : 870 - 877
  • [6] SaaS Multi-Tenant Application Customization
    Tsai, Wei-Tek
    Sun, Xin
    2013 IEEE SEVENTH INTERNATIONAL SYMPOSIUM ON SERVICE-ORIENTED SYSTEM ENGINEERING (SOSE 2013), 2013, : 1 - 12
  • [8] Multi-tenant data authentication model for SaaS
    Li, Lin
    Kong, Lanju
    Li, Qingzhong
    Yan, Zhongmin
    Li, Hui
    Open Cybernetics and Systemics Journal, 2014, 8 (01): : 322 - 329
  • [9] Multi-tenant data authentication model for SaaS
    Li, Qingzhong (lqz@sdu.edu.cn), 1600, Bentham Science Publishers B.V., P.O. Box 294, Bussum, 1400 AG, Netherlands (08):
  • [10] Modeling and Analysis of Availability in Multi-tenant SaaS
    Su, Wenbo
    Liu, Qu
    Lin, Chuang
    Shen, Sherman
    24TH INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS AND NETWORKS ICCCN 2015, 2015,