Multi-Tenant Access and Information Flow Control for SaaS

被引:5
|
作者
Solanki, Nidhiben [1 ]
Zhu, Wei [1 ]
Yen, I-Ling [1 ]
Bastani, Farokh [1 ]
Rezvani, Elham [2 ]
机构
[1] Univ Texas Dallas, Richardson, TX 75083 USA
[2] Microsoft Corp, Redmond, WA 98052 USA
关键词
SaaS; access control; information flow control; RBAC; role hierarchy and resource hierarchy based access control; data dependency; data dependency based information flow control;
D O I
10.1109/ICWS.2016.21
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Due to multi-tenancy, access control is a very important component in SaaS (Software as a Service), especially for controlling cross-tenant accesses. Due to the potential information flow among multiple tenants, information flow control should also be carefully addressed. Existing models for SaaS access control have some limitations, especially in information flow control. In this paper, we define a new SaaS-AIFC model to provide comprehensive and improved access and information flow control in SaaS. SaaS-AIFC incorporates two advanced features. First, SaaS-AIFC integrates the advanced role mapping technique to govern the cross-tenant accesses. Role mapping is very flexible and can be very efficient for SaaS with a large number of tenants. We integrate role mapping in SaaS by developing a detailed process for mapping establishment and retrieval during validation. Second, we propose a new IFC model in SaaS-AIFC, which tracks the dependency of data objects and uses the dependency information to achieve flexible information flow control. An architecture design for realizing the SaaS-AIFC model is also proposed.
引用
收藏
页码:99 / 106
页数:8
相关论文
共 50 条
  • [31] Thread-level resource consumption control of tenant custom code in a shared JVM for multi-tenant SaaS
    Makki, Majid
    Van Landuyt, Dimitri
    Lagaisse, Bert
    Joosen, Wouter
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2021, 115 : 351 - 364
  • [32] Dynamic Provisioning of Service Composition in a Multi-Tenant SaaS Environment
    Sellami, Wael
    Kacem, Hatem
    Kacem, Ahmed
    JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2020, 28 (02) : 367 - 397
  • [33] Middleware for Dynamic Upgrade Activation and Compensations in Multi-tenant SaaS
    Van Landuyt, Dimitri
    Gey, Fatih
    Truyen, Eddy
    Joosen, Wouter
    SERVICE-ORIENTED COMPUTING, ICSOC 2017, 2017, 10601 : 340 - 348
  • [34] ITADP: An inter-tenant attack detection and prevention framework for multi-tenant SaaS
    Yassin, Mohamed
    Talhi, Chamseddine
    Boucheneb, Hanifa
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2019, 49
  • [35] Privacy-aware multi-tenant access control for cloud workflow
    Wen Y.
    Liu J.
    Dou W.
    Chen A.
    Zhou M.
    Jisuanji Jicheng Zhizao Xitong/Computer Integrated Manufacturing Systems, CIMS, 2019, 25 (04): : 894 - 900
  • [36] Using Intrusive Microservices to Enable Deep Customization of Multi-Tenant SaaS
    Chauvel, Franck
    Solberg, Arnor
    2018 11TH INTERNATIONAL CONFERENCE ON THE QUALITY OF INFORMATION AND COMMUNICATIONS TECHNOLOGY (QUATIC), 2018, : 30 - 37
  • [37] Multi-tenant SaaS application placement algorithm based on cost optimization
    Meng, F.-C. (mengfanchao74@163.com), 1600, CIMS (20):
  • [38] A dynamic resource balance algorithm for multi-tenant placement problem in SaaS
    Chen, Xianzhang
    Li, Xiaoping
    2013 INTERNATIONAL CONFERENCE ON SERVICE SCIENCES (ICSS 2013), 2013, : 123 - 128
  • [39] Event-Based Customization of Multi-tenant SaaS Using Microservices
    Nordli, Espen Tonnessen
    Nguyen, Phu H.
    Chauvel, Franck
    Song, Hui
    COORDINATION MODELS AND LANGUAGES, COORDINATION 2020, 2020, 12134 : 171 - 180
  • [40] Multi-tenant SaaS deployment optimisation algorithm for cloud computing environment
    Cao Ming
    Yu Bingjie
    Liu Xiantong
    INTERNATIONAL JOURNAL OF INTERNET PROTOCOL TECHNOLOGY, 2018, 11 (03) : 152 - 158