Multi-Tenant Access and Information Flow Control for SaaS

被引:5
|
作者
Solanki, Nidhiben [1 ]
Zhu, Wei [1 ]
Yen, I-Ling [1 ]
Bastani, Farokh [1 ]
Rezvani, Elham [2 ]
机构
[1] Univ Texas Dallas, Richardson, TX 75083 USA
[2] Microsoft Corp, Redmond, WA 98052 USA
关键词
SaaS; access control; information flow control; RBAC; role hierarchy and resource hierarchy based access control; data dependency; data dependency based information flow control;
D O I
10.1109/ICWS.2016.21
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Due to multi-tenancy, access control is a very important component in SaaS (Software as a Service), especially for controlling cross-tenant accesses. Due to the potential information flow among multiple tenants, information flow control should also be carefully addressed. Existing models for SaaS access control have some limitations, especially in information flow control. In this paper, we define a new SaaS-AIFC model to provide comprehensive and improved access and information flow control in SaaS. SaaS-AIFC incorporates two advanced features. First, SaaS-AIFC integrates the advanced role mapping technique to govern the cross-tenant accesses. Role mapping is very flexible and can be very efficient for SaaS with a large number of tenants. We integrate role mapping in SaaS by developing a detailed process for mapping establishment and retrieval during validation. Second, we propose a new IFC model in SaaS-AIFC, which tracks the dependency of data objects and uses the dependency information to achieve flexible information flow control. An architecture design for realizing the SaaS-AIFC model is also proposed.
引用
收藏
页码:99 / 106
页数:8
相关论文
共 50 条
  • [41] QoS-Aware Service Recommendation for Multi-Tenant SaaS on the Cloud
    Wang, Yanchun
    He, Qiang
    Yang, Yun
    2015 IEEE 12TH INTERNATIONAL CONFERENCE ON SERVICES COMPUTING (SCC 2015), 2015, : 178 - 185
  • [42] Using Microservices for Non-intrusive Customization of Multi-tenant SaaS
    Nguyen, Phu H.
    Song, Hui
    Chauvel, Franck
    Muller, Roy
    Boyar, Seref
    Levin, Erik
    ESEC/FSE'2019: PROCEEDINGS OF THE 2019 27TH ACM JOINT MEETING ON EUROPEAN SOFTWARE ENGINEERING CONFERENCE AND SYMPOSIUM ON THE FOUNDATIONS OF SOFTWARE ENGINEERING, 2019, : 905 - 915
  • [43] Towards a container-based architecture for multi-tenant SaaS applications
    Truyen, Eddy
    Van Landuyt, Dimitri
    Reniers, Vincent
    Rafique, Ansar
    Lagaisse, Bert
    Joosen, Wouter
    15TH WORKSHOP ON ADAPTIVE AND REFLECTIVE MIDDLEWARE (ARM 2016), 2016,
  • [44] Research on Optimization Adjustment Strategy for SaaS Multi-tenant Data Placement
    Li Xiaona
    Li Qingzhong
    Zhu Weiyi
    Li Hui
    INTERNATIONAL JOURNAL OF GRID AND DISTRIBUTED COMPUTING, 2015, 8 (02): : 319 - 330
  • [45] Enhanced Scaffold Design Pattern for Seculde Multi-tenant SaaS Application
    Balasubramanian, Nagarajan
    Jayapal, Suguna
    PROCEEDINGS OF THE FIRST INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND INFORMATICS, ICCII 2016, 2017, 507 : 671 - 680
  • [46] Policy-Driven Middleware for Multi-Tenant SaaS Services Configuration
    Aouzal, Khadija
    Hafiddi, Hatim
    Dahchour, Mohamed
    INTERNATIONAL JOURNAL OF CLOUD APPLICATIONS AND COMPUTING, 2019, 9 (04) : 86 - 106
  • [47] Thread-Level CPU and Memory Usage Control of Custom Code in Multi-tenant SaaS
    Makki, Majid
    Van Landuyt, Dimitri
    Lagaisse, Bert
    Joosen, Wouter
    SERVICE-ORIENTED COMPUTING (ICSOC 2019), 2019, 11895 : 267 - 282
  • [48] Runtime Evolution of Service-Based Multi-tenant SaaS Applications
    Kumara, Indika
    Han, Jun
    Colman, Alan
    Kapuruge, Malinda
    SERVICE-ORIENTED COMPUTING, ICSOC 2013, 2013, 8274 : 192 - 206
  • [49] Design and Evaluation of Automatic Workflow Scaling Algorithms for Multi-tenant SaaS
    Atrey, Ankita
    Moens, Hendrik
    Van Seghbroeck, Gregory
    Volckaert, Bruno
    De Turck, Filip
    PROCEEDINGS OF THE 6TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING AND SERVICES SCIENCE, VOL 1 (CLOSER), 2016, : 221 - 229
  • [50] Leveraging NoSQL for Scalable and Dynamic Data Encryption in Multi-Tenant SaaS
    Rafique, Ansar
    Van Landuyt, Dimitri
    Reniers, Vincent
    Joosen, Wouter
    2017 16TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS / 11TH IEEE INTERNATIONAL CONFERENCE ON BIG DATA SCIENCE AND ENGINEERING / 14TH IEEE INTERNATIONAL CONFERENCE ON EMBEDDED SOFTWARE AND SYSTEMS, 2017, : 885 - 892