Packet: a privacy-aware access control policy composition method for services composition in cloud environments

被引:0
|
作者
Li Lin
Jian Hu
Jianbiao Zhang
机构
[1] Beijing University of Technology,College of Computer Science
[2] Beijing Key Laboratory of Trusted Computing,undefined
[3] National Engineering Laboratory for Classified Information Security Protection,undefined
来源
关键词
cloud service composition; access control; privacy; policy composition; unified policy format; conflict detection; similarity analysis; conflict resolution;
D O I
暂无
中图分类号
学科分类号
摘要
Combining different independent cloud services must coordinate their access control policies. Otherwise unauthorized access to composite cloud service can occur when there’s a conflict among different cloud service providers’ access control policies, and then it will bring serious data security and privacy issues. In this paper, we propose Packet, a novel access control policy composition method that can detect and resolve policy conflicts in cloud service composition, including those conflicts related to privacyaware purposes and conditions. The Packet method is divided into four steps. First, employing a unified description, heterogeneous policies are transformed into a unified attributebased format. Second, to improve the conflict detection efficiency, policy conflicts on the same resource can be eliminated by adopting cosine similarity-based algorithm. Third, exploiting a hierarchical structure approach, policy conflicts related to different resources or privacy-aware purposes and conditions can be detected. Fourth, different conflict resolution techniques are presented based on the corresponding conflict types. We have successfully implemented the Packet method in Openstack platform. Comprehensive experiments have been conducted, which demonstrate the effectiveness of the proposed method by the comparison with the existing XACML-based system at conflict detection and resolution performance.
引用
收藏
页码:1142 / 1157
页数:15
相关论文
共 50 条
  • [41] Access Control Policy Analysis and Access Denial Method for Cloud Services
    Chi-Lun Liu
    Journal of Electronic Science and Technology, 2013, (02) : 176 - 180
  • [42] Using Searchable Encryption for Privacy-Aware Orchestrated Web Service Composition
    Khabou, Imen
    Rouached, Mohsen
    Viejo, Alexandre
    Sanchez, David
    2017 13TH INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND SECURITY (CIS), 2017, : 307 - 311
  • [43] Access Control Policy Analysis and Access Denial Method for Cloud Services
    Chi-Lun Liu
    Journal of Electronic Science and Technology, 2013, 11 (02) : 176 - 180
  • [44] An Enhanced Privacy-Aware Authentication Scheme for Distributed Mobile Cloud Computing Services
    Xiong, Ling
    Peng, Daiyuan
    Peng, Tu
    Liang, Hongbin
    KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2017, 11 (12): : 6169 - 6187
  • [45] Efficient, Traceable and Privacy-Aware Data Access Control in Distributed Cloud-Based IoD Systems
    Ma, Zhuo
    Zhang, Jiawei
    IEEE ACCESS, 2023, 11 : 45206 - 45221
  • [46] On the Security of a Privacy-Aware Authentication Scheme for Distributed Mobile Cloud Computing Services
    Jiang, Qi
    Ma, Jianfeng
    Wei, Fushan
    IEEE SYSTEMS JOURNAL, 2018, 12 (02): : 2039 - 2042
  • [47] Privacy-aware access control through negotiation in daily life service
    Park, Hyun-A
    Zhan, Justin
    Lee, Dong Hoon
    INTELLIGENCE AND SECURITY INFORMATICS, PROCEEDINGS, 2008, 5075 : 514 - +
  • [48] HireSome-II: Towards Privacy-Aware Cross-Cloud Service Composition for Big Data Applications
    Dou, Wanchun
    Zhang, Xuyun
    Liu, Jianxun
    Chen, Jinjun
    IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2015, 26 (02) : 455 - 466
  • [49] Privacy-aware access control for video data in intelligent surveillance systems
    Vagts, Hauke
    Jakoby, Andreas
    MOBILE MULTIMEDIA/IMAGE PROCESSING, SECURITY, AND APPLICATIONS 2012, 2012, 8406
  • [50] A Category-Based Framework for Privacy-Aware Collaborative Access Control
    Obrezkov, Denis
    Sohr, Karsten
    Malaka, Rainer
    TRUST, PRIVACY AND SECURITY IN DIGITAL BUSINESS (TRUSTBUS 2021), 2021, 12927 : 126 - 139