An Attribute-Based Access Control Extension for OpenStack and its Enforcement Utilizing the Policy Machine

被引:0
|
作者
Bhatt, Smriti [1 ]
Patwa, Farhan
Sandhu, Ravi
机构
[1] Univ Texas San Antonio, Inst Cyber Secur, San Antonio, TX 78249 USA
来源
2016 IEEE 2ND INTERNATIONAL CONFERENCE ON COLLABORATION AND INTERNET COMPUTING (IEEE CIC) | 2016年
关键词
Policy Machine; Attribute-Based Access Control; OpenStack; Authorization Engine;
D O I
10.1109/CIC.2016.17
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Role-Based Access Control (RBAC) has been the dominant access control model in industry since the 1990s. It is widely implemented in many applications, including major cloud platforms such as OpenStack, AWS, and Microsoft Azure. However, due to limitations of RBAC, there is a shift towards Attribute-Based Access Control (ABAC) models to enhance flexibility by using attributes beyond roles and groups. In practice, this shift has to be gradual since it is unrealistic for existing systems to abruptly adopt ABAC models, completely eliminating current RBAC implementations. In this paper, we propose an ABAC extension with user attributes for the OpenStack Access Control (OSAC) model and demonstrate its enforcement utilizing the Policy Machine (PM) developed by the National Institute of Standards and Technology. We utilize some of the PM's components along with a proof-of-concept implementation to enforce this ABAC extension for OpenStack, while keeping OpenStack's current RBAC architecture in place. This provides the benefits of enhancing access control flexibility with support of user attributes, while minimizing the overhead of altering the existing OpenStack access control framework. We present use cases to depict added benefits of our model and show enforcement results. We then evaluate the performance of our proposed ABAC extension, and discuss its applicability and possible performance enhancements.
引用
收藏
页码:37 / 45
页数:9
相关论文
共 50 条
  • [31] Dynamic Attribute-Based Access Control in Cloud Storage Systems
    Liu, Zechao
    Jiang, Zoe L.
    Wang, Xuan
    Yiu, S. M.
    Zhang, Chunkai
    Zhao, Xiaomeng
    2016 IEEE TRUSTCOM/BIGDATASE/ISPA, 2016, : 129 - 137
  • [32] A Privacy-Preserving Attribute-Based Access Control Scheme
    Xu, Yang
    Zeng, Quanrun
    Wang, Guojun
    Zhang, Cheng
    Ren, Ju
    Zhang, Yaoxue
    SECURITY, PRIVACY, AND ANONYMITY IN COMPUTATION, COMMUNICATION, AND STORAGE (SPACCS 2018), 2018, 11342 : 361 - 370
  • [33] Efficient Blockchain Enabled Attribute-based Access Control as a Service
    Kumar, Ritik
    Palanisamy, Balaji
    Sural, Shamik
    2022 IEEE 4TH INTERNATIONAL CONFERENCE ON TRUST, PRIVACY AND SECURITY IN INTELLIGENT SYSTEMS, AND APPLICATIONS, TPS-ISA, 2022, : 87 - 96
  • [34] Securing utility computing using enhanced elliptic curve cryptography and attribute-based access control policy
    Varghese, Saira
    Vigila, S. Maria Celestin
    INTERNATIONAL JOURNAL OF GRID AND UTILITY COMPUTING, 2022, 13 (04) : 394 - 405
  • [35] The Policy Machine: A novel architecture and framework for access control policy specification and enforcement
    Ferraiolo, David
    Atluri, Vijayalakshmi
    Gavrila, Serban
    JOURNAL OF SYSTEMS ARCHITECTURE, 2011, 57 (04) : 412 - 424
  • [36] Attribute-based access control scheme for data sharing on hyperledger fabric
    Zhao, Xiaojie
    Wang, Shangping
    Zhang, Yaling
    Wang, Yu
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2022, 67
  • [37] HGAA: An Architecture to Support Hierarchical Group and Attribute-Based Access Control
    Servos, Daniel
    Osborn, Sylvia L.
    PROCEEDINGS OF THE THIRD ACM WORKSHOP ON ATTRIBUTE-BASED ACCESS CONTROL (ABAC'18), 2018, : 1 - 12
  • [38] Securing Smart Home IoT Systems with Attribute-Based Access Control
    Goyal, Gaurav
    Liu, Peng
    Sural, Shamik
    SAT-CPS'22: PROCEEDINGS OF THE 2022 ACM WORKSHOP ON SECURE AND TRUSTWORTHY CYBER-PHYSICAL SYSTEMS, 2022, : 37 - 46
  • [39] Multi-Authority Attribute-Based Access Control with Smart Contract
    Guo, Hao
    Meamari, Ehsan
    Shen, Chien-Chung
    2019 INTERNATIONAL CONFERENCE ON BLOCKCHAIN TECHNOLOGY (ICBCT 2019), 2019, : 6 - 11
  • [40] Distributed attribute-based access control system using permissioned blockchain
    Rouhani, Sara
    Belchior, Rafael
    Cruz, Rui S.
    Deters, Ralph
    WORLD WIDE WEB-INTERNET AND WEB INFORMATION SYSTEMS, 2021, 24 (05): : 1617 - 1644