An Attribute-Based Access Control Extension for OpenStack and its Enforcement Utilizing the Policy Machine

被引:0
作者
Bhatt, Smriti [1 ]
Patwa, Farhan
Sandhu, Ravi
机构
[1] Univ Texas San Antonio, Inst Cyber Secur, San Antonio, TX 78249 USA
来源
2016 IEEE 2ND INTERNATIONAL CONFERENCE ON COLLABORATION AND INTERNET COMPUTING (IEEE CIC) | 2016年
关键词
Policy Machine; Attribute-Based Access Control; OpenStack; Authorization Engine;
D O I
10.1109/CIC.2016.17
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Role-Based Access Control (RBAC) has been the dominant access control model in industry since the 1990s. It is widely implemented in many applications, including major cloud platforms such as OpenStack, AWS, and Microsoft Azure. However, due to limitations of RBAC, there is a shift towards Attribute-Based Access Control (ABAC) models to enhance flexibility by using attributes beyond roles and groups. In practice, this shift has to be gradual since it is unrealistic for existing systems to abruptly adopt ABAC models, completely eliminating current RBAC implementations. In this paper, we propose an ABAC extension with user attributes for the OpenStack Access Control (OSAC) model and demonstrate its enforcement utilizing the Policy Machine (PM) developed by the National Institute of Standards and Technology. We utilize some of the PM's components along with a proof-of-concept implementation to enforce this ABAC extension for OpenStack, while keeping OpenStack's current RBAC architecture in place. This provides the benefits of enhancing access control flexibility with support of user attributes, while minimizing the overhead of altering the existing OpenStack access control framework. We present use cases to depict added benefits of our model and show enforcement results. We then evaluate the performance of our proposed ABAC extension, and discuss its applicability and possible performance enhancements.
引用
收藏
页码:37 / 45
页数:9
相关论文
共 50 条
  • [41] Mining Attribute-Based Access Control Policies from RBAC Policies
    Xu, Zhongyuan
    Stoller, Scott D.
    2013 10TH INTERNATIONAL CONFERENCE AND EXPO ON EMERGING TECHNOLOGIES FOR A SMARTER WORLD (CEWIT), 2013,
  • [42] A Role-Based Access Control System Using Attribute-Based Encryption
    Wang, Yong
    Ma, Yuan
    Xiang, Keyu
    Liu, Zhenyan
    Li, Ming
    2018 INTERNATIONAL CONFERENCE ON BIG DATA AND ARTIFICIAL INTELLIGENCE (BDAI 2018), 2018, : 128 - 133
  • [43] Authentication-enabled attribute-based access control for smart homes
    Burakgazi Bilgen, Melike
    Abul, Osman
    Bicakci, Kemal
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2023, 22 (02) : 479 - 495
  • [44] Authentication-enabled attribute-based access control for smart homes
    Melike Burakgazi Bilgen
    Osman Abul
    Kemal Bicakci
    International Journal of Information Security, 2023, 22 : 479 - 495
  • [45] Specification and Verification of Separation of Duty Constraints in Attribute-Based Access Control
    Jha, Sadhana
    Sural, Shamik
    Atluri, Vijayalakshmi
    Vaidya, Jaideep
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2018, 13 (04) : 897 - 911
  • [46] An Efficient Verification Approach to Separation of Duty in Attribute-Based Access Control
    Yang, Benyuan
    Hu, Hesuan
    IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2024, 36 (09) : 4428 - 4442
  • [47] An Access Control Model for Cloud Storage Using Attribute-Based Encryption
    Sukhodolskiy, Ilya A.
    Zapechnikov, Sergey V.
    PROCEEDINGS OF THE 2017 IEEE RUSSIA SECTION YOUNG RESEARCHERS IN ELECTRICAL AND ELECTRONIC ENGINEERING CONFERENCE (2017 ELCONRUS), 2017, : 578 - 581
  • [48] A NOVEL ATTRIBUTE-BASED ACCESS CONTROL MODEL FOR MULTIMEDIA SOCIAL NETWORKS
    Zhang, Z.
    Han, L.
    Li, C.
    Wang, J.
    NEURAL NETWORK WORLD, 2016, 26 (06) : 543 - 557
  • [49] Supporting attribute-based access control in authorization and authentication infrastructures with ontologies
    Priebe, Torsten
    Dobmeier, Wolfgang
    Schläger, Christian
    Kamprath, Nora
    Journal of Software, 2007, 2 (01) : 27 - 38
  • [50] Privacy-preserving attribute-based access control for grid computing
    Park, Sang M.
    Chung, Soon M.
    INTERNATIONAL JOURNAL OF GRID AND UTILITY COMPUTING, 2014, 5 (04) : 286 - 296