Federated Access Control in Heterogeneous Intercloud Environment: Basic Models and Architecture Patterns

被引:13
作者
Demchenko, Yuri [1 ]
Ngo, Canh [1 ]
de Laat, Cees [1 ]
Lee, Craig [2 ]
机构
[1] Univ Amsterdam, Syst & Network Engn, Amsterdam, Netherlands
[2] Aerosp Corp, El Segundo, CA 90245 USA
来源
2014 IEEE INTERNATIONAL CONFERENCE ON CLOUD ENGINEERING (IC2E) | 2014年
关键词
Federated Intercloud Access Control Infrastructure; Intercloud Federations Framework; Intercloud Architecture Framework; Authorisation; Federated Identity Management; Cloud Security infrastructure;
D O I
10.1109/IC2E.2014.84
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This paper presents on-going research to define the basic models and architecture patterns for federated access control in heterogeneous (multi-provider) multi-cloud and inter-cloud environment. The proposed research contributes to the further definition of Intercloud Federation Framework (ICFF) which is a part of the general Intercloud Architecture Framework (ICAF) proposed by authors in earlier works. ICFF attempts to address the interoperability and integration issues in provisioning on-demand multi-provider multi-domain heterogeneous cloud infrastructure services. The paper describes the major inter-cloud federation scenarios that in general involve two types of federations: customer-side federation that includes federation between cloud based services and customer campus or enterprise infrastructure; and provider-side federation that is created by a group of cloud providers to outsource or broker their resources when provisioning services to customers. The proposed federated access control model uses Federated Identity Management (FIDM) model that can be also supported by the trusted third party entities such as Cloud Service Broker (CSB) and/or trust broker to establish dynamic trust relations between entities without previously existing trust. The research analyses different federated identity management scenarios, defines the basic architecture patterns and the main components of the distributed federated multi-domain Authentication and Authorisation infrastructure. Keywords-Federated
引用
收藏
页码:439 / 445
页数:7
相关论文
共 19 条
[1]  
[Anonymous], 2005, ASS PROT OASIS SEC A
[2]  
[Anonymous], NIST SP
[3]  
[Anonymous], 2012, OASIS ID CLOUD US CA
[4]  
Buyya Rajkumar, 2010, LNCS
[5]  
Chadwick D., 2014, J GRID COMP IN PRESS
[6]  
Demchenko Y., 2010, P 2 IEEE INT C CLOUD
[7]  
Demchenko Y., 2006, COLSEC2006 WORKSH P
[8]  
Demchenko Y., 2007, P IEEE WORKSH POL DI
[9]  
Demchenko Y., 2011, P 3 IEEE C CLOUD COM
[10]  
Demchenko Y., 2013, 27 IEEE INT C ADV IN