Access Control and Security Properties Requirements Specification for Clouds' SecLAs

被引:4
作者
Guesmi, Asma [1 ]
Clemente, Patrice [2 ]
机构
[1] Univ Orleans, LIFO, EA 4022, F-45067 Orleans, France
[2] Univ Orleans, ENSI Bourges, LIFO, EA 4022, F-18020 Bourges, France
来源
2013 IEEE FIFTH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING TECHNOLOGY AND SCIENCE (CLOUDCOM), VOL 1 | 2013年
关键词
Security Level Agreement; Security Requirements; Access Control; Security Properties; Cloud Computing; Cloud Broker;
D O I
10.1109/CloudCom.2013.133
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Current Cloud Service Level Agreements (SLAs) do not cover security requirements. Some consortiums have proposed standards for the evaluation of security offered by the Cloud Providers (CP). Cloud Brokers (CB) can then generate Security Level Agreement (SecLA) contracts between customers and providers to fit users' requirements. However, the SecLAs do not provide enough details for complex customers' situations, such as sharing resources with other users/companies, or set up specific Access Controls and Security Properties (ACSP). In this paper, we tackle this issue, by introducing a general Requirement Specification Language (ACSP-RSL) to allow the customers to express their needs in term of ACSP. The underlying formal model, on which is based RSL, is partially presented. The global SecLA definition and negotiation process is thus extended with our proposal. RSL indeed also allows to express Security Requirements currently existing in SecLAs. The negotiation phase between CB and the CPs is discussed. We show how the RSL specifications expressed by the customer can be projected into a generic detection/protection policy expressed as an extension of RSL. A complete use-case for a healthcare system with multitenancy for users and services deployed is given. Its security requirements are analyzed, modeled, expressed and discussed.
引用
收藏
页码:723 / 729
页数:7
相关论文
共 24 条
[1]  
Adi K, 2009, LECT NOTES BUS INF P, V26, P212
[2]  
Almorsy M., 2011, Proceedings of the 2011 IEEE 4th International Conference on Cloud Computing (CLOUD 2011), P364, DOI 10.1109/CLOUD.2011.9
[3]  
Andrieux A., 2003, WEB SERVICES AGREEME
[4]  
Blanc M, 2006, INT S COLLAB TECHNOL, P270
[5]  
Blanc M., 2006, 1 INT WORKSH PRIV SE
[6]  
C. S. Alliance, 2011, STAR REG ENTR
[7]  
C. S. Alliance, 2011, CONS ASS IN QUEST
[8]  
Clemente P, 2010, LECT NOTES COMPUT SC, V6480, P131, DOI 10.1007/978-3-642-17697-5_7
[9]  
Cloud Security Alliance, 2011, TRUST CLOUD IN REF A
[10]  
Filkins B., 2012, INCIDENT HANDLING HE