A Cloud-Oriented Cross-Domain Security Architecture

被引:6
作者
Nguyen, Thuy D. [1 ]
Gondree, Mark A. [1 ]
Shifflett, David J. [1 ]
Khosalim, Jean [1 ]
Levin, Timothy E. [1 ]
Irvine, Cynthia E. [1 ]
机构
[1] USN, Postgrad Sch, Dept Comp Sci, Monterey, CA 93943 USA
来源
MILITARY COMMUNICATIONS CONFERENCE, 2010 (MILCOM 2010) | 2010年
关键词
cloud computing; cross-domain services; collaborative applications; quality of security services;
D O I
10.1109/MILCOM.2010.5680360
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
The Monterey Security Architecture addresses the need to share high-value data across multiple domains of different classification levels while enforcing information flow policies. The architecture allows users with different security authorizations to securely collaborate and exchange information using commodity computers and familiar commercial client software that generally lack the prerequisite assurance and functional security protections. MYSEA seeks to meet two compelling requirements, often assumed to be at odds: enforcing critical, mandatory security policies, and allowing access and collaboration in a familiar work environment. Recent additions to the MYSEA design expand the architecture to support a cloud of cross-domain services, hosted within a federation of multilevel secure (MLS) MYSEA servers. The MYSEA cloud supports single-sign on, service replication, and network-layer quality of security service. This new cross-domain, distributed architecture follows the consumption and delivery model for cloud services, while maintaining the federated control model necessary to support and protect cross-domain collaboration within the enterprise. The resulting architecture shows the feasibility of high-assurance, cross-domain services hosted within a community cloud suitable for interagency, or joint, collaboration. This paper summarizes the MYSEA architecture and discusses MYSEA's approach to provide an MLS-constrained cloud computing environment.
引用
收藏
页码:441 / 447
页数:7
相关论文
共 53 条
  • [1] Anderson J., 1972, Technical Report ESD-TR-73-51
  • [2] ANDERSON M, 1996, P 12 COMP SEC APPL C
  • [3] [Anonymous], 2009, NIST DEFINITION CLOU
  • [4] [Anonymous], 1975, MTR2997 MITRE CORP
  • [5] A survey of QoS architectures
    Aurrecoechea, C
    Campbell, AT
    Hauw, L
    [J]. MULTIMEDIA SYSTEMS, 1998, 6 (03) : 138 - 151
  • [6] *BAE SYST INF TECH, 2008, SEC TARG VERS 1 22 X
  • [7] BAILEY M, 2007, CROSSTALK MAGAZI JUL, V21, P21
  • [8] Biba K. J., 1977, ESDTR76372 MITRE COR
  • [9] *CNSS, 4009 CNSS
  • [10] *COMM CRIT PROJ SP, 2009, CCMB200907002 COMM C