Federated Authorization for Software-as-a-Service Applications

نویسندگان

  • Maarten Decat
  • Bert Lagaisse
  • Dimitri Van Landuyt
  • Bruno Crispo
  • Wouter Joosen
چکیده

Software-as-a-Service (SaaS) is a type of cloud computing in which a tenant rents access to a shared, typically web-based application hosted by a provider. Access control for SaaS should enable the tenant to control access to data that are located at the provider based on tenant-specific access control policies. To achieve this, state-of-practice SaaS applications provide application-specific access control configuration interfaces and as a result, the tenant policies are evaluated at the provider side. This approach does not support collaboration between provider-side and tenant-side access control infrastructures, thus scattering tenant access control management and forcing the tenant to disclose sensitive access control data. To address these issues, we describe the concept of federated authorization in which management and evaluation of the tenant policies is externalized from the SaaS application to the tenant. This centralizes tenant access control management and lowers the required trust in the provider. This paper presents a generic middleware architecture for federated authorization, describing required extensions to current policy languages and a distributed execution environment. Our evaluation explores the trade-off between performance and security and shows that federated authorization is a feasible and promising approach.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Federated authorization for SaaS applications

With Software-as-a-Service (SaaS), a centrally hosted webbased application is o ered to a large number of customer organizations called tenants, each using multiple applications. The tenant and provider each work in their own authoritative and administrative domain, leading to a federated architecture and raising the bar for security and access control. Access control with SaaS applications is ...

متن کامل

Integrating an AAA-based federation mechanism for OpenStack - The CLASSe view

Identity federations enable users, service providers and identity providers from different organizations to exchange authentication and authorization information in a secure way. In this paper we present a novel identity federation architecture for cloud services based on the integration of a cloud identity management service with an Authentication, Authorization and Accounting (AAA) infrastruc...

متن کامل

Middleware for Scalable Real-time Multimedia Cyberinfrastructure

Middleware is a layer of software that is used by applications to locate people and resources and to provide security. Middleware in the form of authentication, authorization, and directory services is especially of interest for improving the scalability and security of managed multimedia applications. This paper describes the problems, challenges and solutions to creating middleware for real-t...

متن کامل

Group-based Security in a Federated File System

The SILENUS federated file system was developed by the SORCER research group at Texas Tech University. The distributed file system with its dynamic nature does not require any configuration by the end users and system administrators. Managing security in a metacomputing system is a new challenge. It must be ensured that every user has a valid authentication and authorization to view, modify, an...

متن کامل

GÉANT world testbed facility: Federated and distributed testbeds as a service facility of GÉANT

Global network innovation requires large-scale distributed test facilities that are similar to the typically multidomain real-world environments in order to ensure the agile adaptation of new concepts, architectures, technologies and protocols from prototyping through testing into production. Virtualization, in general, allows network researchers to create insulated autonomous slices of product...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2013