Skip to main content
QUICK REVIEW

[論文レビュー] Improved hierarchical role based access control model for cloud computing

Navod Neranjan Thilakarathne, D. Wickramaaarachchi|arXiv (Cornell University)|Nov 16, 2020
Cryptography and Data Security参考文献 1被引用数 7
ひとこと要約

本論文は、クラウドコンピューティング向けに改善された階層型ロールベースアクセス制御(HRBAC)モデルを提案する。このモデルは、ハイブリッド暗号方式(AESおよびRSA)とハイブリッドクラウドアーキテクチャを統合することで、セキュリティ、パフォーマンス、およびデータ整合性を向上させる。モデルはサイバー攻撃に対して強く耐性を持ち、実際のクラウド環境において既存のアクセス制御モデルを上回る性能を示す。

ABSTRACT

Cloud computing is considered as the one of the most dominant paradigm in field of information technology which offers on demand cost effective services such as Software as a service (SAAS), Infrastructure as a service (IAAS) and Platform as a service (PAAS).Promising all these services as it is, this cloud computing paradigm still associates number of challenges such as data security, abuse of cloud services, malicious insider and cyber-attacks. Among all these security requirements of cloud computing access control is the one of the fundamental requirement in order to avoid unauthorized access to a system and organizational assets. Main purpose of this research is to review the existing methods of cloud access control models and their variants pros and cons and to identify further related research directions for developing an improved access control model for public cloud data storage. We have presented detailed access control requirement analysis for cloud computing and have identified important gaps, which are not fulfilled by conventional access control models. As the outcome of the study we have come up with an improved access control model with hybrid cryptographic schema and hybrid cloud architecture and practical implementation of it. We have tested our model for security implications, performance, functionality and data integrity to prove the validity. We have used AES and RSA cryptographic algorithms to implement the cryptographic schema and used public and private cloud to enforce our access control security and reliability.By validating and testing we have proved that our model can withstand against most of the cyber attacks in real cloud environment. Hence it has improved capabilities compared with other previous access control models that we have reviewed through literature.

研究の動機と目的

  • 既存のクラウドアクセス制御モデルにおける深刻なギャップ、特にデータセキュリティと内部者脅威の低減を解決すること。
  • パブリッククラウドのデータストレージに特化したスケーラブルで安全なアクセス制御フレームワークを設計すること。
  • 暗号セキュリティとクラウドアーキテクチャを統合し、サイバー攻撃に対するレジリエンスを向上させること。
  • 実装による実践的評価を通じて、モデルの機能性、パフォーマンス、およびデータ整合性を検証すること。
  • 次世代クラウドアクセス制御システムのための研究方向性を同定すること。

提案手法

  • 組織の各レベルでのユーザー権限を管理するために、階層型ロールベースアクセス制御(HRBAC)構造を採用する。
  • 暗号スキーマにおいて、効率的なデータ暗号化のためのAESと、安全な鍵管理のためのRSAを統合する。
  • パブリッククラウドとプライベートクラウドを組み合わせたハイブリッドクラウドアーキテクチャを用い、アクセス制御ポリシーとデータ隔離を実装する。
  • 暗号認証を介したロールベースのアクセス意思決定によって、アクセス制御を強制する。
  • さまざまなサイバー攻撃シナリオ下で実際のクラウド環境でのテストを実施し、セキュリティとパフォーマンスを評価した。
  • 実装には、アクセス制御ポリシーの強制、データ整合性チェック、および安全な鍵交換メカニズムが含まれる。

実験結果

リサーチクエスチョン

  • RQ1既存のHRBACモデルは、内部者攻撃やデータ漏洩といった現代のクラウドセキュリティ脅威に対処するために、どのように改善できるか?
  • RQ2HRBACと効果的に組み合わせることで、クラウド環境におけるセキュリティとパフォーマンスを向上させる暗号技術は何か?
  • RQ3ハイブリッドクラウドアーキテクチャは、アクセス制御モデルのレジリエンスとスケーラビリティにどのように寄与するか?
  • RQ4本モデルは、実際のクラウドデプロイメントにおいて、一般的なサイバー攻撃に対してどの程度耐性を示すか?
  • RQ5改善されたアクセス制御モデルの主なパフォーマンスおよび整合性メトリクスは、従来のシステムと比較してどのような点で優れているか?

主な発見

  • 提案されたモデルは、実際のクラウド環境において、不正アクセスやデータ改ざんを含む幅広いサイバー攻撃に対して効果的に耐性を示した。
  • AESおよびRSA暗号アルゴリズムの統合により、データ機密性と鍵セキュリティが顕著に向上した。
  • ハイブリッドクラウドデプロイメントモデルにより、機密性の高い操作をプライベートクラウドに隔離することで、システムのレジリエンスが向上した。
  • パフォーマンステストの結果、高負荷状態下でも許容可能な応答時間が維持されたことから、実用性が確認された。
  • すべてのテストシナリオにおいてデータ整合性が保持され、データ破損や不正な変更は観測されなかった。
  • セキュリティカバレッジと脅威低減の観点から、従来のHRBACおよび既存のアクセス制御モデルを上回る性能を示した。

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。