Skip to main content
QUICK REVIEW

[논문 리뷰] Improved hierarchical role based access control model for cloud computing

Navod Neranjan Thilakarathne, D. Wickramaaarachchi|arXiv (Cornell University)|2020. 11. 16.
Cryptography and Data Security참고 문헌 1인용 수 7
한 줄 요약

이 논문은 클라우드 컴퓨팅을 위한 향상된 계층적 역할 기반 접근제어(HRBAC) 모델을 제안하며, 하이브리드 암호화(AES 및 RSA)와 하이브리드 클라우드 아키텍처를 통합하여 보안, 성능 및 데이터 무결성을 향상시킨다. 이 모델은 사이버 공격에 강력한 저항성을 보이며 실제 클라우드 환경에서 기존 접근제어 모델보다 뛰어난 성능을 발휘한다.

ABSTRACT

Cloud computing is considered as the one of the most dominant paradigm in field of information technology which offers on demand cost effective services such as Software as a service (SAAS), Infrastructure as a service (IAAS) and Platform as a service (PAAS).Promising all these services as it is, this cloud computing paradigm still associates number of challenges such as data security, abuse of cloud services, malicious insider and cyber-attacks. Among all these security requirements of cloud computing access control is the one of the fundamental requirement in order to avoid unauthorized access to a system and organizational assets. Main purpose of this research is to review the existing methods of cloud access control models and their variants pros and cons and to identify further related research directions for developing an improved access control model for public cloud data storage. We have presented detailed access control requirement analysis for cloud computing and have identified important gaps, which are not fulfilled by conventional access control models. As the outcome of the study we have come up with an improved access control model with hybrid cryptographic schema and hybrid cloud architecture and practical implementation of it. We have tested our model for security implications, performance, functionality and data integrity to prove the validity. We have used AES and RSA cryptographic algorithms to implement the cryptographic schema and used public and private cloud to enforce our access control security and reliability.By validating and testing we have proved that our model can withstand against most of the cyber attacks in real cloud environment. Hence it has improved capabilities compared with other previous access control models that we have reviewed through literature.

연구 동기 및 목표

  • 기존 클라우드 접근제어 모델의 핵심적 격차, 특히 데이터 보안 및 내부자 위협 완화 측면에서의 문제를 해결하기 위해.
  • 공개 클라우드 데이터 저장소에 특화된 확장 가능하고 안전한 접근제어 프레임워크를 설계하기 위해.
  • 암호 보안을 클라우드 아키텍처와 통합하여 사이버 공격에 대한 내성을 향상시키기 위해.
  • 실제 구현을 통해 모델의 기능성, 성능 및 데이터 무결성을 검증하기 위해.
  • 차세대 클라우드 접근제어 시스템을 위한 연구 방향을 규명하기 위해.

제안 방법

  • 조직의 수준에 따라 사용자 권한을 관리하기 위해 계층적 역할 기반 접근제어(HRBAC) 구조를 사용한다.
  • 암호화 스키마에서 효율적인 데이터 암호화를 위해 AES를, 안전한 키 관리를 위해 RSA를 통합한다.
  • 접근제어 정책과 데이터 격리 구현을 위해 공개 클라우드와 비공개 클라우드를 조합한 하이브리드 클라우드 아키텍처를 사용한다.
  • 암호화 인증을 통해 중재되는 역할 기반 접근 결정을 통해 접근제어를 시행한다.
  • 다양한 사이버 공격 시나리오 하에서 실제 클라우드 환경 테스트를 통해 보안 및 성능을 평가하였다.
  • 구현에는 접근제어 정책 이행, 데이터 무결성 검사, 안전한 키 교환 메커니즘 등이 포함된다.

실험 결과

연구 질문

  • RQ1기존 HRBAC 모델은 현대 클라우드 보안 위협, 예를 들어 내부자 공격 및 데이터 유출과 같은 문제를 어떻게 개선할 수 있는가?
  • RQ2어떤 암호 기법을 HRBAC와 효과적으로 조합하여 클라우드 환경에서 보안과 성능을 동시에 향상시킬 수 있는가?
  • RQ3하이브리드 클라우드 아키텍처는 접근제어 모델의 강건성과 확장성에 어떻게 기여하는가?
  • RQ4제안된 모델은 실제 클라우드 배포 환경에서 일반적인 사이버 공격에 얼마나 잘 저항하는가?
  • RQ5기존 시스템과 비교해 볼 때, 향상된 접근제어 모델의 핵심 성능 및 무결성 메트릭은 무엇인가?

주요 결과

  • 제안된 모델은 실제 클라우드 환경에서 무단 접근 및 데이터 변조와 같은 광범위한 사이버 공격에 효과적으로 저항한다.
  • AES 및 RSA 암호 알고리즘의 통합은 데이터 기밀성과 키 보안을 크게 향상시킨다.
  • 하이브리드 클라우드 배포 모델은 민감한 운영을 비공개 클라우드에 격리함으로써 시스템의 내성을 향상시킨다.
  • 성능 테스트 결과, 고부하 조건에서도 수용 가능한 반응 시간을 유지함으로써 실용적 사용성을 입증하였다.
  • 모든 테스트 시나리오에서 데이터 무결성이 유지되었으며, 데이터 손상 또는 무단 수정 사례는 관찰되지 않았다.
  • 보안 커버리지 및 위협 완화 측면에서 기존의 전통적 HRBAC 및 기존 접근제어 모델보다 뛰어난 성능을 보였다.

더 나은 연구,지금 바로 시작하세요

논문 읽기부터 검토까지, 연구 시간을 획기적으로 줄여보세요.

카드 등록 없음 · 무료 플랜 제공

이 리뷰는 AI가 만들고, 인간 에디터가 검토했습니다.