Skip to main content
QUICK REVIEW

[论文解读] Improved hierarchical role based access control model for cloud computing

Navod Neranjan Thilakarathne, D. Wickramaaarachchi|arXiv (Cornell University)|Nov 16, 2020
Cryptography and Data Security参考文献 1被引用 7
一句话总结

本文提出了一种改进的云环境用分层角色访问控制(HRBAC)模型,通过将混合加密(AES与RSA)与混合云架构相结合,以增强安全性、性能和数据完整性。该模型在真实云环境中表现出对网络攻击的强大抵抗力,并优于现有访问控制模型。

ABSTRACT

Cloud computing is considered as the one of the most dominant paradigm in field of information technology which offers on demand cost effective services such as Software as a service (SAAS), Infrastructure as a service (IAAS) and Platform as a service (PAAS).Promising all these services as it is, this cloud computing paradigm still associates number of challenges such as data security, abuse of cloud services, malicious insider and cyber-attacks. Among all these security requirements of cloud computing access control is the one of the fundamental requirement in order to avoid unauthorized access to a system and organizational assets. Main purpose of this research is to review the existing methods of cloud access control models and their variants pros and cons and to identify further related research directions for developing an improved access control model for public cloud data storage. We have presented detailed access control requirement analysis for cloud computing and have identified important gaps, which are not fulfilled by conventional access control models. As the outcome of the study we have come up with an improved access control model with hybrid cryptographic schema and hybrid cloud architecture and practical implementation of it. We have tested our model for security implications, performance, functionality and data integrity to prove the validity. We have used AES and RSA cryptographic algorithms to implement the cryptographic schema and used public and private cloud to enforce our access control security and reliability.By validating and testing we have proved that our model can withstand against most of the cyber attacks in real cloud environment. Hence it has improved capabilities compared with other previous access control models that we have reviewed through literature.

研究动机与目标

  • 为解决现有云访问控制模型中的关键缺陷,特别是数据安全与内部威胁缓解方面的不足。
  • 设计一种可扩展且安全的访问控制框架,专为公有云数据存储而定制。
  • 将密码学安全机制与云架构集成,以提升对网络攻击的抗御能力。
  • 通过实际实现验证该模型的功能性、性能表现及数据完整性。
  • 识别下一代云访问控制系统的研究方向。

提出的方法

  • 该模型采用分层角色访问控制(HRBAC)结构,以管理组织层级中的用户权限。
  • 在密码学方案中集成AES以实现高效的数据加密,以及RSA以实现安全的密钥管理。
  • 采用混合云架构,结合公有云与私有云,以实施访问控制策略与数据隔离。
  • 通过由密码学认证中介的角色访问决策来强制执行访问控制。
  • 在各种网络攻击场景下,通过真实云环境测试评估安全性和性能。
  • 实现包括访问控制策略强制执行、数据完整性检查以及安全密钥交换机制在内的功能。

实验结果

研究问题

  • RQ1现有HRBAC模型如何改进以应对现代云安全威胁,如内部攻击与数据泄露?
  • RQ2哪些密码学技术可与HRBAC有效结合,以在云环境中同时提升安全性和性能?
  • RQ3混合云架构如何增强访问控制模型的鲁棒性与可扩展性?
  • RQ4该模型在真实云部署中对常见网络攻击的抵抗能力如何?
  • RQ5与先前系统相比,该改进模型的关键性能与完整性指标是什么?

主要发现

  • 所提出的模型在真实云环境中有效抵御了包括未授权访问与数据篡改在内的多种网络攻击。
  • AES与RSA密码算法的集成显著增强了数据机密性与密钥安全性。
  • 混合云部署模型通过在私有云中隔离敏感操作,同时利用公有云的可扩展性,提升了系统韧性。
  • 性能测试证实,该模型在高负载条件下仍能保持可接受的响应时间,展现出实际可用性。
  • 所有测试场景中均保持了数据完整性,未观察到数据损坏或未经授权的修改。
  • 在安全覆盖范围与威胁缓解能力方面,该模型优于传统HRBAC及现有访问控制模型。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。