{"title":"Towards a Flexible Fine-Grained Access Control System for Modern Cloud Applications","authors":"Reza Shiftehfar, K. Mechitov, G. Agha","doi":"10.1109/CLOUD.2014.144","DOIUrl":null,"url":null,"abstract":"The fast growth of cloud applications highlights the requirement of appropriate security controls to restrict access to shared resources limited to authorized users. Existing authorization systems are not primarily designed for cloud environments and do not provide the required flexibility, adaptability, elasticity, scalability, or fine-grainedness of cloud applications. This paper outlines an ongoing effort in development of a flexible fine-grained access control system for modern cloud-based applications. Modern cloud applications are distinctive in that the required authorization rules are defined by the organizations owning data and resources, before the application logic can be developed by their programmers. Although this simplifies cloud application development and provides flexibility and adaptability to potential future policy changes, it highlights the need for an adaptive flexible authorization system.","PeriodicalId":288542,"journal":{"name":"2014 IEEE 7th International Conference on Cloud Computing","volume":"21 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2014-06-27","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"5","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2014 IEEE 7th International Conference on Cloud Computing","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/CLOUD.2014.144","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 5
Abstract
The fast growth of cloud applications highlights the requirement of appropriate security controls to restrict access to shared resources limited to authorized users. Existing authorization systems are not primarily designed for cloud environments and do not provide the required flexibility, adaptability, elasticity, scalability, or fine-grainedness of cloud applications. This paper outlines an ongoing effort in development of a flexible fine-grained access control system for modern cloud-based applications. Modern cloud applications are distinctive in that the required authorization rules are defined by the organizations owning data and resources, before the application logic can be developed by their programmers. Although this simplifies cloud application development and provides flexibility and adaptability to potential future policy changes, it highlights the need for an adaptive flexible authorization system.