Towards a security-enhanced PaaS platform for multi-cloud applications
Autor: | Kyriakos Kritikos, Philippe Massonet, Bartosz Kryza, Tom Kirkham |
---|---|
Rok vydání: | 2017 |
Předmět: |
Cloud computing security
Exploit Computer Networks and Communications business.industry Computer science 020206 networking & telecommunications Access control Provisioning Cloud computing 02 engineering and technology Computer security model User requirements document Computer security computer.software_genre Security information and event management Hardware and Architecture 0202 electrical engineering electronic engineering information engineering 020201 artificial intelligence & image processing business computer Software |
Zdroj: | Future Generation Computer Systems. 67:206-226 |
ISSN: | 0167-739X |
DOI: | 10.1016/j.future.2016.10.008 |
Popis: | Multi-cloud adaptive application provisioning can solve the vendor lock-in problem and allows optimising user requirements by selecting the best from the multitude of services offered by different cloud providers. To this end, such provisioning type is increasingly supported by new or existing research prototypes and platforms. One major concern, actually preventing users from moving to the cloud, comes with respect to security, which becomes more complex in multi-cloud settings. Such a concern spans two main aspects: (a) suitable access control on user personal data, VMs and platform services and (b) planning and adapting application deployments based on security requirements. As such, this paper addresses both security aspects by proposing a novel model-driven approach and architecture which secures multi-cloud platforms, enables users to have their own private space and guarantees that application deployments are not only constructed based on but can also maintain a certain user-required security level. Such a solution exploits state-of-the-art security standards, security software and secure model management technology. Moreover, it covers different access control scenarios involving external, web-based and programmatic user authentication. |
Databáze: | OpenAIRE |
Externí odkaz: |