Authors:
Simeon Veloudis
1
;
Yiannis Verginadis
2
;
Ioannis Patiniotakis
2
;
Iraklis Paraskakis
3
and
Gregoris Mentzas
2
Affiliations:
1
International Faculty of the University of Sheffield and CITY Colle, Greece
;
2
National Technical University of Athens, Greece
;
3
International Faculty of the University of Sheffield, Greece
Keyword(s):
Context-aware Security, Ontologies, Access Control, Data Privacy, Security by Design.
Related
Ontology
Subjects/Areas/Topics:
Access Control
;
Cloud Computing
;
Cloud Computing Enabling Technology
;
Data Engineering
;
Databases and Data Security
;
Information and Systems Security
;
Internet Technology
;
Security, Privacy, and Compliance Management
;
Service Modeling and Specification
;
Services Science
;
Web Information Systems and Technologies
Abstract:
Enterprises are embracing cloud computing in order to reduce costs and increase agility in their everyday business operations. Nevertheless, due mainly to confidentiality, privacy and integrity concerns, many are still reluctant to migrate their sensitive data to the cloud. In this paper, firstly, we outline the construction of a suitable Context-aware Security Model, for enhancing security in cloud applications. Secondly, we outline the construction of an extensible and declarative formalism for representing policy-related knowledge, one which disentangles the definition of a policy from the code employed for enforcing it. Both of them will be employed for supporting innovative PaaS-enabled access control mechanisms.