Authors:
Jorge Bernal Bernabe
1
;
Juan M. Marin Perez
1
;
Jose M. Alcaraz Calero
2
;
Felix J. Garcia Clemente
1
;
Gregorio Martinez Perez
1
and
Antonio F. Gomez Skarmeta
1
Affiliations:
1
University of Murcia, Spain
;
2
Hewlett-Packard Laboratories, United Kingdom
Keyword(s):
Authorization system, Cloud computing, Multi-tenancy, Trust model, Semantic web.
Related
Ontology
Subjects/Areas/Topics:
Access Control
;
Data and Application Security and Privacy
;
Data Engineering
;
Databases and Data Security
;
Information and Systems Security
;
Internet Technology
;
Secure Cloud Computing
;
Web Information Systems and Technologies
Abstract:
The provision of security services is a key enabler in cloud computing architectures. Focusing on multi-tenancy authorization systems, the provision of different models including role based access control (RBAC), hierarchical RBAC (hRBAC), conditional RBAC (cRBAC) and hierarchical objects (HO) is the main objective of this paper. Our proposal is based on the Common Information Model (CIM) and Semantic Web technologies, which have been demonstrated as valid tools for describing authorization models. As the same language is being used for the information and the authorization models they are both well aligned and thus reducing the potential mismatch that may appear between the semantics of both models. A trust model enabling the establishment of coalitions and federations across tenants is also an objective being covered as part of the research being presented in this paper.