1 World-Leading Research with Real-World Impact! Authorization Federation in IaaS Multi Cloud Navid Pustchi, Ram Krishnan and Ravi Sandhu SCC 2015.

Slides:



Advertisements
Similar presentations
Institute for Cyber Security
Advertisements

© 2012 Open Grid Forum Simplifying Inter-Clouds October 10, 2012 Hyatt Regency Hotel Chicago, Illinois, USA.
Identity Network Ideals – Heterogeneity & Co-existence
1 Cloud Computing Prof. Ravi Sandhu Executive Director and Endowed Chair April 12, © Ravi Sandhu World-Leading.
Institute for Cyber Security Multi-Tenant Access Control for Cloud Services World-Leading Research with Real-World Impact! 1 PhD Dissertation Defense Bo.
Copyright © 2011 Cloud Security Alliance Trusted Cloud Initiative Work Group Session.
1 Federated Identity and Single-Sign On Prof. Ravi Sandhu Executive Director and Endowed Chair February 15, 2013
Secure Cyber Incident Information Sharing UTSA Team Leads Dr. Ram Krishnan, Assistant Professor, ECE Dr. Ravi Sandhu, Executive Director, ICS April 30,
1 A Unified Attribute-Based Access Control Model Covering DAC, MAC and RBAC Prof. Ravi Sandhu Executive Director and Endowed Chair DBSEC July 11, 2012.
Institute for Cyber Security Extending OpenStack Access Control with Domain Trust World-Leading Research with Real-World Impact! 1 Bo Tang and Ravi Sandhu.
11 World-Leading Research with Real-World Impact! Constraints Specification for Virtual Resource Orchestration in Cloud IaaS Constraints Specification.
Towards Cloud Federations: what we have; what we want OGF 31, Taipei Cloud security session Jens Jensen Science and Technology Facilities Council Rutherford.
11 World-Leading Research with Real-World Impact! Role and Attribute Based Collaborative Administration of Intra-Tenant Cloud IaaS (Invited Paper) Xin.
Secure Information and Resource Sharing in CloudSecure Information and Resource Sharing in Cloud References OSAC-SID Model [1]K. Harrison and G. White.
Prabath Siriwardena Senior Software Architect. An open source Identity & Entitlement management server.
11 World-Leading Research with Real-World Impact! A Formal Model for Isolation Management in Cloud Infrastructure-as-a-Service Khalid Zaman Bijon, Ram.
Federated A(A(A))I Jens Jensen hepsysman, RAL,
1 A Role Based Administration Model For Attribute Xin Jin, Ram Krishnan, Ravi Sandhu SRAS, Sep 19, 2012 World-Leading Research with Real-World Impact!
Effectively and Securely Using the Cloud Computing Paradigm.
Cloud Computing Cloud Security– an overview Keke Chen.
Institute for Cyber Security Multi-Tenant Access Control for Collaborative Cloud Services CS6393 Spring 2014 PhD Seminar Bo Tang April 11, 2014 © ICS at.
Institute for Cyber Security A Multi-Tenant RBAC Model for Collaborative Cloud Services Bo Tang, Qi Li and Ravi Sandhu Presented by Bo Tang at The 11 th.
INSTITUTE FOR CYBER SECURITY 1 Cyber Security: Past, Present and Future Prof. Ravi Sandhu Executive Director and Endowed Chair Institute for Cyber Security.
UTSA Amy(Yun) Zhang, Ram Krishnan, Ravi Sandhu Institute for Cyber Security University of Texas at San Antonio San Antonio, TX Nov 03, 2014 Presented.
1 Multi Cloud Navid Pustchi April 25, 2014 World-Leading Research with Real-World Impact!
Climate Sciences: Use Case and Vision Summary Philip Kershaw CEDA, RAL Space, STFC.
Cloud computing.
Federated Identity Management for HEP David Kelsey WLCG GDB 9 May 2012.
Microsoft Virtual Academy.
Institute for Cyber Security Cross-Tenant Trust Models in Cloud Computing Bo Tang and Ravi Sandhu IRI Aug 14-16, 2013 San Francisco, CA © ICS at UTSA World-Leading.
1 Grand Challenges in Authorization Systems Prof. Ravi Sandhu Executive Director and Endowed Chair November 14, 2011
1 4/23/2007 Introduction to Grid computing Sunil Avutu Graduate Student Dept.of Computer Science.
Institute for Cyber Security Multi-Tenancy Authorization Models for Collaborative Cloud Services Bo Tang, Ravi Sandhu, and Qi Li Presented by Bo Tang ©
1 The Quest for Single-Sign On Prof. Ravi Sandhu Executive Director and Endowed Chair February 8, © Ravi Sandhu.
EduGain Federation – Web SSO
1 RABAC : Role-Centric Attribute-Based Access Control MMM-ACNS 2012 Xin Jin, Ravi Sandhu, Ram Krishnan University of Texas at San Antonio San Antonio,
1 Cloud Computing and Security Prof. Ravi Sandhu Executive Director and Endowed Chair April 19, © Ravi Sandhu.
INSTITUTE FOR CYBER SECURITY A Hybrid Enforcement Model for Group-Centric Secure Information Sharing (g-SIS) Co-authored with Ram Krishnan, PhD Candidate,
Cloud federation Are we there yet? Marek Denis CERN openlab Major Review Geneva, Switzerland › October
1 Attribute-Based Access Control Models and Beyond Prof. Ravi Sandhu Executive Director, Institute for Cyber Security Lutcher Brown Endowed Chair in Cyber.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
b2access.eudat.eu B2ACCESS The simple and secure authorisation and authentication platform of EUDAT This work is licensed under the Creative.
INDIGO – DataCloud Security and Authorization in WP5 INFN RIA
1 Views of Cloud Computing Prof. Ravi Sandhu Executive Director and Endowed Chair March 25, © Ravi Sandhu.
INDIGO – DataCloud CERN CERN RIA
CERN IT Department CH-1211 Geneva 23 Switzerland t OIS Web site lifecycles Problem is that web sites live forever –Out of date sites with.
1 Authorization Federation in Multi-Tenant Multi-Cloud IaaS Navid Pustchi Advisor: Prof. Ravi Sandhu.
1 Secure Cloud Computing: A Research Perspective Prof. Ravi Sandhu Executive Director and Endowed Chair Texas Fresh Air Big Data and Data Analytics Conference.
Access Policy - Federation March 23, 2016
Institute for Cyber Security
Cloud Security– an overview Keke Chen
Institute for Cyber Security
Federated IdM Across Heterogeneous Clouding Environment
World-Leading Research with Real-World Impact!
Open source Cloud Management Platforms
UTSA's New Center Center for Security and Privacy Enhanced Cloud Computing (C-SPECC) Ravi Sandhu Executive Director of ICS and C-SPECC Professor.
ESA Single Sign On (SSO) and Federated Identity Management
Attribute-Based Access Control: Insights and Challenges
Institute for Cyber Security
Institute for Cyber Security
Institute for Cyber Security
ACS Functionality.
Authentication and Authorization Federation
Matthew Levy Azure AD B2B vs B2C Matthew Levy
Attribute-Based Access Control: Insights and Challenges
Single Sign-On (SSO) Authentication
Community AAI with Check-In
Cloud Computing: Concepts
Views of Cloud Computing
Institute for Cyber Security
Presentation transcript:

1 World-Leading Research with Real-World Impact! Authorization Federation in IaaS Multi Cloud Navid Pustchi, Ram Krishnan and Ravi Sandhu SCC 2015

2 World-Leading Research with Real-World Impact! Why Multi Cloud? Collaboration of organizations across clouds. Organizations with resources across multiple clouds.

3 World-Leading Research with Real-World Impact! Scope of Contribution Cloud Federation IaaS SaaS Peer-to-Peer Circle-of-Trust Authorization Federation Authentication Federation Service Trust Coupling PaaS Platform HomogenousHeterogeneous

4 World-Leading Research with Real-World Impact! Multi Cloud Collaboration Cloud Federation Service (IaaS, PaaS, SaaS)  Heterogeneous: Google account (Open ID 2.0) Heterogeneous within google.  Homogenous: Eduroam federated network access. Platform  Heterogeneous: OpenStack federation with AWS.  Homogenous: Keystone to Keystone federation. Trust  Circle-of-Trust: Alliance of institutions for sharing scientific data such as CERN.  Peer-to-Peer: Best Buy federating with Rackspace. Coupling  Identity Federation: SAML, OAuth, OpenID, SSO.  Authorization Federation: SAML, OAuth.

5 World-Leading Research with Real-World Impact! Trust Framework Trust BidirectionalUnidirectional TransitiveNon-Transitive Unilateral Bilateral Circle-of-Trust Peer-to-Peer Coupling Initiation Direction Transitivity

6 World-Leading Research with Real-World Impact! Concept of Trust

7 World-Leading Research with Real-World Impact! Administrative Realms

8 World-Leading Research with Real-World Impact! Multi Cloud Trust Three trust scopes based on administrative realms in cloud:  Cross Cloud Trust Sharing cloud infrastructure resources, such as services.  Cross Domain Trust Sharing domain resources such as projects.  Cross Project Trust Sharing project resources such as VMs.

9 World-Leading Research with Real-World Impact! Cloud Trust Enables sharing cloud resources, services and domains.  Set of domains shared between clouds with trust type (for domain trust).  Sharing services by creating private domains for service allocation. Trust relation in Cloud Trust is Peer-to-Peer, bilateral, bidirectional, non- transitive.

10 World-Leading Research with Real-World Impact! Domain Trust Enabling cross cloud access by assigning users to PRPs between trusted domains. Trust relations are Peer-to-Peer, unilateral, unidirectional, non-transitive.

Enabling cross cloud access to service instances by assigning users to PRPs between trusted projects. Trust relations are Peer-to-Peer, unilateral, unidirectional, non-transitive. 11 World-Leading Research with Real-World Impact! Project Trust

12 World-Leading Research with Real-World Impact! Related Work RBAC extensions  ROBAC (collaboration ins not supported).  GB-RBAC (group does own users). Role Based delegation models  Delegation chains lacks dynamicity of trust in cloud federation environments. Multi-tenant trust models in single cloud.  MT-RBAC (Multi-Tenant RBAC).  CTTM (Cross Tenant Trust model).  OSAC-DT (OpenStack Access Control with Domain Trust).

13 World-Leading Research with Real-World Impact! Conclusion & Future Work Multi-cloud trust model  Cloud trust.  Domain trust.  Project trust. Trust framework & trust types  Four types of trust applicable to administrative realms in cloud. Implementation in single cloud  Partial implementation of domain-trust in single cloud OpenStack. Future Work  Cloud trust implementation.  Implementation in federated OpenStack clouds.  Project trust implementation.  Hierarchical multi-domain model.  Attribute based models.