Towards Multi-party Policy-based Access Control in Federations of Cloud and Edge Microservices

2019 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)(2019)

引用 12|浏览9
暂无评分
摘要
The development and deployment of microservices and containers come with a promise of flexibility by embracing heterogeneity and reducing the amount of communication and coordination between service teams. However, when such software ecosystems are developed in large organizations with a high degree of independence, and deployed in the cloud and at the edge, security becomes a non-trivial concern. The challenge that we address in this work is the delegated management of access control decisions to multiple stakeholders in continuously evolving federations of cloud and edge microservices. To ensure that user-centric access control remains sustainable in such complex service delivery models, we present a dynamic granular access control solution on top of different authorization frameworks. By leveraging microservice technologies, our solution is flexible, scalable, and contextual, and can adhere to the security needs of different stakeholders in microservice federations - from DevOps teams to common end-users - with the necessary agility to respond to exceptional security circumstances.
更多
查看译文
关键词
authorization,microservices,policy-based access control,edge,federation
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要