Skip to main content

ABAC Based Online Collaborations in the Cloud

  • Conference paper
  • First Online:
Emerging Technologies for Developing Countries (AFRICATEK 2017)

Abstract

Nowadays sharing data among organizations plays an important role for their collaboration. During collaborations, the organizations need to access shared information while respecting the access control constraints. In addition, most organizations rely on cloud based solutions to store their data (e.g. openstack). In such platform, data access is regulated by Access Control Lists (ACLs). ACL defines static access rules. It assumes the knowledge of the whole set of users and possible access requests. This make ACL unusable in collaborative context due to the dynamic nature of collaborative sessions. In this paper, we consider ABAC, a flexible and fine-grained model, as an access control model for cloud-based collaborations to overcome the ACL limitations. We provide an architecture that integrate ABAC in the storage level of a cloud platform.

This is a preview of subscription content, log in via an institution to check access.

Access this chapter

Chapter
USD 29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
eBook
USD 39.99
Price excludes VAT (USA)
  • Available as EPUB and PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book
USD 54.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Institutional subscriptions

References

  1. Mell, P., Grance, T.: The NIST Definition of Cloud Computing. NIST Special Publication 800–145 (Draft). http://csrc.nist.gov/publications/drafts/800-145/Draft-SP-800-145-cloud-definition.pdf (2011). Accessed 10 Sept 2011

  2. Calero, J.M.A., Edwards, N., Kirschnick, J., Wilcock, L., Wray, M.: Toward a multi-tenancy authorization system for cloud services. IEEE Secur. Priv. 8(6), 48–55 (2010)

    Article  Google Scholar 

  3. Tang, B., Sandhu, R.: A Multi-Tenant RBAC model for collaborative cloud services. In: 2013 Eleventh Annual International Conference on Privacy, Security and Trust (PST), pp. 229–238 (2013)

    Google Scholar 

  4. Takabi, H., Joshi, J.B.D., Ahn, G.J.: SecureCloud: towards a comprehensive security framework for cloud computing environments. In: Proceeding of the 1st IEEE International Workshop Emerging Applications for Cloud Computing, pp. 393–398. Seoul, South Korea (2010)

    Google Scholar 

  5. Tanvir, A., Tripathi, A.R.: Specification and verification of security requirements in a programming model for decentralized CSCW systems. ACM Trans. Inf. Syst. Secur. 10(2), 7 (2007)

    Article  Google Scholar 

  6. OpenStack cloud platform. http://www.openstack.org/. Accessed 05 Oct 2016

  7. OpenStack Swift Architecture. https://swiftstack.com/openstack-swift/architecture/. Accessed 05 Oct 2016

  8. Zhang, Y., Krishnan, R., Sandhu, R.: Secure information and resource sharing in cloud. In: CODASPY 2015—Proceedings of the 5th ACM Conference on Data and Application Security and Privacy, pp. 131–133. Association for Computing Machinery, Inc. (2015)

    Google Scholar 

  9. Jin, X., Krishnan, R., Sandhu, R.: A unified attribute-based access control model covering DAC, MAC and RBAC. In: Cuppens-Boulahia, N., Cuppens, F., Garcia-Alfaro, J. (eds.) DBSec 2012. LNCS, vol. 7371, pp. 41–55. Springer, Heidelberg (2012). doi:10.1007/978-3-642-31540-4_4

    Chapter  Google Scholar 

  10. Yuan, E., Tong, J.: Attributed Based Access Control (ABAC) for web services. In: ICWS, pp. 561–569. IEEE Computer Society (2005)

    Google Scholar 

  11. Aydoğan, R., Festen, D., Hindriks, K.V., Jonker, C.M.: Alternating offers protocols for multilateral negotiation. In: Fujita, K., Bai, Q., Ito, T., Zhang, M., Ren, F., Aydoğan, R., Hadfi, R. (eds.) Modern Approaches to Agent-based Complex Automated Negotiation. SCI, vol. 674, pp. 153–167. Springer, Cham (2017). doi:10.1007/978-3-319-51563-2_10

    Chapter  Google Scholar 

  12. Thomas, R.: TMAC: a primitive for applying RBAC in collaborative environment. In: 2nd ACM, Workshop on RBAC, Fairfax, Virginia, USA, pp. 13–19 (1997)

    Google Scholar 

  13. Thomas, R., Sandhu, R.: Task-based Authorization Controls (TBAC): a family of models for active and enterprise-oriented authorization management. In: 11th IFIP Working Conference on Database Security, Lake Tahoe, California, USA (1997)

    Google Scholar 

  14. Sejong, O.H., Park, S.: Task-role-based access control model. Inf. Syst. 28(6), 533–562 (2003)

    Article  MATH  Google Scholar 

  15. Jin, X., Krishnan, R., Sandhu, R.: Role and attribute based collaborative administration of intra-tenant cloud iaas. In: 2014 International Conference on Collaborative Computing: Networking, Applications and Worksharing (CollaborateCom), pp. 261–274 (2014)

    Google Scholar 

  16. Biswas, P., Patwa, F., Sandhu, R.: Content level access control for OpenStack swift storage. In: CODASPY, pp. 123–126 (2015)

    Google Scholar 

  17. Biswas, P., Sandhu, R., Krishnan, R.: An attribute based protection model for JSON documents. In: NSS, pp. 303–317 (2016)

    Google Scholar 

Download references

Author information

Authors and Affiliations

Authors

Corresponding author

Correspondence to Mohamed Amine Madani .

Editor information

Editors and Affiliations

Rights and permissions

Reprints and permissions

Copyright information

© 2018 ICST Institute for Computer Sciences, Social Informatics and Telecommunications Engineering

About this paper

Cite this paper

Madani, M.A., Erradi, M., Benkaouz, Y. (2018). ABAC Based Online Collaborations in the Cloud. In: Belqasmi, F., Harroud, H., Agueh, M., Dssouli, R., Kamoun, F. (eds) Emerging Technologies for Developing Countries. AFRICATEK 2017. Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering, vol 206. Springer, Cham. https://doi.org/10.1007/978-3-319-67837-5_7

Download citation

  • DOI: https://doi.org/10.1007/978-3-319-67837-5_7

  • Published:

  • Publisher Name: Springer, Cham

  • Print ISBN: 978-3-319-67836-8

  • Online ISBN: 978-3-319-67837-5

  • eBook Packages: Computer ScienceComputer Science (R0)

Publish with us

Policies and ethics