Cross-tenant access control method based on trust model in cloud environment
A trust model and access control technology, applied in the field of cloud computing information security, can solve the problems of cloud resources losing security control and inapplicability, and achieve the effect of good promotion and use value, simple structure and reasonable design
Patent Information
- Authority / Receiving Office
- CN · China
- Current Assignee / Owner
- Publication Date
- 2016-08-17
Smart Images
Figure 1 Figure 2 Figure 3
Abstract
Description
technical field
[0001] The invention belongs to the field of cloud computing information security, and more specifically relates to a trust model-based cross-tenant access control method in a cloud environment. Background technique
[0002] Cloud computing is one of the hot topics in the current information technology field, and it is the focus of academia, industry, and government. Its core idea is to link a large number of computing resources, storage resources and software resources together to form a huge scale. Shared virtual IT resource pool. Multi-tenant technology enables different users to share the same resources, which is the key technology adopted by cloud computing and the key reason why resources can be dynamically scaled and fully utilized. Multi-tenant technology also faces new challenges while obtaining cloud services through on-demand customization and shared storage interaction: 1. Unauthorized tenants steal information in order to obtain business secrets...
Examples
Embodiment
[0061] (1) Tenant registration
[0062] Enterprise tenants plan to use the tenant trust relationship management services provided by cloud service providers. First, the enterprise tenant applies to the cloud service provider through the registration process, and registers the tenant information, including company name, address, phone number, etc.; then provides the tenant administrator information (this administrator will be used later to create tenant internal users and assign permissions), Select the specific functional modules of the trust relationship management service, such as application, permission, and revocation.
[0063] (2) Internal access control modeling
[0064] Tenant administrators can choose one of the three access control types (discretionary access control, mandatory access control, and role-based access control) provided by cloud service providers to complete tenant internal access control modeling.
[0065] (3) Cross-tenant access control modeling
[0...