Toward efficient and confidentiality-aware federation of access control policies

  • Authors:
  • Maarten Decat;Bert Lagaisse;Wouter Joosen

  • Affiliations:
  • IBBT-DistriNet, KU Leuven, Leuven, Belgium;IBBT-DistriNet, KU Leuven, Leuven, Belgium;IBBT-DistriNet, KU Leuven, Leuven, Belgium

  • Venue:
  • Proceedings of the 7th Workshop on Middleware for Next Generation Internet Computing
  • Year:
  • 2012

Quantified Score

Hi-index 0.00

Visualization

Abstract

This paper presents our work in progress on efficient and confidentiality-aware access control for Software-as-a-Service applications. In SaaS, a tenant organization rents access to a shared, typically web-based application. Access control for these applications requires large amounts of fine-grained data, also from the remaining on-premise applications, of which often sensitive application data. With current SaaS applications the provider evaluates both provider and tenant policies. This forces the tenant to disclose its sensitive access control data and limits policy evaluation performance by having to fetch this data. To address these challenges, we propose to decompose the tenant policies and deploy them across tenant and provider in order to evaluate parts of the policies near the data they require as much as possible, while taking into account the tenant confidentiality constraints. We present a policy decomposition algorithm based on a general attribute-based policy model and describe a supporting middleware system. In the future, we plan to refine this work and evaluate the impact on performance using real-life policies from research projects.