A model for trust-based access control and delegation in mobile clouds

  • Authors:
  • Indrajit Ray;Dieudonne Mulamba;Indrakshi Ray;Keesook J. Han

  • Affiliations:
  • Dept. of Computer Science, Colorado State University, Fort Collins, CO;Dept. of Computer Science, Colorado State University, Fort Collins, CO;Dept. of Computer Science, Colorado State University, Fort Collins, CO;Air Force Research Laboratory/RIGA, Rome, NY

  • Venue:
  • DBSec'13 Proceedings of the 27th international conference on Data and Applications Security and Privacy XXVII
  • Year:
  • 2013

Quantified Score

Hi-index 0.00

Visualization

Abstract

Multi-tenancy, elasticity and dynamicity pose several novel challenges for access control in mobile smartphone clouds such as the Android$\textsuperscript\texttrademark$ cloud. Accessing subjects may dynamically change, resources requiring protection may be created or modified, and a subject's access requirements to resources may change during the course of the application execution. Cloud tenants may need to acquire permissions from different administrative domains based on the services they require. Moreover, all the entities participating in a cloud may not be trusted to the same degree. Traditional access control models are not adequate for mobile clouds. In this work, we propose a new access control framework for mobile smartphone clouds. We formalize a trust-based access control model with delegation for providing fine-grained access control. Our model incorporates the notion of trust in the Role-Based Access Control (RBAC) model and also formalizes the concept of trustworthy delegation.