Design and Implementation of Virtual Private Services

  • Authors:
  • Sotiris Ioannidis;Steven M. Bellovin;John Ioannidis;Angelos D. Keromytis;Jonathan M. Smith

  • Affiliations:
  • -;-;-;-;-

  • Venue:
  • WETICE '03 Proceedings of the Twelfth International Workshop on Enabling Technologies: Infrastructure for Collaborative Enterprises
  • Year:
  • 2003

Quantified Score

Hi-index 0.00

Visualization

Abstract

Large scale distributed applications such as electroniccommerce and online marketplaces combine network accesswith multiple storage and computational elements. Thedistributed responsibility for resource control creates newsecurity and privacy issues, which are exacerbated by thecomplexity of the operating environment. In order to handlepolicies at multiple locations, the usual tools available(firewalls and compartmented file storage) get to be used inways that are clumsy and prone to failure.We propose a new approach, virtual private services.Our approach relies on two functional divisions. First, wesplit policy specification and policy enforcement, providinglocal autonomy within the constraints of the global securitypolicy. Second, we create virtual security domains, eachwith its own security policy. Every domain has an associatedset of privileges and permissions restricting it to theresources it needs to use and the services it must perform.Virtual private services ensure security and privacy policiesare adhered to through coordinated policy enforcementpoints. We describe our architecture and a prototype implementation,and present a preliminary performance evaluationconfirming that our overhead of policy enforcementusing is small.