Delegation for On-boarding Federation Across Storage Clouds
نویسندگان
چکیده
On-boarding federation allows an enterprise to efficiently migrate its data from one storage cloud provider to another (e.g., for business or legal reasons), while providing continuous access and a unified view over the data during the migration. On-boarding is provided through a federation layer on the new destination cloud. An on-boarding relationship is set up by a user between containers on the two clouds. Once the relationship is set up, the on-boarding layer is responsible to carry out the migration on behalf of the user, reading objects from the old source cloud and writing objects to the new destination cloud. In this paper we describe a delegation architecture for on-boarding where the user delegates to the on-boarding layer a subset of his/her access rights on the source and destination clouds to enable on-boarding to occur in a safe and secure way, such that the on-boarding layer has the least privilege required to carry out its work. We also show how this delegation architecture can be implemented using SAML.
منابع مشابه
How to Federate VISION Clouds through SAML/Shibboleth Authentication
Federation is currently finding a wide argumentation in Cloud Computing. The federation among cloud operators should allow new opportunities and businesses even making the role of SMEs crucial in these new scenarios. In this work, we provide a solution on how to federate Storage Cloud providers, enabling the transparent and dynamic federation among storage suppliers adding new functionalities f...
متن کاملIntroducing Federated WebDAV Access to Cloud Storage Providers
Affordable access to large online hard disks via the Internet has emerged by the continuous evolving of public and private storage clouds. However, difficulties arise as soon as users of such storages want to employ services from different cloud providers simultaneously, e.g., for collaboration among institutions that use different storage providers or for distribution of data backups. The reas...
متن کاملEfficient Hybrid Proxy Re-Encryption for Practical Revocation and Key Rotation
We consider the problems of i) using public-key encryption to enforce dynamic access control on clouds; and ii) key rotation of data stored on clouds. Historically, proxy re-encryption, ciphertext delegation, and related technologies have been advocated as tools that allow for revocation and the ability to cryptographically enforce dynamic access control on the cloud, and more recently they hav...
متن کاملHuman Resource Development Indicators for the Iranian Judo Federation
Objectives. The aim of this study was to identify and prioritize human resource development indicators for the Iranian Judo Federation. Methods. The present study was a combined (mixed) research. The research population consisted of officials from the Federation, the national team coaches and members, delegation officials, university professors, and other experts (n=96). The sampling was purpo...
متن کاملOn the deployment of a real scalable delegation service
This paper explains the evolution of the concept of delegation since its first references in the context of distributed authorization to the actual use as a fundamental part of a privilege management architecture. The work reviews some of the earliest contributions that pointed out the relevance of delegation when dealing with distributed authorization, in particular we comment on PolicyMaker a...
متن کامل