Federated authorization for SaaS applications
نویسندگان
چکیده
With Software-as-a-Service (SaaS), a centrally hosted webbased application is o ered to a large number of customer organizations called tenants, each using multiple applications. The tenant and provider each work in their own authoritative and administrative domain, leading to a federated architecture and raising the bar for security and access control. Access control with SaaS applications is about protecting the tenant's data at the provider's side using the tenant's policies and user information. In current practice however, all access control policies are evaluated at the provider's side, distributing and fragmenting the tenant's policies over the multiple applications it uses. Moreover, all necessary user information now has to be shared with the provider, resulting in the disclosure of con dential tenant data. Therefore, we propose the concept of federated authorization, a combination of externalized authorization and federated access control techniques whereby the tenant's access control policies are evaluated at the tenant's side using local data.
منابع مشابه
Federated Authorization for Software-as-a-Service Applications
Software-as-a-Service (SaaS) is a type of cloud computing in which a tenant rents access to a shared, typically web-based application hosted by a provider. Access control for SaaS should enable the tenant to control access to data that are located at the provider based on tenant-specific access control policies. To achieve this, state-of-practice SaaS applications provide application-specific a...
متن کاملSecurity-as-a-Service in Multi-cloud and Federated Cloud Environments
The economic benefits of cloud computing are encouraging customers to bring complex applications and data into the cloud. However security remains the biggest barrier in the adoption of cloud, and with the advent of multi-cloud and federated clouds in practice security concerns are for applications and data in the cloud. This paper proposes security as a value added service, provisioned dynamic...
متن کاملFederated Authentication and Authorization for Fedora
Fedora's popularity amongst institutions is largely due to its scalability and flexibility to handle a large variety of data types. With the increased take up rate, the need to support federated authentication and flexible authorization is becoming more and more evident. The main drivers are the need by end users to share data across institutional boundaries, and the ability to specify new and ...
متن کاملMiddleware for Secured Video-Conferencing
Video-conferencing over IP networks is rapidly becoming a popular application. Currently, there are two standards for signaling that are used in such applications. H.323 is the signaling standard from ITU-T (used by most commercial video-conferencing system) and SIP, which is an IETF approved standard for voice and video communications. In this paper, we present federated security mechanisms as...
متن کاملCross-domain authorization for federated virtual organizations using the myVocs collaboration environment
Complete List of Authors: Gemmill, Jill; Clemson University, Cyberinfrastructure Technology Integration; Clemson University, School of Computing Robinson, John-Paul; University of Alabama at Birmingham, Information Technology Scavo, Tom; National Center for Supercomputing Applications Bangalore, Purushotham; Univerity of Alabama at Birmingham, Computer and Information Sciences
متن کامل