Español English Contacte con nosotros http://www.uc3m.es/portal/page/portal/biblioteca
DSpace e-Archivo

Archivo Abierto Institucional de la Universidad Carlos III de Madrid > Investigación > Departamentos > Departamento de Ingeniería Telemática > Grupo de Aplicaciones y Servicios Telemáticos (GAST) > DIT - GAST - Artículos de Revistas >

Please use this identifier to cite or link to this item: http://hdl.handle.net/10016/15315

Files in This Item:
metric-based_JNSM_2012_ps.pdf856,37 kBAdobe PDFformato pdf
Title: A metric-based approach to assess risk for "on cloud" federated identity management
Author(s): Arias Cabarcos, Patricia
Almenárez, Florina
Marín-López, Andrés
Díaz-Sánchez, Daniel
Sánchez-Guerrero, Rosa
Publisher: Springer
Issued date: 2012
Citation: Special Issue on Cloud Computing, Networking, and Service (CCNS) Management. Journal of Network and Systems Management, 4 July 2012 (online)
URI: http://hdl.handle.net/10016/15315
ISSN: 1064-7570 (print)
1573-7705 (online)
DOI: 10.1007/s10922-012-9244-2
Abstract: The cloud computing paradigm is set to become the next explosive revolution on the Internet, but its adoption is still hindered by security problems. One of the fundamental issues is the need for better access control and identity management systems. In this context, Federated Identity Management (FIM) is identified by researchers and experts as an important security enabler, since it will play a vital role in allowing the global scalability that is required for the successful implantation of cloud technologies. However, current FIM frameworks are limited by the complexity of the underlying trust models that need to be put in place before inter-domain cooperation. Thus, the establishment of dynamic federations between the different cloud actors is still a major research challenge that remains unsolved. Here we show that risk evaluation must be considered as a key enabler in evidencebased trust management to foster collaboration between cloud providers that belong to unknown administrative domains in a secure manner. In this paper, we analyze the Federated Identity Management process and propose a taxonomy that helps in the classification of the involved risks in order to mitigate vulnerabilities and threats when decisions about collaboration are made. Moreover, a set of new metrics is defined to allow a novel form of risk quantification in these environments. Other contributions of the paper include the definition of a generic hierarchical risk aggregation system, and a descriptive use-case where the risk computation framework is applied to enhance cloud-based service provisioning.
Sponsor: This work was supported in part by the Spanish Ministry of Science and Innovation under the project CONSEQUENCE (TEC2010-20572-C02-01).
Publisher version: http://dx.doi.org/10.1007/s10922-012-9244-2
Keywords: Trust management
Cloud Computing
Risk assessment metrics
SAML
Federation
Rights: © Springer
Appears in Collections:DIT - GAST - Artículos de Revistas

Refworks Export

SFX Query

Items in E-Archivo are protected by copyright, with all rights reserved, unless otherwise indicated.

 

Valid XHTML 1.0! © Universidad Carlos III de Madrid - Software DSpace - Terms of use - Feedback