Repository logo
 

Data-centric access control for cloud computing

Accepted version
Peer-reviewed

Repository DOI


Type

Conference Object

Change log

Authors

Pasquier, T 
Bacon, J 
Eyers, D 

Abstract

© 2016 ACM. The usual approach to security for cloud-hosted applications is strong separation. However, it is often the case that the same data is used by different applications, particularly given the increase in data-driven (big data' and IoT) applications. We argue that access control for the cloud should no longer be application-specific but should be data-centric, associated with the data that can ow between applications. Indeed, the data may originate outside cloud services from diverse sources such as medical monitoring, environmental sensing etc. Information Flow Control (IFC) potentially offers data-centric, system-wide data access control. It has been shown that IFC can be provided at operating system level as part of a PaaS offering, with an acceptable overhead. In this paper we consider how IFC can be integrated with application-specific access control, transparently from application developers, while building from simple IFC primitives, access control policies that align with the data management obligations of cloud providers and tenants.

Description

Keywords

information flow control, cloud computing, data protection

Journal Title

SACMAT '16: Proceedings of the 21st ACM on Symposium on Access Control Models and Technologies

Conference Name

Symposium on Access Control Models and Technologies

Journal ISSN

Volume Title

06-08-June-2016

Publisher

ACM
Sponsorship
Engineering and Physical Sciences Research Council (EP/K011510/1)
This work was supported by the UK EPSRC grant EP/ K011510 CloudSafetyNet. We acknowledge the support of Microsoft through the Microsoft Cloud Computing Research Centre.