Cloud computing is significantly reshaping the computing industry built around core concepts such as virtualization, processing power, connectivity and elasticity to store and share IT resources via a broad network. It has emerged as the key technology that unleashes the potency of Big Data, Internet of Things, Mobile and Web Applications, and other related technologies, but it also comes with its challenges - such as governance, security, and privacy. This paper is focused on the security and privacy challenges of cloud computing with specific reference to user authentication and access management for cloud SaaS applications. The suggested model uses a framework that harnesses the stateless and secure nature of JWT for client authentication and session management. Furthermore, authorized access to protected cloud SaaS resources have been efficiently managed. Accordingly, a Policy Match Gate (PMG) component and a Policy Activity Monitor (PAM) component have been introduced. In addition, other subcomponents such as a Policy Validation Unit (PVU) and a Policy Proxy DB (PPDB) have also been established for optimized service delivery. A theoretical analysis of the proposed model portrays a system that is secure, lightweight and highly scalable for improved cloud resource security and management.
翻译:云计算正在大大改变围绕虚拟化、加工能力、连通性和弹性等核心概念建立的计算行业,通过广泛的网络储存和分享信息技术资源,已成为释放大数据、物联网、移动和网络应用及其他相关技术能力的关键技术,但也面临治理、安全和隐私等挑战。本文件侧重于云计算的安全性和隐私挑战,具体提及用户认证和访问管理,用于云层应用。建议的模型使用一个框架,利用JWT的无国籍和安全性,用于客户认证和会话管理。此外,已对授权获取受保护的云层资源进行了有效管理。因此,引入了政策匹配门(PMG)组件和政策活动监测(PAM)组件。此外,还建立了政策验证股(PVU)和政策普罗克西DB(PDB)等其他子组件,用于优化服务交付。对拟议模型进行了理论分析,描绘了一个安全、轻度和高度可扩展的系统,用于改进云层资源安全和管理。