toggle visibility Search & Display Options

Select All    Deselect All
 |   | 
Details
   print
  Record Links
Author (up) Arias-Cabarcos, P.; Almenárez-Mendoza, F.; Marín-López, A.; Díaz-Sánchez, D.; Sánchez-Guerrero, R. url  doi
openurl 
  Title A Metric-Based Approach to Assess Risk for ”On Cloud” Federated Identity Management Type Journal Article
  Year 2012 Publication Journal of Network and Systems Management Abbreviated Journal  
  Volume 20 Issue 4 Pages 513-533  
  Keywords Cloud computing, consequence, federation, risk assessment, SAML, servicioseguridad, Trust management  
  Abstract The cloud computing paradigm is set to become the next explosive revolution on the Internet, but its adoption is still hindered by security problems. One of the fundamental issues is the need for better access control and identity management systems. In this context, Federated Identity Management (FIM) is identified by researchers and experts as an important security enabler, since it will play a vital role in allowing the global scalability that is required for the successful implantation of cloud technologies. However, current FIM frameworks are limited by the complexity of the underlying trust models that need to be put in place before inter-domain cooperation. Thus, the establishment of dynamic federations between the different cloud actors is still a major research challenge that remains unsolved. Here we show that risk evaluation must be considered as a key enabler in evidence-based trust management to foster collaboration between cloud providers that belong to unknown administrative domains in a secure manner. In this paper, we analyze the Federated Identity Management process and propose a taxonomy that helps in the classification of the involved risks in order to mitigate vulnerabilities and threats when decisions about collaboration are made. Moreover, a set of new metrics is defined to allow a novel form of risk quantification in these environments. Other contributions of the paper include the definition of a generic hierarchical risk aggregation system, and a descriptive use-case where the risk computation framework is applied to enhance cloud-based service provisioning.  
  Address  
  Corporate Author Thesis  
  Publisher Place of Publication Editor  
  Language Summary Language Original Title  
  Series Editor Series Title Abbreviated Series Title  
  Series Volume Series Issue Edition  
  ISSN 1573-7705 ISBN Medium  
  Area Expedition Conference  
  Notes Approved no  
  Call Number UC3M @ josealga @ ariascabarcos001 Serial 89  
Permanent link to this record
Select All    Deselect All
 |   | 
Details
   print

Save Citations:
Export Records: