Multi-tenancy access control model for IaaS cloud

Wenchang Shi,Zhiyu Wang,Ying Huang
DOI: https://doi.org/10.13245/j.hust.160318
2016-01-01
Abstract:Aimed at the needs of data isolation and data sharing between tenants in the IaaS (infra-structure as a service)clouds,an access control model,the MTIAC (multi-tenancy IaaS access con-trol)model,was proposed.MTIAC focuses on three kinds of common access operations in the IaaS environment,which are hypervisor authorization,the allocation of resources to virtual machines,and the communication between virtual machines.The discretionary access control policies of MTIAC al-low administrators to define label sets and conflicting label sets,as well as to assign these labels to workloads.The mandatory access control policies of MTIAC assures that no conflicting workloads will run on the same host machine,while non-conflicting virtual machines can share data in a con-trolled way.MTIAC updates both subjects′and objects′relevant attributes after the authorized opera-tions have been successfully enforced,in order to achieve safe transitions of status.Finally,the trus-ted virtual datacenter (TVDc)technology example illustrates the availability of MTIAC.
What problem does this paper attempt to address?