Information-Flow Control for Building Security and Privacy Preserving Hybrid Clouds

Rudrapatna K. Shyamasundar, N. V. Narendra Kumar, Muttukrishnan Rajarajan · 2016

A hybrid cloud is a cloud computing environment in which an organization provides and manages some internal resources (private cloud) while the other resources are provisioned externally (public cloud). Rapid deployment of hybrid clouds for utility, cost, effectiveness and flexibility has made it necessary to assure the security and privacy of hybrid clouds as it transcends different domains. Further, successful hybrid cloud implementation requires a well-structured architecture supporting the functionalities of both private and public clouds and the seamless transitions between them. One of the challenges in a hybrid cloud is securing resource access, in particular, enforcing that the owner's policy never gets violated even when the data gets consumed and processed in multiple domains. Existing mechanisms for achieving this, including industry standards such as XACML, SAML, and OAuth, are vulnerable to indirect information leaks as they do not keep track of information flow. The Readers-Writers Flow Model (RWFM) is a novel security model with an intuitive security policy that tracks and controls the flow of information in a decentralized system. In this paper, we present an approach to building a hybrid cloud that preserves the given security and privacy policy by integrating an RWFM security module into a cloud service manager. An advantage of RWFM is that it provides a uniform solution for securing various kinds of hybrid cloud architectures ranging from the simple pairwise federation to the complex interclouds, and supporting varying degrees of flexibility in workload placement ranging from a simple static placement to fully dynamic migration. Further, RWFM framework is forensic-ready by design, because the labels of data and services readily provide the necessary forensic information.

Read the paper · More papers on PaperTik