HT-RBAC: A Design of Role-based Access Control Model for Microservice Security Manager

Chittipat Pasomsup, Yachai Limpiyakorn · 2021

For transitioning to a decentralized system, a microservices platform has become popular in today software development due to its lightweight mechanisms. However, increasing the number of services results in a challenge to maintain the security of access control. The more attack surfaces can bring security and privacy risk via sensitive data. Therefore, a chain of trust domains was introduced to solve this problem. The extended Role-Based Access Control model (Hierarchical Trust RBAC: HT-RBAC) for microservice security managers is proposed for leveraging threats of unauthorized access to sensitive information and identity verification across all environments in application container solutions. This paper proposes using an HT-RBAC to authenticate, authorize, and identify user’s access control via API-Gateway. A prototype system integrated with OAuth 2.0 authentication server is implemented for empirical study. The results report that the approach provides faster and more flexible access to information in addition to improving incident response time.

Read the paper · More papers on PaperTik