• Home
  • Search
  • Securing Access to Cloud Computing for Critical Infrastructure
  • Cite Icon2
  • https://doi.org/10.24377/ljmu.t.00004453Copy DOI Icon

Securing Access to Cloud Computing for Critical Infrastructure

Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

Cloud computing offers cost effective services on-demand which encourage critical infrastructure providers to consider migrating to the cloud. Critical infrastructures are considered as a backbone of modern societies such as power plants and water. Information in cloud computing is likely to be shared among different entities, which could have various degrees of sensitivity. This requires robust isolation and access control mechanisms. Although various access control models and policies have been developed, they cannot fulfil requirements for a cloud based access control system. The reason is that cloud computing has a diverse sets of security requirements and unique security challenges such as multi-tenant and heterogeneity of security policies, rules and domains. This thesis provides a detailed study of cloud computing security challenges and threats, which were used to identify security requirements for various critical infrastructure providers. We found that an access control system is a crucial security requirement for the surveyed critical infrastructure providers. Furthermore, the requirement analysis was used to propose a new criteria to evaluate access control systems for cloud computing. Moreover, this work presents a new cloud based access control model to meet the identified cloud access control requirements. The model does not only ensure the secure sharing of resources among potential untrusted tenants, but also has the capacity to support different access permissions for the same cloud user. Our focused in the proposed model is the lack of data isolation in lower levels (CPU caches), which could lead to bypass access control models to gain some sensitive information by using cache side-channel attacks. Therefore, the thesis investigates various real attack scenarios and the gaps in existing mitigation approaches. It presents a new Prime and Probe cache side-channel attack, which can give detailed information about addresses accessed by a virtual machine with no need for any information about cache sets accessed by the virtual machine. The design, implementation and evaluation of a proposed solution preventing cache side-channel attacks are also presented in the thesis. It is a new lightweight solution, which introduces very low overhead (less than 15,000 CPU cycles). It can be applied in any operating system and prevents cache side-channel attacks in cloud computing. The thesis also presents a new detecting cache side-channel attacks solution. It focuses on the infrastructure used to host cloud computing tenants by counting cache misses caused by a virtual machine. The detection solutions has 0% false negative and 15% false positive.

Similar Papers
  • Book Chapter
  • Citations4

Chapter 23 - Policies, Access Control, and Formal Methods

  • Jan 01, 2012
  • Handbook on Securing Cyber-Physical Critical Infrastructure
  • Elisa Bertino
  • Research Article
  • Citations5

A Combination of Semantic and Attribute based Access Control Model for Virtual Organizations

  • Aug 05, 2015
  • Isecure.
  • Morteza Amini +1
  • Supplementary Content

A Governance Method for Overcoming Cloud Computing Barriers with Architectural Requirements: Mixed Method Study Based on the Government Cloud in Saudi Arabia

  • May 19, 2020
  • Griffith Research Online (Griffith University, Queensland, Australia)
  • Bader Alghamdi
  • Research Article
  • Citations85

MTBAC: A mutual trust based access control model in Cloud computing

  • Apr 01, 2014
  • China Communications
  • Guoyuan Lin +3
  • Research Article
  • Citations11

Towards more pro-active access control in computer systems and networks

  • Dec 25, 2014
  • Computers & Security
  • Yixuan Zhang +4
  • Research Article

Applying pi-Calculus to Practice: An Example of a Unified Security Mechanism

  • Nov 06, 2003
  • BRICS Report Series
  • Jörg Abendroth
  • PDF
  • Research Article
  • Citations2

Service-Based Hybrid Access Control Technology with Priority Level for the Internet of Vehicles under the Cloud Architecture

  • Dec 03, 2021
  • Security and Communication Networks
  • Pengshou Xie +5
  • Research Article

Reducing the Digital Divide by using Cloud Computing – A focus on Education.

  • Jan 01, 2012
  • 施力歐
  • Research Article
  • Citations3

Fine-Grained Access Control via XACML Policy Optimization in Cloud Computing

  • Nov 01, 2015
  • International Journal of Software Engineering and Knowledge Engineering
  • Xin Pei +2
  • Research Article
  • Citations5

A uniform approach for access control and business models with explicit rule realization

  • Feb 11, 2015
  • International Journal of Information Security
  • Vahid R Karimi +2
  • Research Article

A Review on Security Issues in Cloud Computing

  • Jan 01, 2015
  • International Journal of Advanced Research in Computer Science
  • Harmanjeet Kaur +1
  • Research Article
  • Citations1

Securing Cloud Data: An Enhanced Approach through Attribute-Based Access Control Mechanism

  • Oct 30, 2023
  • International Journal on Recent and Innovation Trends in Computing and Communication
  • Et Al K Raja
  • Conference Article
  • Citations4

Verification of Secure Inter-operation Properties in Multi-domain RBAC Systems

  • Jun 01, 2013
  • Antonios Gouglidis +2
  • Conference Article
  • Citations23

Comparative Analysis of Access Control Systems on Cloud

  • Aug 01, 2012
  • Um-E-Ghazia +2
  • Conference Article
  • Citations2

An Enhanced Access Control Model Based on Trusted Computing

  • Jan 01, 2016
  • Kuanmin Hu +2
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.