信息网络安全 ›› 2016, Vol. 16 ›› Issue (3): 53-58.doi: 10.3969/j.issn.1671-1122.2016.03.009

• 技术研究 • 上一篇    下一篇

针对内部威胁的可控云计算关键技术研究与实现

向林波, 刘川意   

  1. 北京邮电大学可信分布式计算与服务教育部重点实验室,北京 100876
  • 收稿日期:2016-01-20 出版日期:2016-03-25
  • 通讯作者: 向林波 396397826@qq.com
  • 作者简介:向林波(1992--),男,湖南,硕士研究生,主要研究方向为云计算与云安全;刘川意(1982-),男,四川,副教授,博士,主要研究方向为云计算与云安全,数据安全与数据保护.
  • 基金资助:
    国家高技术研究发展计划(国家863计划)[2015AA016001]

Key Technology Research and Implement on Insider Threat for Controlled Cloud Computing

XIANG Linbo, LIU Chuanyi   

  1. Key Laboratory of Trustworthy Distributed Computing and Service, Ministry of Education, Beijing University of Posts and Telecommunications, Beijing 100876, China
  • Received:2016-01-20 Online:2016-03-25

摘要: 云计算在学术界和工业界获得了广泛关注,但是云计算中的数据安全和隐私保护问题阻碍了云计算的发展.文章从开源云计算框架OpenStack出发,分析其运维方式,提出使用API代理及访问控制的方法实现对云平台的内部管控,防止用户数据受到来自云平台内部的威胁.实验结果表明,文章提出的方法在满足云平台正常运维需求的基础上,实现了对云管理员的权限划分,并且能够拦截恶意和非法的访问请求.

关键词: 云计算, 可控云, 内部威胁, API代理, 访问控制

Abstract: Cloud computing has generated significant interest in both academia and industry, but the data security and privacy problem is hindering the development of cloud computing. Originated from the OpenStack open source cloud computing framework, this paper analyzes its operation and maintenance mode, and proposes using API proxy and access control to achieve internal controls of cloud platform and protect user data from insider threat in cloud platform. Experiment results show that the method in this article, which can achieve the basic need of cloud platform operation maintenance, implements the division of authority to the cloud administrator and can block malicious and illegal access requests.

Key words: cloud computing, controlled cloud, insider threat, API proxy, access control

中图分类号: