loading
Papers Papers/2022 Papers Papers/2022

Research.Publish.Connect.

Paper

Paper Unlock

Author: HongQian Karen Lu

Affiliation: Gemalto and Inc., United States

Keyword(s): Access control, client application authentication, cloud API, key management, smart cards.

Abstract: A common method for accessing and managing cloud computing resources is through an Application Programming Interface (API). Each API request from an application must include a client authentication to the cloud service, which proves the possession of a secret key. Securing such keys is critical to the confidentiality, integrity, and availability of the data and services hosted in the cloud. Currently users manually handle these keys; a process that is neither secure nor user-friendly. Where to store the keys and how to access them are still security challenges especially for those applications that reside in the cloud themselves. Furthermore, keys are in clear text at least in a computer’s memory. Attackers can find ways to recover them. This paper presents a solution to these problems by using portable security devices. The device securely exchanges keys with the cloud serve, securely stores the keys, and performs cryptographic computations using these keys for the client authentic ation. The user must have the device and authenticate to it in order use it. The solution enables a two-factor hierarchical security protection of the cloud computing resources. It not only enhances the security but also improves the usability. (More)

CC BY-NC-ND 4.0

Sign In Guest: Register as new SciTePress user now for free.

Sign In SciTePress user: please login.

PDF ImageMy Papers

You are not signed in, therefore limits apply to your IP address 44.192.53.34

In the current month:
Recent papers: 100 available of 100 total
2+ years older papers: 200 available of 200 total

Paper citation in several formats:
Karen Lu, H. (2011). Accessing Cloud through API in a More Secure and Usable Way . In Proceedings of the 8th International Workshop on Security in Information Systems (ICEIS 2011) - WOSIS; ISBN 978-989-8425-61-4, SciTePress, pages 25-38. DOI: 10.5220/0003559100250038

@conference{wosis11,
author={HongQian {Karen Lu}.},
title={Accessing Cloud through API in a More Secure and Usable Way },
booktitle={Proceedings of the 8th International Workshop on Security in Information Systems (ICEIS 2011) - WOSIS},
year={2011},
pages={25-38},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0003559100250038},
isbn={978-989-8425-61-4},
}

TY - CONF

JO - Proceedings of the 8th International Workshop on Security in Information Systems (ICEIS 2011) - WOSIS
TI - Accessing Cloud through API in a More Secure and Usable Way
SN - 978-989-8425-61-4
AU - Karen Lu, H.
PY - 2011
SP - 25
EP - 38
DO - 10.5220/0003559100250038
PB - SciTePress