Enhancing Security in cloud environments with acces control mechanisms

This thesis explores the enhancement of security in cloud environments through advanced access control mechanisms. With the increasing adoption of cloud computing, ensuring robust security measures has become paramount. The study focuses on implementing Role-Based Access Control (RBAC) and Attribute...

ver descrição completa

Detalhes bibliográficos
Autor: Niguidula Enriquez, Jose
Tipo de documento: dissertação
Data de publicação:2024
País:España
Recursos:Universitat Politècnica de Catalunya (UPC)
Repositório:UPCommons. Portal del coneixement obert de la UPC
Idioma:inglês
OAI Identifier:oai:upcommons.upc.edu:2117/416407
Acesso em linha:https://hdl.handle.net/2117/416407
Access Level:Acceso aberto
Palavra-chave:Computer security
Cloud computing
Acess Control
ABAC
RBAC
AWS
GCP
Azure
IAM
Authorization
Control de Acceso
Seguretat informàtica
Computació en núvol
Àrees temàtiques de la UPC::Informàtica::Seguretat informàtica
Descrição
Resumo:This thesis explores the enhancement of security in cloud environments through advanced access control mechanisms. With the increasing adoption of cloud computing, ensuring robust security measures has become paramount. The study focuses on implementing Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC) to provide flexible and scalable security solutions. Initially, the research aimed to present a detailed comparative of access control policies across major public cloud providers. As the research progressed, the inherent complexity and variability of these policies became evident, thus the thesis focus shifted to proposing a unified approach in defining access control mechanisms. After researching available platforms for access control, the thesis opted on using the Open Policy Agent (OPA). OPA is a Cloud Native Computing Foundation (CNCF) project, which offers a unified model for access control policy enforcement that is highly scalable and flexible. The thesis also evaluates OPA's effectiveness compared to other access control mechanisms, such as Google's Zanzibar and Topaz, in enhancing cloud security. The thesis? project implementation demonstrates how OPA's policy-as-code approach can simplify policy management and improve authorization processes in multi-cloud environments. By leveraging OPA, this study presents a unified access control framework that can adapt to the dynamic needs of modern cloud infrastructures, thereby enhancing security and operational efficiency.