|
With the Internet application technology continues to mature, the traditional software industry is undergoing tremendous changes, such as cloud , SaaS concepts continue to emerge, and get more and more attention and recognition. To sum up, these new concepts and techniques are based on a multi-tenant model as its core architecture . Relative ten traditional software , multi-tenant applications, especially single-instance multi-tenant applications can significantly reduce software costs and achieve economies of scale, has obvious advantages and broad prospects for development , but also on system security put forward new requirements. In the traditional security technologies and multi-tenant architecture , based on analysis , this paper discusses how to build from a security point of view multi-tenant applications , namely multi-tenant applications for storage security , transmission security and access control two main security issues discussed . First, the mode for multi-tenant storage security , this paper discusses the application of multi-tenant data isolation strategy to study how the field isolation and data encryption means to further protect the data storage. Secondly, the analysis of the multi-tenant transmission security requirements , the introduction of WS-Security specification , examples of how the XML Encryption and XML Signature , based on the data to ensure that businesses and service providers in a safe and reliable transport between and combines PKI and IBC two kinds of key system characteristics , we propose a model for more than a dozen tenants key system . Second, for the access control problem, access control model analysis and study, and ARBAC97 as the basis for design, through hierarchical management role model for enterprises to provide customizable access control policy.
|