Swinburne
Browse

TOSSMA: A tenant-oriented SaaS security management architecture

Download (360.11 kB)
conference contribution
posted on 2024-07-09, 13:49 authored by Mohamed Abdelrazek, John Grundy, Amani S. Ibrahim
Multi-tenancy helps service providers to save costs, improve resource utilization, and reduce service customization and maintenance time by sharing of resources and services. On the other hand, supporting multi-tenancy adds more complexity to the shared application's required capabilities. Security is a key requirement that must be addressed when engineering new SaaS applications or when re-engineering existing applications to support multi-tenancy. Traditional security (re)engineering approaches do not fit with the multitenancy application model where tenants and their security requirements emerge after the system was first developed. Enabling, runtime, adaptable and tenant-oriented application security customization on single service instance is a key challenging security goal in multi-tenant application engineering. In this paper we introduce TOSSMA, a Tenant- Oriented SaaS Security Management Architecture. TOSSMA allows service providers to enable their tenants in defining, customizing and enforcing their security requirements without having to go back to application developers for maintenance or security customizations. TOSSMA supports security management for both new and existing systems. Service providers are not required to write security integration code to use a specific security platform or mechanism. In this paper, we describe details of our approach and architecture, our prototype implementation of TOSSMA, give a usage example of securing a multi-tenant SaaS, and discuss our evaluation experiments of TOSSMA.

History

Available versions

PDF (Accepted manuscript)

ISBN

9780769547558

Journal title

Proceedings - 2012 IEEE 5th International Conference on Cloud Computing, CLOUD 2012

Conference name

2012 IEEE 5th International Conference on Cloud Computing, CLOUD 2012

Location

Honolulu, HI

Start date

2012-06-24

End date

2012-06-29

Pagination

7 pp

Publisher

IEEE

Copyright statement

Copyright © 2012 IEEE. The accepted manuscript is reproduced in accordance with the copyright policy of the publisher. Personal use of this material is permitted. However, permission to reprint/republish this material for advertising or promotional purposes or for creating new collective works for resale or redistribution to servers or lists, or to reuse any copyrighted component of this work in other works must be obtained from the IEEE.

Language

eng

Usage metrics

    Publications

    Categories

    No categories selected

    Keywords

    Exports

    RefWorks
    BibTeX
    Ref. manager
    Endnote
    DataCite
    NLM
    DC