| By Business Wire | Article Rating: |
|
| January 8, 2013 10:24 AM EST | Reads: |
483 |
The OASIS international open standards consortium has launched the Cloud Authorization (CloudAuthZ) Technical Committee, a project to develop enhanced models for managing authorizations and entitlements in SaaS, PaaS, and IaaS contexts. The goal of CloudAuthZ is to provide greater control of the way cloud computing resources are used. It will enable contextual information (such as where users are, what they are doing, which device they are using, etc.) to inform authorization decisions.
CloudAuthZ will define configurations of existing standards, such as OAuth, SCIM, and XACML, to provide mechanisms for enabling the delivery of cloud contextual attributes to Policy Enforcement Points. This will allow cloud infrastructures to provide--in real time--a subset of contextual entitlements sets that can be used to authorize or deny a Consumer’s use of a specific resource.
Bank of America’s Radu Marian co-chairs the OASIS CloudAuthZ Technical Committee. He explained, “CloudAuthZ will reduce the need for customized interactions between customer and vendor systems and so decrease the overhead of supporting authorization and entitlement. It will also enhance portability across multiple systems.”
“CloudAuthZ profiles will allow cloud providers to enforce authorization policies in the most optimal way possible,” added Anil Saldhana of Red Hat, who also co-chairs the OASIS group.
Contributions of relevant use cases for CloudAuthZ are welcome. New members are encouraged to join the Technical Committee at any time. Archives of the work are accessible to both members and non-members, and OASIS invites public review and comment on the work.
Support for CloudAuthZ
Red Hat
"Security and authorization are fundamental
challenges that need resolving in any system and cloud is no different.
As a cloud leader, Red Hat is fully committed to addressing these
problems in standards and open source. We are happy to support the
creation of the CloudAuthZ Technical Committee and will be working to
help it succeed."
--Mark Little, vice president,
Engineering, Middleware Engineering, Red Hat
SailPoint
"Providing a flexible, extensible and open
authorization model is key to the deployment of high-value applications
in the cloud. The CloudAuthZ Committee will help profile the flow and
use of key entitlement giving attributes. Standardizing this process
will greatly enhance the governance and compliance process for secure
reliable cloud-based applications."
-- Darran Rolls, CTO,
SailPoint
ViewDS
"ViewDS is pleased to participate on the OASIS
CloudAuthZ Technical Committee. We see the task of standardizing the
management and enforcement of access to cloud resources, especially for
mobile clients, as critical to the evolution of corporate computing. We
look forward to applying our real-world experience with our Access
Sentinel XACML authorization technology to this effort."
--Gil
Kirkpatrick, CTO, ViewDS Identity Solutions
Additional information:
OASIS CloudAuthZ Technical Committee
http://www.oasis-open.org/committees/cloudauthz/
About OASIS:
OASIS (Organization for the Advancement of Structured Information Standards) is a not-for-profit, international consortium that drives the development, convergence and adoption of open standards for the global information society. OASIS promotes industry consensus and produces worldwide standards for cloud computing, security, privacy, content technologies, business transactions, the Smart Grid, emergency management, and other applications. OASIS open standards offer the potential to lower cost, stimulate innovation, grow global markets, and protect the right of free choice of technology. OASIS members broadly represent the marketplace of public and private sector technology leaders, users, and influencers. The consortium has more than 5,000 participants representing over 600 organizations and individual members in 100 countries.
Published January 8, 2013 Reads 483
Copyright © 2013 SYS-CON Media, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
More Stories By Business Wire
Copyright © 2009 Business Wire. All rights reserved. Republication or redistribution of Business Wire content is expressly prohibited without the prior written consent of Business Wire. Business Wire shall not be liable for any errors or delays in the content, or for any actions taken in reliance thereon.
- Cloud People: A Who's Who of Cloud Computing
- Cloud Expo New York: Cloud Is Changing the Economics of Business
- Windows Azure IaaS Reaches General Availability
- Portable Experimenter’s Platform, Powered by Raspberry Pi
- Cloudant to Exhibit at Cloud Expo & Big Data Expo New York
- Learn How To Use Google Apps Script
- Cloud Computing Is Simplifying Things
- Cloud Expo New York: Basics of SSD Technology and Its Use in Cloud
- Cloud Expo New York: The Big Challenge of Big Data & Hadoop Integration
- Overview of the OpenStack Cloud
- Session Topics: 12th Cloud Expo / Cloud Expo New York
- The Flexible Cloud
- Cloud People: A Who's Who of Cloud Computing
- Cloud Expo New York: Cloud Is Changing the Economics of Business
- Cloud Expo New York: How to Use Google Apps Script
- Windows Azure IaaS Reaches General Availability
- Rackspace Hosting Named “Platinum Plus Sponsor” of Cloud Expo New York
- Portable Experimenter’s Platform, Powered by Raspberry Pi
- Small Cancers, Big Data, and a Life Examined
- SUSE Receives Common Criteria Security Certifications
- Basho Announces Open Source Riak CS and General Availability of Riak CS Enterprise v1.3
- Cloudant to Exhibit at Cloud Expo & Big Data Expo New York
- Learn How To Use Google Apps Script
- VMware Sets Up New Hybrid Cloud Unit
- After Ubuntu, Windows Looks Increasingly Bad, Increasingly Archaic, Increasingly Unfriendly
- SCO CEO Posts Open Letter to the Open Source Community
- Simula Labs Launches Hosted Delivery Platform To Enable Enterprise Open Source Adoption
- Where Are RIA Technologies Headed in 2008?
- Source Claims SCO Will Sue Google
- How Open Is "Open"? – Industry Luminaries Join the Debate
- Latest SCO News is Plain Weird
- SCO Claims Linux Lifted ELF
- IBM Tells SCO Court It Can't Find AIX-on-Power Code
- Developing an Application Using the Eclipse BIRT Report Engine API
- Should RIM BlackBerries Be Rented?
- Flashback: Investing in 'Professional Open Source' - Exclusive 2004 Interview with David Skok, Matrix Partners























