2017
DOI: 10.1007/978-3-319-61176-1_4
|View full text |Cite
|
Sign up to set email alerts
|

Object-Tagged RBAC Model for the Hadoop Ecosystem

Abstract: Hadoop ecosystem provides a highly scalable, fault-tolerant and cost-effective platform for storing and analyzing variety of data formats. Apache Ranger and Apache Sentry are two predominant frameworks used to provide authorization capabilities in Hadoop ecosystem. In this paper we present a formal multi-layer access control model (called HeAC) for Hadoop ecosystem, as an academic-style abstraction of Ranger, Sentry and native Apache Hadoop access-control capabilities. We further extend HeAC base model to prov… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
17
0

Year Published

2019
2019
2022
2022

Publication Types

Select...
5
3

Relationship

1
7

Authors

Journals

citations
Cited by 27 publications
(17 citation statements)
references
References 34 publications
(38 reference statements)
0
17
0
Order By: Relevance
“…The access control requirements and privacy analysis of Hadoop frameworks have been addressed in the literature [5,27]. Recently, Gupta et al [18] and [19] Big data privacy issues are also well addressed, and novel solutions have been proposed in [27,33,34,35], in addition to an SSO framework for Hadoop services in [36]. Colombo et al conducted a comprehensive study of big data technologies, including access control requirements, state-of-the-art and future trends, in [37,5,21].…”
Section: Related Workmentioning
confidence: 99%
See 1 more Smart Citation
“…The access control requirements and privacy analysis of Hadoop frameworks have been addressed in the literature [5,27]. Recently, Gupta et al [18] and [19] Big data privacy issues are also well addressed, and novel solutions have been proposed in [27,33,34,35], in addition to an SSO framework for Hadoop services in [36]. Colombo et al conducted a comprehensive study of big data technologies, including access control requirements, state-of-the-art and future trends, in [37,5,21].…”
Section: Related Workmentioning
confidence: 99%
“…We have formally defined the federation supported access control model in Table 2. This model has been adapted from the object tagged RBAC model [19] for Hadoop, and introduces required components to demonstrate the federation. User Subject…”
Section: Formal Access Control Model Componentsmentioning
confidence: 99%
“…A recent work targeting access control enforcement within MapReduce systems is described in Gupta et al (2017). More precisely, Gupta et al (2017) introduces the foundations of an access control model, called HeAC, which formalizes the authorization model of Apache Ranger 6 and Apache Sentry 7 , as well as the native access control features of Hadoop. Apache Ranger and Apache Sentry represent state of the art technologies for the enforcement of fine grained access control in Hadoop ecosystems.…”
Section: Mapreduce Systemsmentioning
confidence: 99%
“…Authorization assignments are specified for operations and objects, possibly on the basis of object tags, namely attributes specifying properties, like sensitivity, content, or expiration date. Moreover, Gupta et al (2017) introduces the foundation of Object Tagged RBAC, an RBAC model which, while preserving RBAC role based permission assignments, introduces support for object attributes. A prototypical implementation of the model has been defined by introducing role support into Apache Ranger.…”
Section: Mapreduce Systemsmentioning
confidence: 99%
“…Since the authors of this scheme proposed only a conceptual model, the next step that they would like to do is to implement the actual model in the Hadoop Framework. In 2018, Gubta et al [Gupta, Patwa, and Sandhu (2017)] proposed a fine-grained Attribute-Based Access Control model (HeABAC), which satisfies the security and privacy necessities of multi-tenant Hadoop environment. The scheme is an extension to the existing Hadoop Access Control model (HeAC), which includes the authorization capabilities of core Hadoop (2.x), two important security projects, such as Apache Ranger (version 0.6), Sentry (version 1.7.0), and RBAC extension object-tagged rolebased access control (OT-RBAC) model [Wenrong, Yang and Luo (2013)], a previously proposed work done by the same authors.…”
Section: Framework For Access Control Big Datamentioning
confidence: 99%