Securing Workflows Using Microservices and Metagraphs - Université Polytechnique des Hauts-de-France Accéder directement au contenu
Article Dans Une Revue Electronics Année : 2021

Securing Workflows Using Microservices and Metagraphs

Résumé

Companies such as Netflix increasingly use the cloud to deploy their business processes. Those processes often involve partnerships with other companies, and can be modeled as workflows where the owner of the data at risk interacts with contractors to realize a sequence of tasks on the data to be secured. In this paper, we first show how those workflows can be deployed and enforced while preventing data exposure. Second, this paper provides a global framework to enable the verification of workflow policies. Following the principles of zero-trust, we develop an infrastructure using the isolation provided by a microservice architecture to enforce owner policy. We implement a workflow with our infrastructure in a publicly available proof of concept. This work allows us to verify that the specified policy is correctly enforced by testing the deployment for policy violations, and find the overhead cost of authorization to be reasonable for the benefits. In addition, this paper presents a way to verify policies using a suite of tools transforming and checking policies as metagraphs. It is evident from the results that our verification method is very efficient regarding the size of the policies. Overall, this infrastructure and the mechanisms that verify the policy is correctly enforced, and then correctly implemented, help us deploy workflows in the cloud securely.
Fichier principal
Vignette du fichier
electronics-10-03087-v2.pdf (1.23 Mo) Télécharger le fichier
Origine : Publication financée par une institution
Licence : CC BY - Paternité

Dates et versions

hal-03709704 , version 1 (30-06-2022)

Licence

Paternité

Identifiants

Citer

Loïc Miller, Pascal Mérindol, Antoine Gallais, Cristel Pelsser. Securing Workflows Using Microservices and Metagraphs. Electronics, 2021, 10 (24), pp.3087. ⟨10.3390/electronics10243087⟩. ⟨hal-03709704⟩
19 Consultations
111 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More