Information flow control (IFC) is a well-understood mandatory access control methodology that can provide better cloud security than what is currently available. IFC models how information, like data, is allowed to flow between subjects like processes and objects like files in a system. Decentralized forms of IFC have been designed and implemented in academic research projects. This paper proposes IFC as a service (IFCaaS) for cloud security, where both cloud tenants and providers can agree on security policies in a way that does not require them to understand the details of the cloud software stack. IFCaaS would allow enforcement of security policies based on the data being protected.
Related topics: