论文标题
Capodaz:使用微服务的集装箱授权和政策驱动的体系结构
CAPODAZ: A Containerised Authorisation and Policy-driven Architecture using Microservices
论文作者
论文摘要
微服务架构方法在敏捷应用的开发和复杂解决方案的交付方面具有重要的好处。但是,要以可验证和无状态的方式传达信息并共享服务之间的数据,需要启用适当的访问控制方法和授权。在本文中,我们研究了使用基于混合云的基础架构和物联网(IoT)服务的现实世界对机器(M2M)场景的独立细粒度微服务的使用。我们还对促进涉及实体之间的消息交换的身份验证流进行建模,并使用微服务范式提出了一个容器化的授权和政策驱动的架构(CAPODAZ)。拟议的架构实现了基于政策的管理框架,并将其集成到有关云iot智能运输服务的持续工作中。对于深入的定量评估,我们对用户人群的多个分布进行了处理,并根据其他类似的微服务评估了所提出的体系结构。基于实验数据的数值结果表明,在延迟,吞吐量和成功的请求方面,性能优势存在很大的优势。
The microservices architectural approach has important benefits regarding the agile applications' development and the delivery of complex solutions. However, to convey the information and share the data amongst services in a verifiable and stateless way, there is a need to enable appropriate access control methods and authorisations. In this paper, we study the use of policy-driven authorisations with independent fine-grained microservices in the case of a real-world machine-to-machine (M2M) scenario using a hybrid cloud-based infrastructure and Internet of Things (IoT) services. We also model the authentication flows which facilitate the message exchanges between the involved entities, and we propose a containerised authorisation and policy-driven architecture (CAPODAZ) using the microservices paradigm. The proposed architecture implements a policy-based management framework and integrates in an on-going work regarding a Cloud-IoT intelligent transportation service. For the in-depth quantitative evaluation, we treat multiple distributions of users' populations and assess the proposed architecture against other similar microservices. The numerical results based on the experimental data show that there exists significant performance preponderance in terms of latency, throughput and successful requests.