<p>Secure data exchange across the distributed computing continuum is essential for decision-making processes. However, achieving this securely is challenging due to the heterogeneous nature of the continuum, where each infrastructure presents distinct requirements and capabilities in computing, storage, and energy. This paper presents Xook-Sec, a framework for building secure data-sharing systems within the computing continuum. Xook-Sec is grounded in three key concepts: Policy-as-Code (PaC), Infrastructure-as-Code (IaC), and architectural patterns. PaC enables organizations to integrate multiple security services with applications distributed across different infrastructures managed via IaC. Architectural patterns support the customization and optimization of security services. Xook-Sec enables organizations to define multiple data-sharing patterns, taking into account various security requirements and infrastructure characteristics. We implemented a Xook-Sec prototype and conducted case studies including sensitive medical and satellite imagery. Our evaluation shows that Xook-Sec is both flexible and efficient, outperforming comparable state-of-the-art solutions. Specifically, in direct comparisons with Jenkins and Nextflow, Xook-Sec achieves performance improvements of up to 50% and 40%, respectively.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Xook-Sec: A policy-as-code framework for secure data-sharing on the computing continuum

  • Catherine A. Torres-Charles,
  • Dante D. Sanchez-Gallegos,
  • J. L. Gonzalez-Compean,
  • Miguel Morales-Sandoval,
  • Jesus Carretero

摘要

Secure data exchange across the distributed computing continuum is essential for decision-making processes. However, achieving this securely is challenging due to the heterogeneous nature of the continuum, where each infrastructure presents distinct requirements and capabilities in computing, storage, and energy. This paper presents Xook-Sec, a framework for building secure data-sharing systems within the computing continuum. Xook-Sec is grounded in three key concepts: Policy-as-Code (PaC), Infrastructure-as-Code (IaC), and architectural patterns. PaC enables organizations to integrate multiple security services with applications distributed across different infrastructures managed via IaC. Architectural patterns support the customization and optimization of security services. Xook-Sec enables organizations to define multiple data-sharing patterns, taking into account various security requirements and infrastructure characteristics. We implemented a Xook-Sec prototype and conducted case studies including sensitive medical and satellite imagery. Our evaluation shows that Xook-Sec is both flexible and efficient, outperforming comparable state-of-the-art solutions. Specifically, in direct comparisons with Jenkins and Nextflow, Xook-Sec achieves performance improvements of up to 50% and 40%, respectively.