PHD thesis/doctoral suggestions ...

Morvan Müller muller.md74 at gmail.com
Mon Jul 30 00:06:04 EDT 2012


Hello list,

I´m Brazilian,I am doing research in various areas of cloud, focusing
on security, looking for challenges to define a PHD thesis/doctoral
(must be innovative and validated through implementation or
simulation).
As you are experts and know what the biggest challenges today in the
cloud, can easily score specific questions that would give a thesis. I
Would be very grateful if you can help me with ideas.
For example:
a)There are open challenges in shibboleth framewwork in "Federated
security accross clouds"? Like, developing a user centric access
control where user requests to service providers are bundled with
their identity and entitlement information?
b) Clustering implementation (distributed services) of the services:
Shibboleth Identity provider (IdP), Service provider (SP) or WAYF
(where are you from)?
c) Other aspects
If I have a specific aspect to give a little scientific contribution,
it can be a thesys. So I can specify and implement this aspect to
contribute with your project.


Some points:
In recent months I have focused on the IAM (indentity and access
management) area:
1) IETF drafts proposed SCIM as a standard:
"draft-scim-core-schema-00.txt" and "draft-scim-api-00.txt". SCIM
security are resolved with HTTPS (scim-api-00 suggests TLS v1.2).
2) "Federated security accross clouds" is listed as an open challenge
by http://cloud-standards.org/wiki/index.php?title=Cloud_standards_overview
 list
3) CSA, Cloud Security Alliance. “Defined Categories of Service 2011”.
26 out. 2011. https://cloudsecurityalliance.org/wp-content/uploads/2011/09/SecaaS_V1_0.pdf.
Defines as open challenges in IAM area:
a)  Developing a user centric access control where user requests to
service providers are bundled with their identity and entitlement
information
b)  Delegation of authorizations/entitlements
c)  Dynamically scale up and down; scale to hundreds of millions of
transactions for millions of identities and thousands of connections
in a reasonable time.
d)  Privilege escalation

Thanks,
Morvan.


More information about the dev mailing list