Resource usage policy expression and enforcement in grid computing

Jun Feng, G. Wasson, M. Humphrey
{"title":"Resource usage policy expression and enforcement in grid computing","authors":"Jun Feng, G. Wasson, M. Humphrey","doi":"10.1109/GRID.2007.4354117","DOIUrl":null,"url":null,"abstract":"To date, not enough attention has been paid to issues surrounding the description and enforcement of policies for controlling grid resources. These policies define the permitted or desired usage scenario(s) allowed by resource providers, virtual organizations, or even the governing body for an entire grid. Most existing Grid systems have either \"in-spirit\" usage policies with no actual enforcement (e.g., all resource providers are assumed to contribute in kind), or have implicit resource usage policies whose intent can only be manifested by examining the ad-hoc policy enforcement. Moreover, systems that do define some resource usage policies typically consider only CPU resources, without mentioning other grid resources such as disk and bandwidth. Unless sufficient resource usage policies and enforcement mechanisms are created, resource providers will be increasingly reluctant to participate in grids out of fear that their local resources will be overrun. In this paper, we identify the requirements for a resource usage policy language, and then propose an event-centric model by which to implement these policies. We describe the language structure, its implementation on top of the XML access control language XACML and a policy service that processes the language. Because decisions based on this type of policy typically require information from outside the security context of a single grid request, we extend XACML for general timer-based and event-centric processing necessary to enforce such Grid resource usage policies. We evaluate our prototype implementation on a grid consisting of three data repositories by showing that a usage policy-controlled grid environment can be achieved with only minimal overhead.","PeriodicalId":304508,"journal":{"name":"2007 8th IEEE/ACM International Conference on Grid Computing","volume":"17 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2007-09-19","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"25","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2007 8th IEEE/ACM International Conference on Grid Computing","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/GRID.2007.4354117","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 25

Abstract

To date, not enough attention has been paid to issues surrounding the description and enforcement of policies for controlling grid resources. These policies define the permitted or desired usage scenario(s) allowed by resource providers, virtual organizations, or even the governing body for an entire grid. Most existing Grid systems have either "in-spirit" usage policies with no actual enforcement (e.g., all resource providers are assumed to contribute in kind), or have implicit resource usage policies whose intent can only be manifested by examining the ad-hoc policy enforcement. Moreover, systems that do define some resource usage policies typically consider only CPU resources, without mentioning other grid resources such as disk and bandwidth. Unless sufficient resource usage policies and enforcement mechanisms are created, resource providers will be increasingly reluctant to participate in grids out of fear that their local resources will be overrun. In this paper, we identify the requirements for a resource usage policy language, and then propose an event-centric model by which to implement these policies. We describe the language structure, its implementation on top of the XML access control language XACML and a policy service that processes the language. Because decisions based on this type of policy typically require information from outside the security context of a single grid request, we extend XACML for general timer-based and event-centric processing necessary to enforce such Grid resource usage policies. We evaluate our prototype implementation on a grid consisting of three data repositories by showing that a usage policy-controlled grid environment can be achieved with only minimal overhead.
网格计算中资源使用策略的表达与实施
到目前为止,还没有对控制网格资源的策略的描述和执行给予足够的关注。这些策略定义了资源提供者、虚拟组织甚至治理机构对整个网格允许的或期望的使用场景。大多数现有的网格系统要么具有没有实际实施的“精神上的”使用策略(例如,假定所有资源提供者都以实物形式提供服务),要么具有隐含的资源使用策略,其意图只能通过检查特定策略的实施来体现。此外,定义了一些资源使用策略的系统通常只考虑CPU资源,而不考虑磁盘和带宽等其他网格资源。除非创建足够的资源使用政策和执行机制,否则资源提供者将越来越不愿意参与网格,因为担心他们的本地资源将被占用。在本文中,我们确定了资源使用策略语言的需求,然后提出了一个以事件为中心的模型,通过该模型来实现这些策略。我们描述了语言结构、它在XML访问控制语言XACML之上的实现以及处理该语言的策略服务。由于基于这类策略的决策通常需要来自单个网格请求的安全上下文之外的信息,因此我们扩展XACML,以实现执行此类网格资源使用策略所必需的基于定时器和以事件为中心的一般处理。我们在由三个数据存储库组成的网格上评估我们的原型实现,通过展示使用策略控制的网格环境可以以最小的开销实现。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信