Access Control Strategies for Virtualized Environments in Grid Computing Systems

A. Squicciarini, E. Bertino, S. Goasguen
{"title":"Access Control Strategies for Virtualized Environments in Grid Computing Systems","authors":"A. Squicciarini, E. Bertino, S. Goasguen","doi":"10.1109/FTDCS.2007.10","DOIUrl":null,"url":null,"abstract":"The development of adequate security solutions and in particular of authentication and authorization techniques for grid computing systems is a challenging task. Challenges arise from the heterogeneity of users, the presence of multiple security administration entities, the heterogeneity of security techniques used at the various grid hosts, the scalability requirements, and the need for high-level policies concerning resource sharing. Recent trends, like accessing grid through science gateways and the use of virtual organizations (VO) for managing user communities, further complicate the problem of security for grid computing systems. Currently, the GSI component developed as part of the Globus Toolkit, the de-facto standard for grid infrastructures is not fully suited to meet those challenges. The main drawback of such an approach is that it relies on a low level identity-based authorization scheme. .A low-level access control policy maps a user's identity (distinguished name) to a local account. Such approach does not scale and does not address many of the outlined requirements. We thus need security solutions that go beyond the simple solutions currently in use. The goal of this paper is to make a first step towards such solutions. The paper discusses and analyzes authentication and authorization solutions that better fit novel grid infrastructures characterized by virtual organizations and science gateways. Some of these solutions derive from ongoing work in current grid infrastructure projects; others are new proposals that we think worthy of discussion. In particular, we analyze the solutions proposed as part of the GridShib and the VO Privilege projects","PeriodicalId":199987,"journal":{"name":"11th IEEE International Workshop on Future Trends of Distributed Computing Systems (FTDCS'07)","volume":"68 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2007-03-21","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"5","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"11th IEEE International Workshop on Future Trends of Distributed Computing Systems (FTDCS'07)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/FTDCS.2007.10","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 5

Abstract

The development of adequate security solutions and in particular of authentication and authorization techniques for grid computing systems is a challenging task. Challenges arise from the heterogeneity of users, the presence of multiple security administration entities, the heterogeneity of security techniques used at the various grid hosts, the scalability requirements, and the need for high-level policies concerning resource sharing. Recent trends, like accessing grid through science gateways and the use of virtual organizations (VO) for managing user communities, further complicate the problem of security for grid computing systems. Currently, the GSI component developed as part of the Globus Toolkit, the de-facto standard for grid infrastructures is not fully suited to meet those challenges. The main drawback of such an approach is that it relies on a low level identity-based authorization scheme. .A low-level access control policy maps a user's identity (distinguished name) to a local account. Such approach does not scale and does not address many of the outlined requirements. We thus need security solutions that go beyond the simple solutions currently in use. The goal of this paper is to make a first step towards such solutions. The paper discusses and analyzes authentication and authorization solutions that better fit novel grid infrastructures characterized by virtual organizations and science gateways. Some of these solutions derive from ongoing work in current grid infrastructure projects; others are new proposals that we think worthy of discussion. In particular, we analyze the solutions proposed as part of the GridShib and the VO Privilege projects
网格计算系统中虚拟化环境的访问控制策略
为网格计算系统开发适当的安全解决方案,特别是身份验证和授权技术是一项具有挑战性的任务。挑战来自于用户的异构性、多个安全管理实体的存在、在各种网格主机上使用的安全技术的异构性、可伸缩性需求以及对有关资源共享的高级策略的需求。最近的趋势,如通过科学网关访问网格和使用虚拟组织(VO)来管理用户社区,使网格计算系统的安全问题进一步复杂化。目前,作为Globus Toolkit的一部分开发的GSI组件,即网格基础设施的事实标准,并不能完全适应这些挑战。这种方法的主要缺点是它依赖于低级的基于身份的授权方案,低级访问控制策略将用户的身份(专有名称)映射到本地帐户。这种方法不能扩展,也不能解决许多概述的需求。因此,我们需要超越目前使用的简单解决方案的安全解决方案。本文的目标是朝着这样的解决方案迈出第一步。本文讨论和分析了更适合以虚拟组织和科学网关为特征的新型网格基础设施的认证和授权解决方案。其中一些解决方案源于当前电网基础设施项目中正在进行的工作;还有一些是我们认为值得讨论的新建议。特别是,我们分析了作为GridShib和VO特权项目的一部分提出的解决方案
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信