Addressing credential revocation in grid environments

B. Sundaram, B. Chapman
{"title":"Addressing credential revocation in grid environments","authors":"B. Sundaram, B. Chapman","doi":"10.1109/GRID.2005.1542764","DOIUrl":null,"url":null,"abstract":"Credential revocation is a critical problem in grid environments and remains unaddressed in existing grid security solutions. We present our ongoing work in designing a novel grid authentication system, based on Globus GSI, that solves the revocation problem. The focus of this work is to ensure instantaneous revocation of both long-term digital identities of hosts/users and short-lived identities of user proxies. Our system employs mediated RSA (mRSA), adapts Boneh's notion of semi-trusted mediators to suit security in virtual organizations and propagates proxy revocation information as in Micali's NOVO-MODO system. We envision that our system would additionally provide a configuration-free security model for end users and fine-grained management of user credentials.","PeriodicalId":347929,"journal":{"name":"The 6th IEEE/ACM International Workshop on Grid Computing, 2005.","volume":"42 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2005-11-13","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"5","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"The 6th IEEE/ACM International Workshop on Grid Computing, 2005.","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/GRID.2005.1542764","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 5

Abstract

Credential revocation is a critical problem in grid environments and remains unaddressed in existing grid security solutions. We present our ongoing work in designing a novel grid authentication system, based on Globus GSI, that solves the revocation problem. The focus of this work is to ensure instantaneous revocation of both long-term digital identities of hosts/users and short-lived identities of user proxies. Our system employs mediated RSA (mRSA), adapts Boneh's notion of semi-trusted mediators to suit security in virtual organizations and propagates proxy revocation information as in Micali's NOVO-MODO system. We envision that our system would additionally provide a configuration-free security model for end users and fine-grained management of user credentials.
解决网格环境中的凭证撤销问题
证书撤销是网格环境中的一个关键问题,在现有的网格安全解决方案中仍未得到解决。本文介绍了基于Globus GSI的新型网格认证系统的设计工作,该系统解决了吊销问题。这项工作的重点是确保主机/用户的长期数字身份和用户代理的短期身份的即时撤销。我们的系统采用中介RSA (mRSA),采用Boneh的半信任中介概念来适应虚拟组织的安全性,并像Micali的NOVO-MODO系统一样传播代理撤销信息。我们设想,我们的系统还将为最终用户提供一个无需配置的安全模型,并对用户凭证进行细粒度管理。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信