Policy-based access control in peer-to-peer grid systems

J. F. Silva, L. Gaspary, M. Barcellos, André Detsch
{"title":"Policy-based access control in peer-to-peer grid systems","authors":"J. F. Silva, L. Gaspary, M. Barcellos, André Detsch","doi":"10.1109/GRID.2005.1542731","DOIUrl":null,"url":null,"abstract":"Access control to resources is one of the most important requirements to be satisfied in grid systems that span over multiple administrative domains. Such a mechanism allows every institution taking part of a grid community to define and enforce policies for the use of their local resources by remote users. Despite the efforts of the research community to address this topic, existing approaches do not scale (e.g., in terms of communication overhead) for a large number of nodes (peers) providing resources, as these approaches rely on centralized servers to process access requests. Furthermore, they provide limited, large-grain policy specification functionality and are not committed to employing open, standardized formats to express policies. In this paper, we address these limitations by proposing PeGAC (peer-to-peer grid access control), a policy-based, distributed access control mechanism, which can be applied to P2P grid systems. In our proposal, policies are specified using the role-based access control model and coded using the extensible access control markup language. As a proof-of-concept we have integrated PeGAC into OurGrid, a middleware for the implementation of P2P grid systems. Preliminary results of experiments carried out at the resulting infrastructure show that our solution poses small communication and processing overhead, and can handle large policy repositories efficiently.","PeriodicalId":347929,"journal":{"name":"The 6th IEEE/ACM International Workshop on Grid Computing, 2005.","volume":"8 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2005-11-13","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"23","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"The 6th IEEE/ACM International Workshop on Grid Computing, 2005.","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/GRID.2005.1542731","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 23

Abstract

Access control to resources is one of the most important requirements to be satisfied in grid systems that span over multiple administrative domains. Such a mechanism allows every institution taking part of a grid community to define and enforce policies for the use of their local resources by remote users. Despite the efforts of the research community to address this topic, existing approaches do not scale (e.g., in terms of communication overhead) for a large number of nodes (peers) providing resources, as these approaches rely on centralized servers to process access requests. Furthermore, they provide limited, large-grain policy specification functionality and are not committed to employing open, standardized formats to express policies. In this paper, we address these limitations by proposing PeGAC (peer-to-peer grid access control), a policy-based, distributed access control mechanism, which can be applied to P2P grid systems. In our proposal, policies are specified using the role-based access control model and coded using the extensible access control markup language. As a proof-of-concept we have integrated PeGAC into OurGrid, a middleware for the implementation of P2P grid systems. Preliminary results of experiments carried out at the resulting infrastructure show that our solution poses small communication and processing overhead, and can handle large policy repositories efficiently.
对等网格系统中基于策略的访问控制
在跨越多个管理域的网格系统中,对资源的访问控制是需要满足的最重要的需求之一。这种机制允许作为网格社区一部分的每个机构定义和执行远程用户使用其本地资源的策略。尽管研究团体努力解决这个问题,但现有的方法不能扩展(例如,在通信开销方面),因为这些方法依赖于集中式服务器来处理访问请求。此外,它们提供有限的大粒度策略规范功能,并且不致力于使用开放的、标准化的格式来表示策略。在本文中,我们通过提出PeGAC(点对点网格访问控制)来解决这些限制,PeGAC是一种基于策略的分布式访问控制机制,可应用于P2P网格系统。在我们的建议中,使用基于角色的访问控制模型指定策略,并使用可扩展访问控制标记语言进行编码。作为概念验证,我们已经将PeGAC集成到OurGrid中,这是一个实现P2P网格系统的中间件。在所得到的基础设施上进行的实验的初步结果表明,我们的解决方案具有很小的通信和处理开销,并且可以有效地处理大型策略存储库。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信