On usage control for GRID systems

被引:25
作者
Martinelli, Fabio [1 ]
Mori, Paolo [1 ]
机构
[1] CNR, Ist Informat & Telemat, I-56100 Pisa, Italy
来源
FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE | 2010年 / 26卷 / 07期
关键词
Access/usage control; Security policies; Grid security; Distributed systems security; MANAGEMENT; ACCESS; AUTHORIZATION; SECURITY;
D O I
10.1016/j.future.2009.12.005
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
This paper introduces a formal model, an architecture and a prototype implementation for usage control on GRID systems. The usage control model (UCON) is a new access control paradigm proposed by Park and Sandhu that encompasses and extends several existing models (e.g. MAC, DAC, Bell-Lapadula, RBAC, etc.). Its main novelty is based on continuity of the access monitoring and mutability of attributes of subjects and objects. We identified this model as a perfect candidate for managing access/usage control in GRID systems due to their peculiarities, where continuity of control is a central issue. Here we adapt the original UCON model to develop a full model for usage control in GRID systems. We use as policy specification language a process description language and show how this is suitable to model the usage policy models of the original UCON model. We also describe a possible architecture to implement the usage control model. Moreover, we describe a prototype implementation for usage control of GRID computational services, and we show how our language can be used to define a security policy that regulates the usage of network communications to protect the local computational service from the applications that are executed on behalf of remote GRID users. (C) 2009 Elsevier B.V. All rights reserved.
引用
收藏
页码:1032 / 1042
页数:11
相关论文
共 34 条
[1]   From gridmap-file to VOMS: managing authorization in a Grid environment [J].
Alfieri, R ;
Cecchini, R ;
Ciaschini, V ;
dell'Agnello, L ;
Frohner, A ;
Lorentey, K ;
Spataro, E .
FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2005, 21 (04) :549-558
[2]   UNICORE: uniform access to supercomputing as an element of electronic commerce [J].
Almond, J ;
Snelling, D .
FUTURE GENERATION COMPUTER SYSTEMS, 1999, 15 (5-6) :539-548
[3]  
[Anonymous], P COMP HIGH EN NUCL
[4]  
[Anonymous], P 5 ACM COMP COMM SE, DOI DOI 10.1145/288090.288111
[5]  
Baiardi F, 2004, LECT NOTES COMPUT SC, V3292, P123
[6]  
BANKS T, 2006, WEB SERVICES RESOURC
[7]  
BERLICH R, 2005, ACSW FRONTIERS 05, P21
[8]   The PERMIS X.509 role based privilege management infrastructure [J].
Chadwick, DW ;
Otenko, A .
FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2003, 19 (02) :277-289
[9]  
Colombo M, 2007, LECT NOTES COMPUT SC, V4804, P1505
[10]  
ERWIN DW, 2001, LECT NOTES COMPUTER, V2150, P825