Policy based access control in dynamic grid-based collaborative environment

被引:0
|
作者
Demchenko, Yuri [1 ]
Gommans, Leon [1 ]
de Laat, Cees [1 ]
Tokmakoff, Andrew [2 ]
van Buuren, Rene [2 ]
机构
[1] Univ Amsterdam, NL-1012 WX Amsterdam, Netherlands
[2] Telematica Inst, Enschede, Netherlands
来源
2006 INTERNATIONAL SYMPOSIUM ON COLLABORATIVE TECHNOLOGIES AND SYSTEMS, PROCEEDINGS | 2006年
关键词
Grid-based Collaborative Environment; policy-based access control; workflow; RBAC; SAML; XACML;
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
This paper describes the design and development of a flexible, customer-driven, security infrastructure for Grid-based Collaborative Environments. The paper proposes further development of the access control model built around a service or resource provisioning agreement (e.g., an experiment or project) that is used as a basis for an instant access control policy definition and virtual association of users and resources. Work/flow management technology is considered as a solution for dynamic security context management during the lifetime of an experiment. The paper analyses the required functionality and suggests extensions to the generic AAA Authorisation framework in order to support complex collaboration scenarios in dynamic virtualised environments. The paper provides implementation details on the use of XACML for fine-grained access control policy definition for complex resources and team-based role management, and SAML for secure credentials exchange. In addition, the paper discusses how the Virtual Organisations (VO) concept can be used for experiment-based dynamic security association management. The proposed technical solutions are intended to be compatible and interoperable with the current implementation of the Grid security middleware in the Globus Toolkit and gLite. The paper is based on experiences gained from major Grid-based and Grid-oriented projects in collaborative applications and complex resource provisioning.
引用
收藏
页码:64 / +
页数:2
相关论文
共 50 条
  • [21] Research on grid-based personalized collaborative learning system
    Zhao Chengling
    Yan, Cao
    Tan Xiaodong
    Qi, Luo
    Ying, Yu
    Proceedings of 2006 International Conference on Artificial Intelligence: 50 YEARS' ACHIEVEMENTS, FUTURE DIRECTIONS AND SOCIAL IMPACTS, 2006, : 638 - 642
  • [22] Research on Grid-Based Management of Collaborative Logistics System Based on Internet
    Yong, Yin Xiao
    Wei, Tan
    2012 INTERNATIONAL CONFERENCE ON INDUSTRIAL CONTROL AND ELECTRONICS ENGINEERING (ICICEE), 2012, : 968 - 971
  • [23] Grid-based biological computation service environment
    Zhu, J
    Yang, GW
    Zheng, WM
    Zhu, T
    Shen, MM
    Qiao, L
    Liu, XJ
    GRID AND COOPERATIVE COMPUTING, PT 1, 2004, 3032 : 237 - 241
  • [24] Grid-based Parallel and Distributed Simulation environment
    Kim, CH
    Lee, TD
    Hwang, SC
    Jeong, CS
    PARALLEL COMPUTING TECHNOLOGIES, PROCEEDINGS, 2003, 2763 : 503 - 508
  • [25] Grid-based collaborative simulation system for vehicle crashworthiness
    Weng, Yiliu
    Jin, Xianlong
    Zhao, Zhijie
    Cao, Yuan
    Wang, Jianwei
    SIMULATION MODELLING PRACTICE AND THEORY, 2010, 18 (06) : 752 - 767
  • [26] A Grid-based problem solving environment for GECEM
    Lin, M
    Walker, DW
    Chen, Y
    Jones, JW
    2005 IEEE INTERNATIONAL SYMPOSIUM ON CLUSTER COMPUTING AND THE GRID, VOLS 1 AND 2, 2005, : 686 - 693
  • [27] Access control model based on dynamic negotiating in grid
    Zhang, Runlian
    Dong, Xiaoshe
    Wu, Xiaonian
    Huazhong Keji Daxue Xuebao (Ziran Kexue Ban)/Journal of Huazhong University of Science and Technology (Natural Science Edition), 2006, 34 (SUPPL.): : 177 - 180
  • [28] A dynamic awareness model for service-based collaborative grid application in Access Grid
    Chen, Xiaowu
    Ji, Xiangyu
    Zhao, Qinping
    ADVANCES IN GRID AND PERVASIVE COMPUTING, PROCEEDINGS, 2008, 5036 : 459 - 470
  • [29] Dynamic coupling of grid-based multidisciplinary applications
    Ding, Y
    Münch, M
    Laux, M
    PROCEEDINGS OF THE SEVENTH EUROMICRO WORKSHOP ON PARALLEL AND DISTRIBUTED PROCESSING, PDP'99, 1999, : 249 - 255
  • [30] Grid-based data access to nucleotide sequence database
    Wang, Frank Zhigang
    Wu, Sining
    Helian, Na
    Xu, Zhiwei
    Deng, Yuhui
    Khare, Vineet
    Liao, Chenhan
    Thompson, Chris
    Parker, Micliael
    NEW GENERATION COMPUTING, 2007, 25 (04) : 409 - 424