Policy based access control in dynamic grid-based collaborative environment

被引:0
|
作者
Demchenko, Yuri [1 ]
Gommans, Leon [1 ]
de Laat, Cees [1 ]
Tokmakoff, Andrew [2 ]
van Buuren, Rene [2 ]
机构
[1] Univ Amsterdam, NL-1012 WX Amsterdam, Netherlands
[2] Telematica Inst, Enschede, Netherlands
来源
2006 INTERNATIONAL SYMPOSIUM ON COLLABORATIVE TECHNOLOGIES AND SYSTEMS, PROCEEDINGS | 2006年
关键词
Grid-based Collaborative Environment; policy-based access control; workflow; RBAC; SAML; XACML;
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
This paper describes the design and development of a flexible, customer-driven, security infrastructure for Grid-based Collaborative Environments. The paper proposes further development of the access control model built around a service or resource provisioning agreement (e.g., an experiment or project) that is used as a basis for an instant access control policy definition and virtual association of users and resources. Work/flow management technology is considered as a solution for dynamic security context management during the lifetime of an experiment. The paper analyses the required functionality and suggests extensions to the generic AAA Authorisation framework in order to support complex collaboration scenarios in dynamic virtualised environments. The paper provides implementation details on the use of XACML for fine-grained access control policy definition for complex resources and team-based role management, and SAML for secure credentials exchange. In addition, the paper discusses how the Virtual Organisations (VO) concept can be used for experiment-based dynamic security association management. The proposed technical solutions are intended to be compatible and interoperable with the current implementation of the Grid security middleware in the Globus Toolkit and gLite. The paper is based on experiences gained from major Grid-based and Grid-oriented projects in collaborative applications and complex resource provisioning.
引用
收藏
页码:64 / +
页数:2
相关论文
共 50 条
  • [31] HotGrid: Graduated access to grid-based science gateways
    Williams, R
    Steenberg, C
    Bunn, J
    ADVANCES IN GRID COMPUTING - EGC 2005, 2005, 3470 : 78 - 87
  • [32] Grid-based Data Access to Nucleotide Sequence Database
    Frank Zhigang Wang
    Sining Wu
    Na Helian
    Zhiwei Xu
    Yuhui Deng
    Vineet Khare
    Chenhan Liao
    Chris Thompson
    Michael Parker
    New Generation Computing, 2007, 25 : 409 - 424
  • [33] COLLABORATIVE APPROACH IN ACCESSING HOMOGENEOUS MEDICAL DATA IN GRID-BASED ENVIRONMENT (ENHANCING DISEASES CLASSIFICATION)
    Khor, E. T.
    VALUE IN HEALTH, 2014, 17 (07) : A802 - A802
  • [34] Grid-Based Large-scale Web3D Collaborative Virtual Environment
    Lin, Qingping
    Neo, Hoon Kang
    Zhang, Liang
    Huang, Guangbin
    Gay, Robert
    WEB3D 2007 - 12TH INTERNATIONAL CONFERENCE ON 3D WEB TECHNOLOGY, PROCEEDINGS, 2007, : 123 - +
  • [35] VO-based dynamic security associations in collaborative grid environment
    Demchenko, Yuri
    de Laat, Cees
    Ciaschini, Vincenzo
    2006 INTERNATIONAL SYMPOSIUM ON COLLABORATIVE TECHNOLOGIES AND SYSTEMS, PROCEEDINGS, 2006, : 38 - +
  • [36] Policy-based access control framework for grid computing
    Wu, Jin
    Leangsuksun, Chokchai Box
    Rampure, Vishal
    Ong, Hong
    SIXTH IEEE INTERNATIONAL SYMPOSIUM ON CLUSTER COMPUTING AND THE GRID: SPANNING THE WORLD AND BEYOND, 2006, : 391 - +
  • [37] The cost of transparency: Grid-based file access on the Avaki Data Grid
    Huang, H. Howie
    Grimshaw, Andrew S.
    PARALLEL AND DISTRIBUTED PROCESSING AND APPLICATIONS, 2006, 4330 : 642 - +
  • [38] A fuzzy trust evaluation based access control in grid environment
    Chen, Yi
    Luo, Junzhou
    Ni, Xudong
    PROCEEDINGS OF THE THIRD CHINAGRID ANNUAL CONFERENCE, 2008, : 190 - 196
  • [39] Policy Architecture for Credential Based Access Control in Open Access Environment
    Dagdee, Nirmal
    Vijaywargiya, Ruchi
    JOURNAL OF INFORMATION ASSURANCE AND SECURITY, 2011, 6 (01): : 39 - 47
  • [40] A grid-based experiment environment in civil engineering research
    Lee, Jang Ho
    Kim, Dong Wook
    Jang, Sun
    Jeong, Taikyeong
    Yi, Yi Song
    WSEAS Transactions on Information Science and Applications, 2007, 4 (05): : 976 - 981