Policy based access control in dynamic grid-based collaborative environment

被引:0
|
作者
Demchenko, Yuri [1 ]
Gommans, Leon [1 ]
de Laat, Cees [1 ]
Tokmakoff, Andrew [2 ]
van Buuren, Rene [2 ]
机构
[1] Univ Amsterdam, NL-1012 WX Amsterdam, Netherlands
[2] Telematica Inst, Enschede, Netherlands
来源
2006 INTERNATIONAL SYMPOSIUM ON COLLABORATIVE TECHNOLOGIES AND SYSTEMS, PROCEEDINGS | 2006年
关键词
Grid-based Collaborative Environment; policy-based access control; workflow; RBAC; SAML; XACML;
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
This paper describes the design and development of a flexible, customer-driven, security infrastructure for Grid-based Collaborative Environments. The paper proposes further development of the access control model built around a service or resource provisioning agreement (e.g., an experiment or project) that is used as a basis for an instant access control policy definition and virtual association of users and resources. Work/flow management technology is considered as a solution for dynamic security context management during the lifetime of an experiment. The paper analyses the required functionality and suggests extensions to the generic AAA Authorisation framework in order to support complex collaboration scenarios in dynamic virtualised environments. The paper provides implementation details on the use of XACML for fine-grained access control policy definition for complex resources and team-based role management, and SAML for secure credentials exchange. In addition, the paper discusses how the Virtual Organisations (VO) concept can be used for experiment-based dynamic security association management. The proposed technical solutions are intended to be compatible and interoperable with the current implementation of the Grid security middleware in the Globus Toolkit and gLite. The paper is based on experiences gained from major Grid-based and Grid-oriented projects in collaborative applications and complex resource provisioning.
引用
收藏
页码:64 / +
页数:2
相关论文
共 50 条
  • [41] Grid-based Mapping and Tracking in Dynamic Environments using a Uniform Evidential Environment Representation
    Tanzmeister, Georg
    Thomas, Julian
    Wollherr, Dirk
    Buss, Martin
    2014 IEEE INTERNATIONAL CONFERENCE ON ROBOTICS AND AUTOMATION (ICRA), 2014, : 6090 - 6095
  • [42] A Dynamic Access Control Policy Based on Hierarchical Description
    Han, Dao-jun
    Gong, Ling
    Qin, Fen
    2016 INTERNATIONAL CONFERENCE ON CYBER-ENABLED DISTRIBUTED COMPUTING AND KNOWLEDGE DISCOVERY PROCEEDINGS - CYBERC 2016, 2016, : 76 - 80
  • [43] Semantic search of learning services in a grid-based collaborative system
    Vega-Gorgojo, G
    Bote-Lorenzo, ML
    Gomez-Sanchez, E
    Dimitriadis, YA
    Asensio-Perez, JI
    2005 IEEE INTERNATIONAL SYMPOSIUM ON CLUSTER COMPUTING AND THE GRID, VOLS 1 AND 2, 2005, : 19 - 26
  • [44] Grid-based Virtual Collaborative Facility: Concurrent and Collaborative Engineering for Space Projects
    Beco, Stefano
    Parrini, Andrea
    Paccagnini, Carlo
    Feresin, Fred
    Ton, Arne
    Lervik, Rolf
    Surridge, Mike
    Watkins, Rowland
    COLLABORATIVE PRODUCTIVE AND SERVICE LIFE CYCLE MANAGEMENT FOR A SUSTAINABLE WORLD, 2008, : 77 - +
  • [45] A grid-based remote experiment environment in civil engineering
    Lee, Jang Ho
    Jeong, Taikyeong
    Yi, Sougyi
    ADVANCES IN GRID AND PERVASIVE COMPUTING, PROCEEDINGS, 2007, 4459 : 263 - +
  • [46] GRID-Based Prediction of Electromagnetic Fields in Urban Environment
    Coco, Salvatore
    Laudani, Antonino
    Pollicino, Giuseppe
    IEEE TRANSACTIONS ON MAGNETICS, 2009, 45 (03) : 1060 - 1063
  • [47] Research on key Technologies for Grid-based Network Collaborative Design
    Chen, Xuebin
    Duan, Guolin
    Sun, Yan
    Gu, Jiantao
    NCM 2008: 4TH INTERNATIONAL CONFERENCE ON NETWORKED COMPUTING AND ADVANCED INFORMATION MANAGEMENT, VOL 2, PROCEEDINGS, 2008, : 639 - +
  • [48] Trustworthiness-based dynamic access control for grid application
    Chen, Xu-Ri
    Xu, Wei-Min
    Shen, Wen-Feng
    Hunan Daxue Xuebao/Journal of Hunan University Natural Sciences, 2008, 35 (07): : 85 - 89
  • [49] Extending user-controlled security domain with TPM/TCG in Grid-based virtual collaborative environment
    Demchenko, Yuri
    Gommans, Leon
    de Laat, Cees
    CTS 2007: PROCEEDINGS OF THE 2007 INTERNATIONAL SYMPOSIUM ON COLLABORATIVE TECHNOLOGIES AND SYSTEMS, 2007, : 57 - 65
  • [50] Dynamic grid-based approach to data distribution management
    Boukerche, A
    Roy, A
    JOURNAL OF PARALLEL AND DISTRIBUTED COMPUTING, 2002, 62 (03) : 366 - 392