On Usage Control for GRID Services

被引:2
作者
Colombo, Maurizio [1 ]
Martinelli, Fabio [1 ]
Mori, Paolo [1 ]
Lazouski, Aliaksandr [2 ]
机构
[1] CNR, Ist Informat & Telemat, Via G Moruzzi 1, I-56100 Pisa, Italy
[2] Univ Pisa, Dipartimento Informat, I-56100 Pisa, Italy
来源
INTERNATIONAL JOINT CONFERENCE ON COMPUTATIONAL SCIENCES AND OPTIMIZATION, VOL 1, PROCEEDINGS | 2009年
关键词
D O I
10.1109/CSO.2009.479
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
In recent years, usage control has been proposed as a novel authorization solution for open, heterogeneous, distributed computer environments. Grid is a such environment providing services for seamless sharing and usage of heterogeneous computational resources. Researches have shown that usage control is a viable solution for authorization in Grid. Unfortunately, the implementation of continues usage control for Grid services is not widely presented. In this paper, we present a usage control model and focus on continuous control over Grid services. If a security policy is violated during a service execution, the service should be blocked or terminated. Our approach presents different levels of granularity and enforces coarse and fine-grained usage control on generic and computational Grid services. Furthermore, we present an implementation of our prototype based on POLPA policy language and its reasoning authorization engine integrated into Grid services runtime component of Globus Toolkit. Our prototype is facilitated through implementation of service interfaces compliant with OGSA standard and can be easily plugged-in to existing Globus authorization infrastructure.
引用
收藏
页码:47 / +
页数:2
相关论文
共 8 条
[1]  
FOSTER I, 2005, LNCS
[2]  
Foster I.K., 2002, Global Grid Forum
[3]  
FOSTER IT, 2001, EURO PAR 01
[4]  
MARTINELLI F, 2005, ICAS ICNS 05
[5]  
Martinelli F., 2007, P 1 INT WORKSH SEC T
[6]  
PARK J, 2004, ACM T INF SYST SECUR
[7]  
STELL AJ, 2005, HPCS 05
[8]  
ZHANG X, 2008, ACM T INF SYST SECUR