PERMIS: a modular authorization infrastructure

被引:40
作者
Chadwick, David [1 ]
Zhao, Gansen [2 ]
Otenko, Sassa [2 ]
Laborde, Romain [3 ]
Su, Linying [1 ]
Nguyen, Tuan Anh [1 ]
机构
[1] Univ Kent, Comp Lab, Canterbury, Kent, England
[2] Oracle Corp UK Ltd, Reading RG6 1RA, Berks, England
[3] Univ Toulouse 3, IRIT, F-31062 Toulouse 9, France
关键词
PDP; authorization infrastructure; access control decisions; Grid security;
D O I
10.1002/cpe.1313
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Authorization infrastructures manage privileges and render access control decisions, allowing applications to adjust their behavior according to the privileges allocated to users. This paper describes the PERMIS role-based authorization infrastructure along with its conceptual authorization, access control, and trust models. PERMIS has the novel concept of a credential validation service, which verifies a user's credentials prior to access control decision-making and enables the distributed management of credentials. PERMIS also supports delegation of authority; thus, credentials can be delegated between users, further decentralizing credential management. Finally, PERMIS supports history-based decision-making, which can be used to enforce such aspects as separation of duties and cumulative use of resources. Details of the design and the implementation of PERMIS are presented along with details of its integration with Globus Toolkit, Shibboleth, and GridShib. A comparison of PERMIS with other authorization and access control implementations is given, along with suggestions where future research and development are still needed. Copyright (c) 2008 John Wiley & Sons, Ltd.
引用
收藏
页码:1341 / 1357
页数:17
相关论文
共 25 条
[1]   From gridmap-file to VOMS: managing authorization in a Grid environment [J].
Alfieri, R ;
Cecchini, R ;
Ciaschini, V ;
dell'Agnello, L ;
Frohner, A ;
Lorentey, K ;
Spataro, E .
FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2005, 21 (04) :549-558
[2]  
[Anonymous], 1999, KEYNOTE TRUST MANAGE
[3]  
[Anonymous], SEC ASS MARK LANG SA
[4]  
BARTON T, 2006, 5 ANN PKI R D WORKSH
[5]   'R-What?' - Development of a role-based access control policy-writing tool for e-Scientists [J].
Brostoff, S ;
Sasse, MA ;
Chadwick, D ;
Cunningham, J ;
Mbanaso, U ;
Otenko, S .
SOFTWARE-PRACTICE & EXPERIENCE, 2005, 35 (09) :835-856
[6]  
CANTOR S, 2005, SHIBBOLETH IN PRESS
[7]  
CHADWICK D, 2005, NIST 4 ANN PKI WORKS
[8]  
CHADWICK D, 2007, CONCURRENCY COMPUTAT
[9]  
CHADWICK D, 2004, P 8 ANN IFIP TC 6 TC
[10]  
Chadwick D. W., 2006, Campus-Wide Information Systems, V23, P297, DOI 10.1108/10650740610704153