From gridmap-file to VOMS: managing authorization in a Grid environment

被引:128
作者
Alfieri, R
Cecchini, R
Ciaschini, V
dell'Agnello, L
Frohner, A
Lorentey, K
Spataro, E
机构
[1] Ist Nazl Fis Nucl, CNAF, I-40100 Bologna, Italy
[2] Ist Nazl Fis Nucl, Parma, Italy
[3] Univ Parma, I-43100 Parma, Italy
[4] Ist Nazl Fis Nucl, I-50125 Florence, Italy
[5] CERN, CH-1211 Geneva, Switzerland
来源
FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE | 2005年 / 21卷 / 04期
关键词
grids; authorization; attributes;
D O I
10.1016/j.future.2004.10.006
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Grids are potentially composed of several thousands of users from different institutions sharing their computing resources (or using resources provided by third parties). Controlling access to these resources is a difficult problem, as it depends on the policies of the organizations the users belong to and of the resource owners. Moreover, a simple authorization implementation, based on a direct user registration on the resources, is not applicable to a large scale environment. In this paper, we describe the solution to this problem developed in the framework of the European DataGrid [M. Draoli, G. Mascari, R. Piccinelli, Project Presentation, DataGrid-11-NOT-0103-(-1)] and DataTAG [http://www.datatag.org/] projects: the Virtual Organization Membership Service (VOMS) [R. Alfieri, et al., Managing Dynamic User Communities in a Grid of Autonomous Resources, TUBT005, in: Proceedings of the CHEP 2003, 2003]. VOMS allows a fine grained control of the use of the resources both to the users' organizations and to the resource owners. (c) 2005 Elsevier B.V. All rights reserved.
引用
收藏
页码:549 / 558
页数:10
相关论文
共 23 条
[1]  
ALFIERI R, 2003, P CHEP 2003
[2]  
[Anonymous], 3280 RFC
[3]  
Box D., 2000, SIMPLE OBJECT ACCESS
[4]   The PERMIS X.509 role based privilege management infrastructure [J].
Chadwick, DW ;
Otenko, A .
FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2003, 19 (02) :277-289
[5]  
Cornwall L, 2003, P UK E SCI ALL HANDS, P382
[6]  
DRAOLI M, PROJECT PRESENTATION
[7]  
FARREL S, 2002, 3281 RFC
[8]   The anatomy of the grid: Enabling scalable virtual organizations [J].
Foster, I ;
Kesselman, C ;
Tuecke, S .
INTERNATIONAL JOURNAL OF HIGH PERFORMANCE COMPUTING APPLICATIONS, 2001, 15 (03) :200-222
[9]  
FOSTER I, 1998, P IPPS SPDP 98 HET C
[10]  
Foster I., 2002, OP GRID SERV INFR WG