Coordinating access control in grid services

被引:7
作者
Chadwick, David W. [1 ]
Su, Linying [1 ]
Laborde, Romain [2 ]
机构
[1] Univ Kent, Comp Lab, Canterbury CT2 7NF, Kent, England
[2] Univ Toulouse 3, Inst Rech Informat Toulouse, F-31062 Toulouse 9, France
关键词
PDP; coordinated access control; grid security;
D O I
10.1002/cpe.1284
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
We describe how to control the cumulative use of distributed grid resources by using coordination-aware policy decision points (coordinated PDPs) and an SQL database to hold 'coordination' data. When access to a resource is granted, obligations in the security policy ensure that the coordination database is updated. The coordination database is a normal grid service providing distributed access to the coordinated PDPs. Access to the databases is secured by the grid security infrastructure (GSI) and its own PDP, so that only authorized users (the coordinated PDPs) can access it. A coordinated PDP is imbedded into the Globus Toolkitv4 authorization chain as a custom PDP so that any grid service can be protected by a security policy that provides a coordination capability. Each coordinated PDP uses the services of an uncoordinated PDP to make its access control decisions, so that any existing stateless PDP can be supplemented with a coordination capability. We provide performance results for the coordinated PDPs and compare these with two stateless PDPs. Virtually the entire performance penalty of using coordinated PDPs is accounted for by the heavy costs of using GSI to secure communications between the coordinated PDPs and the coordination database. Copyright (C) 2007 John Wiley & Sons, Ltd.
引用
收藏
页码:1071 / 1094
页数:24
相关论文
共 25 条
[1]  
Abadi M., 2003, P 10 ANN NETW DISTR
[2]   From gridmap-file to VOMS: managing authorization in a Grid environment [J].
Alfieri, R ;
Cecchini, R ;
Ciaschini, V ;
dell'Agnello, L ;
Frohner, A ;
Lorentey, K ;
Spataro, E .
FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2005, 21 (04) :549-558
[3]  
[Anonymous], P 6 IEEE INT WORKSH
[4]  
[Anonymous], 2004, J. Grid Comput
[5]  
[Anonymous], P IEEE 3 INT WORKSH
[6]  
[Anonymous], P 12 IEEE INT S HIGH
[7]   Coordination between distributed PDPs [J].
Chadwick, David W. ;
Su, Linying ;
Otenko, Oleksandr ;
Laborde, Romain .
SEVENTH IEEE INTERNATIONAL WORKSHOP ON POLICIES FOR DISTRIBUTED SYSTEMS AND NETWORKS, PROCEEDINGS, 2006, :163-+
[8]  
CHADWICK DW, 2002, FUTURE GENER COMP SY, V936, P1
[9]  
DUMITRESCU C, 2005, P ACM IEEE C SUP
[10]   A model for usage policy-based resource allocation in grids [J].
Dumitrescu, CL ;
Wilde, M ;
Foster, I .
Sixth IEEE International Workshop on Policies for Distributed Systems and Networks, Proceedings, 2005, :191-200