Countering security threats in service-oriented on-demand grid computing using sandboxing and trusted computing techniques

被引:17
作者
Smith, Matthew [1 ]
Friese, Thomas [1 ]
Engel, Michael [1 ]
Freisleben, Bernd [1 ]
机构
[1] Univ Marburg, Dept Math & Comp Sci, D-35032 Marburg, Germany
关键词
grid security; on-demand computing; service-orientation; sandboxing; virtualization; trusted computing;
D O I
10.1016/j.jpdc.2006.04.009
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
In this paper, an analysis of security threats within service-oriented on-demand Grid computing environments is presented. The analysis is based on identifying three levels of trust relationships and three types of Grid applications in on-demand computing; the trust relationships involve interactions among resource providers, middleware producers, solution producers, and users. The paper presents solutions for addressing the threats inherent to these three increasingly demanding levels. The solutions involve applying sandbox-based approaches using virtual machine technology and jailing mechanisms to ensure trust for the first two levels of on-demand Grid computing, as well as Trusted Computing Platform Alliance (TCPA) technology for the third level of on-demand Grid computing. A brief taxonomy of the presented solutions is introduced. (C) 2006 Elsevier Inc. All rights reserved.
引用
收藏
页码:1189 / 1204
页数:16
相关论文
共 35 条
[1]   VOMS, an authorization system for virtual organizations [J].
Alfieri, R ;
Cecchini, R ;
Ciaschini, V ;
dell'Agnello, L ;
Frohner, A ;
Gianoli, A ;
Lorentey, K ;
Spataro, F .
GRID COMPUTING, 2004, 2970 :33-40
[2]  
*AP SOFTW FDN, 2004, AP WEB SERV PROJ
[3]  
Barham P., 2003, Operating Systems Review, V37, P164, DOI 10.1145/1165389.945462
[4]  
*BMBF, 2006, D GRID
[5]   Role-based access control with X.509 attribute certificates [J].
Chadwick, DW ;
Otenko, A ;
Ball, E .
IEEE INTERNET COMPUTING, 2003, 7 (02) :62-69
[6]  
Clark B, 2004, USENIX ASSOCIATION PROCEEDINGS OF THE FREENIX TRACK 2004 USENIX ANNUAL TECHNICAL CONFERENCE, P135
[7]  
*COMP SEC I, 2004, CSI FBI COMP CRIM SE
[8]  
*EGEE PROJ, 2004, DJRA31 EGEE EU
[9]  
FOSTER I, 2004, OPEN GRID SERVICES A
[10]  
FOSTER I, 2002, GLOB GRID FOR