Managing role-based access control policies for grid databases in OGSA-DAI using CAS

被引:11
作者
Pereira A.L. [1 ]
Muppavarapu V. [1 ]
Chung S.M. [1 ]
机构
[1] Department of Computer Science and Engineering, Wright State University, Dayton
关键词
Community Authorization Service (CAS); Grid databases; Open Grid Services Architecture - Data Access and Integration (OGSA-DAI); Role-based access control (RBAC); Virtual organization (VO);
D O I
10.1007/s10723-006-9054-4
中图分类号
学科分类号
摘要
In this paper, we present a role-based access control method for accessing databases through the Open Grid Services Architecture - Data Access and Integration (OGSA-DAI) framework. OGSA-DAI is an efficient Grid-enabled middleware implementation of interfaces and services to access and control data sources and sinks. However, in OGSA-DAI, access control causes substantial administration overhead for resource providers in virtual organizations (VOs) because each of them has to manage a role-map file containing authorization information for individual Grid users. To solve this problem, we used the Community Authorization Service (CAS) provided by the Globus Toolkit to support the role-based access control (RBAC) within OGSA-DAI. CAS uses the Security Assertion Markup Language (SAML). Our method shows that CAS can support a wide range of security policies using role-privileges, role hierarchies, and constraints. The resource providers need to maintain only the mapping information from VO roles to local database roles and the local policies in the role-map files, so that the number of entries in the role-map file is reduced dramatically. Also, unnecessary authentication, mapping and connections can be avoided by denying invalid requests at the VO level. Thus, our access control method provides increased manageability for a large number of users and reduces day-to-day administration tasks of the resource providers, while they maintain the ultimate authority over their resources. Performance analysis shows that our method adds very little overhead to the existing security infrastructure of OGSA-DAI. © Springer Science + Business Media B.V. 2006.
引用
收藏
页码:65 / 81
页数:16
相关论文
共 24 条
[21]  
Cannon S., Chan S., Olson D., Tull C., Welch V., Pearlman L., Using CAS to manage role-based VO sub-groups, Proceedings of International Conference for Computing in High Energy and Nuclear Physics, (2003)
[22]  
Sandhu R., Ferraiolo D.F., Kuhn D.R., The NIST model for role based access control: Towards a unified standard, Proceedings of the 5th ACM Workshop on Role Based Access Control, (2000)
[23]  
Jackson M., Antonioletti M., Hong N.C., Hume A., Krause A., Sugden T., Westhead M., Performance analysis of the OGSA-DAI software, Proceedings of UK E-Science All Hands Meeting, (2004)
[24]  
Yee K., Secure interaction design and the principle of least authority, Proceedings of Workshop on Human-Computer Interaction and Security Systems, (2003)