Beyond X.509: token-based authentication and authorization for HEP

被引:4
|
作者
Ceccanti, Andrea [1 ]
Vianello, Enrico [1 ]
Caberletti, Marco [1 ]
Giacomini, Francesco [1 ]
机构
[1] INFN CNAF, Via Berti Pichat 6-2, I-40137 Bologna, Italy
关键词
D O I
10.1051/epjconf/201921409002
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
X.509 certificates and VOMS have proved to be a secure and reliable solution for authentication and authorization on the Grid, but also showed usability issues and required the development of ad-hoc services and libraries to support VO-based authorization schemes in Grid middleware and experiment computing frameworks. The need to move beyond X.509 certificates is recognized as an important objective in the HEP R&D roadmap for software and computing, to overcome the usability issues of the current AAI and embrace recent advancement in web technologies widely adopted in industry, but also to enable the secure composition of computing and storage resources provisioned across heterogeneous providers in order to meet the computing needs of HL-LHC. A flexible and usable AAI based on modern web technologies is a key enabler of such secure composition and has been a major topic of research of the recently concluded INDIGO-DataCloud project. In this contribution, we present an integrated solution, based on the INDIGO-DataCloud Identity and Access Management service that demonstrates how a next generation, token-based VO-aware AAI can be built in support of HEP computing use cases, while maintaining compatibility with the existing, VOMS-based AAI used by the Grid.
引用
收藏
页数:8
相关论文
共 50 条
  • [21] Inter-Cloud Authentication through X.509 for Defense Organization
    Ul Arifeen, Fahan
    Siddiqui, Raees A.
    Ashraf, Sajjad
    Waheed, Salman
    [J]. 2015 12TH INTERNATIONAL BHURBAN CONFERENCE ON APPLIED SCIENCES AND TECHNOLOGY (IBCAST), 2015, : 299 - 306
  • [22] Validating X.509 Certificates Based on Their Quality
    Wazan, Ahmad Samer
    Laborde, Romain
    Barrere, Francois
    Benzekri, Abdelmalek
    [J]. PROCEEDINGS OF THE 9TH INTERNATIONAL CONFERENCE FOR YOUNG COMPUTER SCIENTISTS, VOLS 1-5, 2008, : 2055 - 2060
  • [23] TBAS: Token-based authorization service architecture in Internet of things scenarios
    Lee, Shih-Hsiung
    Huang, Ko-Wei
    Yang, Chu-Sing
    [J]. INTERNATIONAL JOURNAL OF DISTRIBUTED SENSOR NETWORKS, 2017, 13 (07):
  • [24] Token-Based Authentication Techniques on Open Source Cloud Platforms
    Banerjee, Amit
    Hasan, Mahamudul
    [J]. SISTEMAS & TELEMATICA, 2018, 16 (47): : 9 - 29
  • [25] An Updateable Token-Based Schema for Authentication and Access Management in Clouds
    Emadinia, Tayyebe
    Moghaddam, Faraz Fatemi
    Wieder, Philipp
    Dabbaghi, Shirin
    Yahyapour, Ramin
    [J]. 2019 7TH INTERNATIONAL CONFERENCE ON FUTURE INTERNET OF THINGS AND CLOUD (FICLOUD 2019), 2019, : 50 - 56
  • [26] A Token-based Authentication and Key Agreement Protocol for Cloud Computing
    Xu, Zisang
    Xu, Jianbo
    Kuang, Li-Dan
    [J]. 2021 IEEE 6TH INTERNATIONAL CONFERENCE ON SMART CLOUD (SMARTCLOUD 2021), 2021, : 38 - 43
  • [27] Anonymity 2.0 - X.509 extensions supporting privacy-friendly authentication
    Benjumea, Vicente
    Choi, Seung G.
    Lopez, Javier
    Yung, Moti
    [J]. CRYPTOLOGY AND NETWORK SECURITY, 2007, 4856 : 265 - +
  • [28] Adoption of a token-based authentication model for the CMS Submission Infrastructure
    Perez-Calero Yzquierdo, Antonio
    Mascheroni, Marco
    Kizinevic, Edita
    Khan, Farrukh Aftab
    Kim, Hyunwoo
    Flechas, Maria Acosta
    Tsipinakis, Nikos
    Haleem, Saqib
    Wurthwein, Frank
    [J]. 26TH INTERNATIONAL CONFERENCE ON COMPUTING IN HIGH ENERGY AND NUCLEAR PHYSICS, CHEP 2023, 2024, 295
  • [29] Attribute-Based Encryption goes X.509
    Reimair, Florian
    Feichtner, Johannes
    Teufl, Peter
    [J]. 2015 IEEE 12TH INTERNATIONAL CONFERENCE ON E-BUSINESS ENGINEERING (ICEBE), 2015, : 393 - 400
  • [30] A token-based user authentication mechanism for data exchange in RESTful API
    Huang, Xiang-Wen
    Hsieh, Chin-Yun
    Wu, Cheng Hao
    Cheng, Yu Chin
    [J]. PROCEEDINGS 2015 18TH INTERNATIONAL CONFERENCE ON NETWORK-BASED INFORMATION SYSTEMS (NBIS 2015), 2015, : 601 - 606