Role-based access control for a Grid system using OGSA-DAI and Shibboleth

被引:5
|
作者
Muppavarapu, Vineela [1 ]
Pereira, Anil L. [1 ]
Chung, Soon M. [1 ]
机构
[1] Wright State Univ, Dept Comp Sci & Engn, Dayton, OH 45435 USA
来源
JOURNAL OF SUPERCOMPUTING | 2010年 / 54卷 / 02期
关键词
Open Grid Services Architecture Data Access and Integration (OGSA-DAI); Grid data resources; Virtual organization (VO); Shibboleth; Object; STANDARDS; SERVICES;
D O I
10.1007/s11227-009-0306-5
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper, we propose a new role-based access control (RBAC) system for Grid data resources in the Open Grid Services Architecture Data Access and Integration (OGSA-DAI). OGSA-DAI is a widely used framework for integrating data resources in Grids. However, OGSA-DAI's identity-based access control causes substantial administration overhead for the resource providers in virtual organizations (VOs) because of the direct mapping between individual Grid users and the privileges on the resources. To solve this problem, we used the Shibboleth, an attribute authorization service, to support RBAC within the OGSA-DAI. In addition, access control policies need to be specified and managed across multiple VOs. For the specification of access control policies, we used the Core and Hierarchical RBAC profile of the eXtensible Access Control Markup Language (XACML); and for distributed administration of those policies and the user-role assignments, we used the Object, Metadata and Artifacts Registry (OMAR). OMAR is based on the e-business eXtensible Markup Language (ebXML) registry specifications developed to achieve interoperable registries and repositories. Our RBAC system provides scalable and fine-grain access control and allows privacy protection. It also supports dynamic delegation of rights and user-role assignments, and reduces the administration overheads for the resource providers because they need to maintain only the mapping information from VO roles to local database roles. Moreover, unnecessary mapping and connections can be avoided by denying invalid requests at the VO level. Performance analysis shows that our RBAC system adds only a small overhead to the existing security infrastructure of OGSA-DAI.
引用
收藏
页码:154 / 179
页数:26
相关论文
共 50 条
  • [1] Role-based access control for a Grid system using OGSA-DAI and Shibboleth
    Vineela Muppavarapu
    Anil L. Pereira
    Soon M. Chung
    [J]. The Journal of Supercomputing, 2010, 54 : 154 - 179
  • [2] Managing role-based access control policies for grid databases in OGSA-DAI using CAS
    Pereira A.L.
    Muppavarapu V.
    Chung S.M.
    [J]. Journal of Grid Computing, 2007, 5 (1) : 65 - 81
  • [3] Research on Heterogeneous Data Access Based on OGSA-DAI
    Zheng CuiFang
    Zhang Qing
    Cheng Zheng
    [J]. Proceedings of the 2016 3rd International Conference on Mechatronics and Information Technology (ICMIT), 2016, 49 : 430 - 434
  • [4] Role-Based Access Control in a Data Grid Using the Storage Resource Broker and Shibboleth
    Vineela Muppavarapu
    Soon M. Chung
    [J]. Journal of Grid Computing, 2009, 7 : 265 - 283
  • [5] Open Grid Services Architecture - Data Access and Integration (OGSA-DAI)
    Husemann, Martin
    Ritter, Norbert
    [J]. Datenbank-Spektrum, 2010, 10 (03) : 159 - 161
  • [6] Role-Based Access Control in a Data Grid Using the Storage Resource Broker and Shibboleth
    Muppavarapu, Vineela
    Chung, Soon M.
    [J]. JOURNAL OF GRID COMPUTING, 2009, 7 (02) : 265 - 283
  • [7] Semantic-Based Access Control for Data Resources in Open Grid Services Architecture: Data Access and Integration (OGSA-DAI)
    Muppavarapu, Vineela
    Chung, Soon M.
    [J]. INTERNATIONAL JOURNAL OF GRID AND HIGH PERFORMANCE COMPUTING, 2014, 6 (02) : 1 - 23
  • [8] Semantic-based Access Control for Grid Data Resources in Open Grid Services Architecture - Data Access and Integration (OGSA-DAI)
    Muppavarapu, Vineela
    Chung, Soon M.
    [J]. 20TH IEEE INTERNATIONAL CONFERENCE ON TOOLS WITH ARTIFICIAL INTELLIGENCE, VOL 2, PROCEEDINGS, 2008, : 315 - 322
  • [9] The design and implementation of Grid database services in OGSA-DAI
    Antonioletti, M
    Atkinson, M
    Baxter, R
    Borley, A
    Hong, NPC
    Collins, B
    Hardman, N
    Hume, AC
    Knox, A
    Jackson, M
    Krause, A
    Laws, S
    Magowan, J
    Paton, NW
    Pearson, D
    Sugden, T
    Watson, P
    Westhead, M
    [J]. CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2005, 17 (2-4): : 357 - 376
  • [10] The Applications of the Flood Forecast System Based on OGSA-DAI
    Shi, Yaqing
    He, Yinjun
    [J]. ADVANCED RESEARCH ON AUTOMATION, COMMUNICATION, ARCHITECTONICS AND MATERIALS, PTS 1 AND 2, 2011, 225-226 (1-2): : 798 - +