Role-based access control for a Grid system using OGSA-DAI and Shibboleth

被引:5
|
作者
Muppavarapu, Vineela [1 ]
Pereira, Anil L. [1 ]
Chung, Soon M. [1 ]
机构
[1] Wright State Univ, Dept Comp Sci & Engn, Dayton, OH 45435 USA
来源
JOURNAL OF SUPERCOMPUTING | 2010年 / 54卷 / 02期
关键词
Open Grid Services Architecture Data Access and Integration (OGSA-DAI); Grid data resources; Virtual organization (VO); Shibboleth; Object; STANDARDS; SERVICES;
D O I
10.1007/s11227-009-0306-5
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper, we propose a new role-based access control (RBAC) system for Grid data resources in the Open Grid Services Architecture Data Access and Integration (OGSA-DAI). OGSA-DAI is a widely used framework for integrating data resources in Grids. However, OGSA-DAI's identity-based access control causes substantial administration overhead for the resource providers in virtual organizations (VOs) because of the direct mapping between individual Grid users and the privileges on the resources. To solve this problem, we used the Shibboleth, an attribute authorization service, to support RBAC within the OGSA-DAI. In addition, access control policies need to be specified and managed across multiple VOs. For the specification of access control policies, we used the Core and Hierarchical RBAC profile of the eXtensible Access Control Markup Language (XACML); and for distributed administration of those policies and the user-role assignments, we used the Object, Metadata and Artifacts Registry (OMAR). OMAR is based on the e-business eXtensible Markup Language (ebXML) registry specifications developed to achieve interoperable registries and repositories. Our RBAC system provides scalable and fine-grain access control and allows privacy protection. It also supports dynamic delegation of rights and user-role assignments, and reduces the administration overheads for the resource providers because they need to maintain only the mapping information from VO roles to local database roles. Moreover, unnecessary mapping and connections can be avoided by denying invalid requests at the VO level. Performance analysis shows that our RBAC system adds only a small overhead to the existing security infrastructure of OGSA-DAI.
引用
收藏
页码:154 / 179
页数:26
相关论文
共 50 条
  • [21] Grid Learning Management System with Role-Based Access Control
    Somasundaram, Thamarai Selvi
    Manimalar, PriyaaDharshini
    Kannan, G.
    Kumar, Vive
    Sidhan, Mohan
    [J]. FIRST INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING 2009 (ICAC 2009), 2009, : 167 - +
  • [22] Handling Role-based Access Control in the Digital Grid
    Fries, Steffen
    Falk, Rainer
    Bisale, Chaitanya
    [J]. SEVENTH INTERNATIONAL CONFERENCE ON SMART GRIDS, GREEN COMMUNICATIONS AND IT ENERGY-AWARE TECHNOLOGIES (ENERGY 2017), 2017, : 27 - 32
  • [23] Dynamically Authorized Role-Based Access Control for Grid Applications
    YAO Hanbing HU Heping LU Zhengding LI Ruixuan
    [J]. Geo-spatial Information Science, 2006, (03) : 223 - 228
  • [24] Dynamically Authorized Role-Based Access Control for Grid Applications
    Yao Hanbing
    Hu Heping
    Lu Zhengding
    Li Ruixuan
    [J]. GEO-SPATIAL INFORMATION SCIENCE, 2006, 9 (03) : 223 - +
  • [25] A Role-based Access Control Model Supporting Regional Division in Smart Grid System
    Rosic, Daniela
    Lendak, Imre
    Vukmirovic, Srdjan
    [J]. ACTA POLYTECHNICA HUNGARICA, 2015, 12 (07) : 237 - 250
  • [26] Role-Based Access Control Model Supporting Regional Division in Smart Grid System
    Rosic, Daniela
    Novak, Ugljesa
    Vukmirovic, Srdjan
    [J]. 2013 FIFTH INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE, COMMUNICATION SYSTEMS AND NETWORKS (CICSYN), 2013, : 197 - 201
  • [27] Role-based access control for grid database services using the community authorization service
    Pereira, AL
    Muppavarapu, V
    Chung, SM
    [J]. IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2006, 3 (02) : 156 - 166
  • [28] A Role-Based Access Control System Using Attribute-Based Encryption
    Wang, Yong
    Ma, Yuan
    Xiang, Keyu
    Liu, Zhenyan
    Li, Ming
    [J]. 2018 INTERNATIONAL CONFERENCE ON BIG DATA AND ARTIFICIAL INTELLIGENCE (BDAI 2018), 2018, : 128 - 133
  • [29] A Role-Based Access Control System for Intelligent Buildings
    Xue, Nian
    Jiang, Chenglong
    Huang, Xin
    Liu, Dawei
    [J]. NETWORK AND SYSTEM SECURITY, 2017, 10394 : 710 - 720
  • [30] Service Infrastructure for Cross-Matching Distributed Datasets Using OGSA-DAI and TAP
    Holliman, Mark
    Alemu, Tilaye
    Hume, Alastair
    van Hemert, Jano
    Mann, Robert G.
    Noddle, Keith
    Valkonen, Laura
    [J]. ASTRONOMICAL DATA ANALYSIS SOFTWARE AND SYSTEMS XX, 2011, 442 : 579 - +