Token-based authorization in StoRM WebDAV

被引:0
|
作者
Ceccanti, Andrea [1 ]
Vianello, Enrico [1 ]
Michelotto, Diego [1 ]
机构
[1] INFN CNAF, Viale Berti Pichat 6-2, I-40127 Bologna, Italy
关键词
D O I
10.1051/epjconf/202024504020
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
At the end of May 2017 the Globus Alliance announced that the open-source Globus Toolkit (GT) would be no longer supported by the Globus team at the University of Chicago. This announcement had an obvious impact on WLCG, given the central role of the Globus Security Infrastructure (GSI) and GridFTP in the WLCG data management framework, so discussions started in the appropriate forums on the search for alternatives. At the same time, support for token-based authentication and authorization has emerged as a key requirement for storage elements powering WLCG data centers. In this contribution, we describe the work done to enable token-based authentication and authorization in the StoRM WebDAV service, describing and highlighting the differences between support for external OpenID connect providers, group-based and capability-based authorization schemes, and locally-issued authorization tokens. We discuss how StoRM WebDAV token-based authorization is being exploited in several contexts, from WLCG DOMA activities to other scientific experiments hosted at the INFN Tier-1 data center. In this contribution, we also describe the methodology used to compare Globus GridFTP and StoRM WebDAV and we present initial results confirming how HTTP represent a viable alternative to GridFTP for data transfers also performance-wise.
引用
收藏
页数:6
相关论文
共 50 条
  • [1] A Secure Token-Based Communication for Authentication and Authorization Servers
    Kubovy, Jan
    Huber, Christian
    Jaeger, Markus
    Kueng, Josef
    [J]. FUTURE DATA AND SECURITY ENGINEERING, FDSE 2016, 2016, 10018 : 237 - 250
  • [2] Token-Based Authorization and Authentication for Secure Internet of Vehicles Communication
    Manogaran, Gunasekaran
    Rawal, Bharat S.
    Saravanan, Vijayalakshmi
    Priyan, M. K.
    Xin, Qin
    Shakeel, P.
    [J]. ACM TRANSACTIONS ON INTERNET TECHNOLOGY, 2022, 22 (04)
  • [3] Beyond X.509 Token-based authentication and authorization in practice
    Ceccanti, Andrea
    Vianello, Enrico
    Giacomini, Francesco
    [J]. 24TH INTERNATIONAL CONFERENCE ON COMPUTING IN HIGH ENERGY AND NUCLEAR PHYSICS (CHEP 2019), 2020, 245
  • [4] Beyond X.509: token-based authentication and authorization for HEP
    Ceccanti, Andrea
    Vianello, Enrico
    Caberletti, Marco
    Giacomini, Francesco
    [J]. 23RD INTERNATIONAL CONFERENCE ON COMPUTING IN HIGH ENERGY AND NUCLEAR PHYSICS (CHEP 2018), 2019, 214
  • [5] TBAS: Token-based authorization service architecture in Internet of things scenarios
    Lee, Shih-Hsiung
    Huang, Ko-Wei
    Yang, Chu-Sing
    [J]. INTERNATIONAL JOURNAL OF DISTRIBUTED SENSOR NETWORKS, 2017, 13 (07):
  • [6] MQTT-Auth: a Token-based Solution to Endow MQTT with Authentication and Authorization Capabilities
    Calabretta, Marco
    Pecori, Riccardo
    Vecchio, Massimo
    Veltri, Luca
    [J]. JOURNAL OF COMMUNICATIONS SOFTWARE AND SYSTEMS, 2018, 14 (04) : 320 - 331
  • [7] Token-based platform governance
    Abadi, Joseph
    Brunnermeier, Markus
    [J]. JOURNAL OF FINANCIAL ECONOMICS, 2024, 162
  • [8] Token-based Authentication for Smartphones
    Koschuch, Manuel
    Hudler, Matthias
    Eigner, Hubert
    Saffer, Zsolt
    [J]. PROCEEDINGS OF THE 4TH INTERNATIONAL CONFERENCE ON DATA COMMUNICATION NETWORKING (DCNET 2013), 2013, : 49 - 54
  • [9] Token-based sequential consistency
    Raynal, M
    [J]. COMPUTER SYSTEMS SCIENCE AND ENGINEERING, 2002, 17 (06): : 359 - 365
  • [10] Usability in a Token-Based Ecosystem
    Kwon, Kimin
    Han, Sung H.
    Jang, Hyeji
    Kim, Ju Hwan
    [J]. ADVANCES IN USABILITY, USER EXPERIENCE, WEARABLE AND ASSISTIVE TECHNOLOGY, AHFE 2021, 2021, 275 : 880 - 885