A VO-friendly, Community-based Authorization Framework Part 1: Use Cases, Requirements, and Approach
نویسندگان
چکیده
The era of massive surveys like LSST are driving the increasing necessity for astronomical research that is network-based and features remote data access and remote data analysis. With the development of the Virtual Observatory (VO) come the tools to make remote science easier. The VO community is large—thousands of potential users, and traditional authorization models based on individuals will simply not scale. In traditional models, authorization policies are enforced solely using permissions associated with login accounts; thus, a user or group must exist for every set of authorizations. This three-part document proposes an application of the Globus Community Authorization Service (CAS) to centralize authorization policies that must be enforced by a number of resources, minimizing the authorization intelligence needed by the resources. To ease the burden on users, we introduce the concept of weak certificates that enable a sufficient level of access control common in many existing web based applications today but which is compatible with stricter grid security practices. In part 1, we describe three general use cases that we aim to address, list requirements, and summarize our approach using the Globus CAS. In part 2, we describe how the CASbased model can be applied to a single organization that manages many distributed services and users within a single administration domain. In part 3, we extend the model for use in VO applications that span across administration domains; in this model, VO users can establish a single login that can be used with any compliant portal or service.
منابع مشابه
Trait-Based Authorization Requirements for the Session Initiation Protocol (SIP)
Status of This Memo This memo provides information for the Internet community. It does not specify an Internet standard of any kind. Distribution of this memo is unlimited. Abstract This document lays out a set of requirements related to trait-based authorization for the Session Initiation Protocol (SIP). While some authentication mechanisms are described in the base SIP specification, trait-ba...
متن کاملMaintaining the Correctness of the Linux Security Modules Framework
In this paper, we present an approach, supported by software tools, for maintaining the correctness of the Linux Security Modules (LSM) framework (the LSM community is aiming for inclusion in Linux 2.5). The LSM framework consists of a set of function call hooks placed at locations in the Linux kernel that enable greater control of user-level processes’ use of kernel functionality, such as is n...
متن کاملEnhancing the Scalability of the Community Authorization Service for Virtual Organizations
Grid computing has emerged as a special form of distributed computing and is distinguished from conventional distributed computing by its focus on dynamic, large-scale resource sharing over a wide geographic distribution. Grid Computing System (GCS) is a distributed system infrastructure over which distributed applications with crossorganization resource sharing are operated. Grid applications ...
متن کاملUsing SAML-Based VOMS for Authorization within Web Services-Based UNICORE Grids
In recent years, the Virtual Organization Membership Service (VOMS) emerged within Grid infrastructures providing dynamic, fine-grained, access control needed to enable resource sharing across Virtual Organization (VOs). VOMS allows to manage authorization information in a VO scope to enforce agreements established between VOs and resource owners. VOMS is used for authorization in the EGEE and ...
متن کاملAuthorization Strategies for Virtualized Environments in Grid Computing Systems
The development of adequate security solutions, and in particular of authentication and authorization techniques, for grid computing systems is a challenging task. Recent trends of service oriented architectures (SOA), where users access grids through a science gateway — a web service that serves as a portal between users of a virtual organizations (VO) and the various computation resources, fu...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2005