Group-based Security in a Federated File System
نویسندگان
چکیده
The SILENUS federated file system was developed by the SORCER research group at Texas Tech University. The distributed file system with its dynamic nature does not require any configuration by the end users and system administrators. Managing security in a metacomputing system is a new challenge. It must be ensured that every user has a valid authentication and authorization to view, modify, and create files in the system spread across many heterogeneous computers that to individual requestor, it looks and acts like a single computer. User management is a must be on a metacomputing system and scale well. Existing user credential databases must be incorporated as secure data services if present. In this paper a new scalable authentication model for federated file systems is described. In this model users authenticate to an authentication service for their identity and a group manager service for their collaborative groups membership. The group manager service provides an authorization token that can be used to invoke service-oriented functionality of the federated file system. The group manager service uses existing user credential databases as its back-end. There may be any number of group manager services on the network with different user administration domains to provide desirable scalability. Multiple replicated group manager services for the same user base can provide for increased reliability. A scaled-down replica called nomadic group manager service provides support for disconnected operations. It contains the necessary credentials for a single user to use the system while being disconnected from the main network.
منابع مشابه
Integrating Multilevel Security Policies in Multilevel Federated Database Systems
Federated database systems solve the problem of sharing information among independent entities. When building and operating such a federated database system, it is necessary to protect data. Because of heterogeneities among security systems of component databases an integration of them is essential, taking into account new security features of the federation itself. This paper describes a multi...
متن کاملEx Vivo Comparison of File Fracture and File Deformation in Canals with Moderate Curvature: Neolix Rotary System versus Manual K-files
Background and Aim: Cleaning and shaping is one of the important steps in endodontic treatment, which has an important role in root canal treatment outcome. This study evaluated the rate of file fracture and file deformation in Neolix rotary system and K-files in shaping of the mesiobuccal canal of maxillary first molars with moderate curvature. Materials and Methods: In this ex vivo exp...
متن کاملInternet Engineering Task Force (ietf) Administration Protocol for Federated File Systems Admin Protocol for Federated File Systems
This document describes the administration protocol for a federated file system (FedFS) that enables file access and namespace traversal across collections of independently administered fileservers. The protocol specifies a set of interfaces by which fileservers with different administrators can form a fileserver federation that provides a namespace composed of the file systems physically hoste...
متن کاملArchitecting Information Security Services for Federated Satellite Systems
This paper investigates the provision of information security services in Federated Satellite Systems. We initiate the discussion by describing possible threats that the system faces, as well as the speci c security services that have to be provided in order to mitigate them. Next, we de ne a set of ve primal security functions that a federated satellite system has to implement and propose the ...
متن کاملSecurity issues for federated database systems
This paper describes security issues for federated database management systems set up for managing distributed, heterogeneous and autonomous multilevel databases. It builds on our previous work in multilevel secure distributed database management systems and on the results of others’ work in federated database systems. In particular, we define a multilevel secure federated database system and d...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2007