首页> 外文会议>Advances in information security and assurance >Fine-Grain Access Control Using Shibboleth for the Storage Resource Broker
【24h】

Fine-Grain Access Control Using Shibboleth for the Storage Resource Broker

机译:使用Shibboleth进行细粒度访问控制的存储资源代理

获取原文
获取原文并翻译 | 示例

摘要

In this paper, we propose a fine-grain access control system for data resources in the Storage Resource Broker (SRB). The SRB is a Data Grid management system, which can integrate heterogeneous data resources of virtual organizations (VOs). The SRB stores the access control information of individual users in the Metadata Catalog (MCAT) database. However, because of the specific MCAT schema, this information can only be used by the SRB applications. If VOs also have many non-SRB applications, each with its own storage format for user access control information, it creates a scalability problem with regard to administration. To solve this problem, we use Shibboleth, which is an attribute authorization service. By using Shibboleth, the authentication and access control information of the user can be obtained from the user's home institution. Thus, the administration overhead is reduced because the access control information of individual users is now managed by the user's home institution alone, not by MCAT or applications. The use of Shibboleth allows access control decisions to be made based on the user attributes such as role memberships and institutional affiliation, instead of the identity. Thus, our system provides scalable and fine-grain access control and allows privacy protection. Performance analysis shows that our system adds only a small overhead to the existing security infrastructure of the SRB.
机译:在本文中,我们为存储资源代理(SRB)中的数据资源提出了一种细粒度的访问控制系统。 SRB是一个数据网格管理系统,可以集成虚拟组织(VO)的异构数据资源。 SRB将单个用户的访问控制信息存储在元数据目录(MCAT)数据库中。但是,由于特定的MCAT模式,此信息只能由SRB应用程序使用。如果VO还具有许多非SRB应用程序,每个应用程序都有用于用户访问控制信息的自己的存储格式,则它会在管理方面造成可伸缩性问题。为了解决此问题,我们使用Shibboleth,这是一种属性授权服务。通过使用Shibboleth,可以从用户的家庭机构获取用户的身份验证和访问控制信息。因此,减少了管理开销,因为单个用户的访问控制信息现在仅由用户的家庭机构而不是MCAT或应用程序管理。 Shibboleth的使用允许基于用户属性(例如角色成员资格和机构隶属关系)而非身份来做出访问控制决策。因此,我们的系统提供了可扩展的细粒度访问控制,并提供了隐私保护。性能分析表明,我们的系统仅在SRB的现有安全基础结构中增加了很小的开销。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号