首页> 外文会议>International Conference on Availability, Reliability and Security >Using SAML and XACML for Complex Authorisation Scenarios in Dynamic Resource Provisioning
【24h】

Using SAML and XACML for Complex Authorisation Scenarios in Dynamic Resource Provisioning

机译:使用SAML和XACML在动态资源配置中的复杂授权方案

获取原文
获取外文期刊封面目录资料

摘要

This paper presents ongoing research and current results on the development of flexible access control infrastructures for complex resource provisioning in Grid-based collaborative applications and on-demand network services provisioning. The paper identifies basic resource provisioning models and specifies major requirements to Authorisation (AuthZ) service infrastructure to support these models and focus on two main issues - AuthZ session support and policy expression for complex resource models. For the practical implementation, we investigate the use of two popular standards SAML and XACML for complex authorisation scenarios in dynamic resource provisioning across multiple administrative and security domains. The paper describes a proposed XML based AuthZ ticket format that is capable of supporting extended AuthZ session context. Additionally, the paper discusses what specific functionality should be added to existing Grid-oriented authorization frameworks to handle dynamic domain-related security context including AuthZ session support. The paper is based on experiences gained from major Grid based and Grid oriented projects such as EGEE, NextGrid, Phosphorus and GigaPort Research on Network.
机译:本文展示了持续的研究和目前对基于网格的协作应用中复杂资源供应的灵活访问控制基础架构以及按需网络服务供应的开发。本文标识了基本资源配置模型,并指定了授权(Authz)服务基础架构的主要要求,以支持这些模型,并专注于两个主要问题 - 复杂资源模型的Authz会话支持和策略表达式。为了实现实际实现,我们调查了在多个管理和安全域中的动态资源配置中的复杂授权方案的使用对多个流行标准SAML和XACM。本文介绍了一种基于XML的Authz票证格式,其能够支持扩展的Authz会话上下文。此外,本文讨论了应将特定功能添加到现有的面向网格的授权框架中,以处理与Authz会话支持的动态域相关的安全上下文。本文基于基于主要网球和网格导向项目获得的经验,如Egee,NextGrid,磷和Gigaport对网络的研究。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号