首页> 外文会议>International Joint Conference on Computer, Information, and Systems Sciences, and Engineering >An Access Control Model for a Grid Environment Employing Security-as-a-Service Approach
【24h】

An Access Control Model for a Grid Environment Employing Security-as-a-Service Approach

机译:使用“安全即服务”方法的网格环境访问控制模型

获取原文

摘要

There is a continuous effort at addressing security challenges of large scale service oriented computing (SOC) infrastructures like grids. A lot of research efforts towards development of authentication and authorization models for grid systems have been made because existing grid security solutions do not satisfy some desirable access control requirements of distributed services; such as support for multiple security policies. However, most of these security models are domain and/or application specific. Domain/application-specific approach to providing security solution is a duplication of effort, which also increases the cost of developing and maintaining applications. This paper presents the design of an access control model for grid-based system that employs security as a service (SecaaS) approach. By SecaaS approach, each atomic access control function (such as authentication, authorization) will be provided as a reusable service that can be published and subscribed to by different grid entities. In this approach, each admin domain will no longer need to have its own domain-specific access control logic built into it. Whenever an access control service is required the domain administrator subscribes to this service from SecaaS. This approach has a number of benefits, including making changes to security policies dynamically on the fly.
机译:为了解决诸如网格之类的大规模面向服务的计算(SOC)基础结构的安全性挑战,我们正在进行不懈的努力。由于现有的网格安全解决方案不能满足分布式服务的某些期望的访问控制要求,因此已经为网格系统的认证和授权模型的开发进行了大量的研究工作。例如对多种安全策略的支持。但是,大多数这些安全模型是特定于域和/或应用程序的。提供安全解决方案的特定于域/应用程序的方法是重复的工作,这也增加了开发和维护应用程序的成本。本文介绍了采用安全即服务(SecaaS)方法的基于网格的系统的访问控制模型的设计。通过SecaaS方法,每个原子访问控制功能(例如身份验证,授权)将作为可重用服务提供,可以由不同的网格实体发布和订阅。通过这种方法,每个管理域将不再需要内置其自己的特定于域的访问控制逻辑。每当需要访问控制服务时,域管理员都会从SecaaS订阅此服务。这种方法有很多好处,包括动态地动态更改安全策略。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号