首页> 外文会议>Supercomputing, 2005. Proceedings of the ACM/IEEE SC 2005 Conference >Identity Boxing: A New Technique for Consistent Global Identity
【24h】

Identity Boxing: A New Technique for Consistent Global Identity

机译:身份拳击:一致的全局身份的新技术

获取原文

摘要

Today, users of the grid may easily authenticate themselves to computing resources around the world using a public key security infrastructure. However, users are forced to employ a patchwork of local identities, each assigned by a different local authority. This forces each grid system to provide a mapping from global to local identities, creating a significant administrative burden and inhibiting many possibilities of data sharing. To remedy this, we introduce the technique of identity boxing. This technique allows a high-level identity to be attached directly to each process and resource that a user employs, rendering the local account name irrelevant. This allows a grid user to be known by the same name consistently at all sites, thus reducing administrative burdens and enabling new forms of sharing. We have implemented identity boxing at the user level within a secure system-call interposition agent and applied it to a distributed storage and execution system. The performance overhead of this implementation is only 0.7 to 6.5 percent for a selection of scientific applications, but as high as 35 percent for a metadata-intensive software build. We conclude with some reflections on how the operating system might be modified to better support grid computing.
机译:如今,网格的用户可以使用公钥安全基础结构轻松地向世界各地的计算资源进行身份验证。但是,用户被迫采用本地身份的拼凑而成,每个本地身份由不同的本地权限分配。这迫使每个网格系统提供从全局标识到本地标识的映射,这将产生巨大的管理负担,并抑制了数据共享的许多可能性。为了解决这个问题,我们介绍了身份拳击技术。此技术允许将高级身份直接附加到用户使用的每个进程和资源,从而使本地帐户名称无关紧要。这允许在所有站点上以相同的名称一致地认识网格用户,从而减轻了管理负担并启用了新的共享形式。我们已经在安全的系统调用插入代理中的用户级别实现了身份装箱,并将其应用于分布式存储和执行系统。对于某些科学应用程序,此实现的性能开销仅为0.7%至6.5%,而对于元数据密集型软件,则高达35%。最后,我们对如何修改操作系统以更好地支持网格计算进行了总结。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号