首页> 外文会议>IEEE International Symposium on High Performance Distributed Computing >Identity boxing: secure user-level containment for the grid
【24h】

Identity boxing: secure user-level containment for the grid

机译:Identity Boleing:对网格的安全用户级Conceptment

获取原文

摘要

Today, a public key infrastructure allows grid users to be identified with strong cryptographic credentials and and a descriptive, globally-unique name such as /O=UnivNowhere/CN=Fred. This powerful security infrastructure allows users to perform a single login and then access a variety of remote resources on the grid without further authentication steps. However, once connected to a specific system, a user's grid credentials must somehow be mapped to a local namespace. This creates a significant burden upon the administrator of each site to manage a continuously-changing user list. Large systems have worked around this by employing the old insecure standby of shared user accounts. A single user may be known by a different account name at every single site that he or she accesses, in addition to a variety of identity names given by certificate authorities. In order to access a resource, the user may need to have a local account generated. In order to share resources, each user must know the local identities of users that he/she wishes to share with. To solve these problems, we introduce the technique of identity boxing. An identity box is a well-defined execution space in which all processes and resources are associated with an external identity that need not have any relationship to the set of local accounts. That is, within an identity box, a program runs with an explicit grid identity string rather than with a simple integer UID. As a program executes, all access controls are performed using the high level name rather than the low-level account information. A single Unix account may be used to securely manage several identity boxes simultaneously, thus eliminating the need to services to run as root merely to change identities.
机译:今天,公钥基础架构允许网格用户与强大的加密证书,并和描述的,全球唯一的名称,如/ O = UnivNowhere / CN =弗雷德被识别。这种强大的安全基础架构允许用户执行单个登录,然后在没有进一步的身份验证步骤的情况下访问网格上的各种远程资源。然而,一旦连接到特定的系统中,用户的网格证书必须以某种方式映射到本地命名空间。这在每个站点的管理员身上创造了重大负担来管理不断更改的用户列表。通过使用共享用户帐户的旧不安全的待机,大型系统遍及此目的。除了证书颁发机构给出的各种身份名称之外,他或她访问的每个站点都可以通过不同的帐户名称所知。为了访问资源,用户可能需要生成本地帐户。为了共享资源,每个用户必须知道他/她希望与众不同的用户的本地身份。为了解决这些问题,我们介绍了身份拳击技术。身份框是一个明确的执行空间,其中所有进程和资源都与外部标识相关联,不需要与本地帐户集合任何关系。也就是说,在身份框中,程序以显式网格标识字符串运行,而不是使用简单的整数UID运行。作为程序执行,所有访问控制都是使用高级名称而不是低级帐户信息执行的。可以使用单个UNIX帐户来同时安全地管理多个身份框,从而消除了仅仅以改变标识作为root运行的服务。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号