首页> 外文会议>International Conference on Advances in Information Security and Its Applications >Fine-Grain Access Control Using Shibboleth for the Storage Resource Broker
【24h】

Fine-Grain Access Control Using Shibboleth for the Storage Resource Broker

机译:使用Shibboleth用于存储资源经纪的细粒程访问控制

获取原文

摘要

In this paper, we propose a fine-grain access control system for data resources in the Storage Resource Broker (SRB). The SRB is a Data Grid management system, which can integrate heterogeneous data resources of virtual organizations (VOs). The SRB stores the access control information of individual users in the Metadata Catalog (MCAT) database. However, because of the specific MCAT schema, this information can only be used by the SRB applications. If VOs also have many non-SRB applications, each with its own storage format for user access control information, it creates a scalability problem with regard to administration. To solve this problem, we use Shibboleth, which is an attribute authorization service. By using Shibboleth, the authentication and access control information of the user can be obtained from the user's home institution. Thus, the administration overhead is reduced because the access control information of individual users is now managed by the user's home institution alone, not by MCAT or applications. The use of Shibboleth allows access control decisions to be made based on the user attributes such as role memberships and institutional affiliation, instead of the identity. Thus, our system provides scalable and fine-grain access control and allows privacy protection. Performance analysis shows that our system adds only a small overhead to the existing security infrastructure of the SRB.
机译:在本文中,我们提出了一种用于存储资源代理(SRB)中的数据资源的精细谷物访问控制系统。 SRB是数据网格管理系统,可以集成虚拟组织(VOS)的异构数据资源。 SRB存储元数据目录(MCAT)数据库中的各个用户的访问控制信息。但是,由于特定的MCAT架构,该信息只能由SRB应用程序使用。如果VOS还具有许多非SRB应用程序,则每个具有自身存储格式的用户访问控制信息,它会在管理方面创建可扩展性问题。为了解决这个问题,我们使用shibboleth,这是一个属性授权服务。通过使用Shibboleth,可以从用户的家庭机构获得用户的认证和访问控制信息。因此,由于用户的家庭机构仅由MCAT或应用程序管理,因此,所以减少了管理开销。 Shibboleth的使用允许基于用户属性(如角色成员资格和机构附属)而不是身份的用户属性进行访问控制决定。因此,我们的系统提供可扩展和精细的谷物访问控制,并允许隐私保护。性能分析表明,我们的系统仅在SRB的现有安全基础架构中增加了一个小开销。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号