首页> 外文会议>IEEE International Conference on E-Science Workshops >Design and Implementation of a Grid Proxy Auditing Infrastructure
【24h】

Design and Implementation of a Grid Proxy Auditing Infrastructure

机译:网格代理审计基础设施的设计与实现

获取原文

摘要

Single sign-on and delegation of rights are key requirements for modern Grid infrastructures. These requirements are usually facilitated by X.509 und Private-Key Infrastructures (PKI) and proxy certificates. Proxy certificates, however, can be obtained and abused by a malicious third party. There is currently no method for end users to detect such abuse.We have designed a solution that enables a thorough auditing of Grid proxy usage in Globus-based Grids and implemented a service that accepts auditing information via a web service interface and saves them to a back-end database. We introduce modifications to the Grid Security Infrastructure that allow sending audit trails from within Globus components if the user desires to track credential usage. A web-based front-end shows all logged information. With our approach, expert users can now closely monitor how their credentials are used after job submission. This will help build trust in Grid infrastructures and delegated authentication and authorization.
机译:单一登录和权利授权是现代网格基础设施的关键要求。这些要求通常通过X.509缺陷私钥基础设施(PKI)和代理证书促进。然而,可以通过恶意第三方获得并滥用代理证书。目前没有用于最终用户的方法来检测这种滥用。我们设计了一种解决方案,可以在基于Globus的网格中彻底审核网格代理使用,并实现了通过Web服务接口接受审计信息的服务,并将其保存到a后端数据库。如果用户希望跟踪凭据使用,我们将对网格安全基础架构引入网格安全基础架构的修改,从Globus组件中发送审计跟踪。基于Web的前端显示所有记录信息。通过我们的方法,专家用户现在可以密切监视其凭据在作业提交后使用的凭据。这将有助于在网格基础架构和委托身份验证和授权中构建信任。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号