首页> 外文会议>International Workshop on Organizational Security Aspects >Security Concept and Implementation for a Cloud Based E-science Infrastructure
【24h】

Security Concept and Implementation for a Cloud Based E-science Infrastructure

机译:基于云的电子科学基础设施的安全概念与实现

获取原文

摘要

In this paper we present a novel Kerberos-based security concept for heterogeneous distributed e-Science infrastructures. The e-Science infrastructure we have recently developed is currently being tested by the breath gas analysis community, whose activities are based on large-scale collaborations. In many e-Science domains personal related data (e.g. patient data) is involved and therefore privacy and security is very important. Several publications mentioned that it is straightforward to add additional security to an existing infrastructure by the means of Kerberos. Our experience shows that it is not really true; at our e-Science infrastructure we discovered the following key problems: (a) to forward Kerberos tickets and (b) to use Kerberos within a cloud infrastructure. Exactly such challenges are addressed by this paper. The central aspect of the security concept presented is the authentication of the user to the lowest level (e.g. database) and not only to the first level of the e-Science services. We have to consider that our infrastructure involves several research centers with their own scientific private data. The designed security concept was implemented and tested with a cloud-based code execution framework to be able to concurrently execute problem solving environment codes (e.g. MATLAB, R, Octave). The resulting system supports EC2 compatible cloud infrastructures (e.g. AWS, Eucalyptus), enabling them to be combined to build a hybrid cloud. This paper describes several challenges and their solution including how to (a) use client authentication through all levels of the system, (b) guarantee secured execution of time consuming cloud based analysis, and (c) inject security credentials into dynamically created VM-instances.
机译:在本文中,我们为异构分布式电子科学基础设施提出了一种基于Kerberos的安全概念。我们最近开发的电子科学基础设施目前正在由呼气气体分析社区进行测试,其活动基于大规模合作。在许多e-science域中,个人相关数据(例如患者数据)涉及,因此隐私和安全性非常重要。通过Kerberos的方式向现有的基础设施添加额外的安全性,提到了几种出版物。我们的经验表明,这并不是真的;在我们的电子科学基础设施中,我们发现了以下关键问题:(a)转发Kerberos票证和(b)以在云基础架构中使用Kerberos。本文提出了恰当的挑战。呈现的安全概念的中心方面是用户对最低级别(例如数据库)的认证,而不仅仅是电子科学服务的第一级。我们必须考虑我们的基础架构涉及几个研究中心与他们自己的科学私人数据。设计并测试了设计的安全概念,并使用基于云的代码执行框架进行了测试,以便能够同时执行解决问题解决环境代码(例如MATLAB,R,Octave)。生成的系统支持EC2兼容的云基础架构(例如AWS,Eucalyptus),使它们能够组合以构建混合云。本文介绍了多项挑战及其解决方案,包括如何(a)通过系统的所有级别使用客户端身份验证,(b)保证耗时的云基于云的分析执行,(c)将安全凭证注入动态创建的VM-实例。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号