首页> 外文学位 >Role-based access control for the Open Grid Services Architecture-Data Access and Integration (OGSA-DAI).
【24h】

Role-based access control for the Open Grid Services Architecture-Data Access and Integration (OGSA-DAI).

机译:开放式网格服务体系结构的基于角色的访问控制-数据访问和集成(OGSA-DAI)。

获取原文
获取原文并翻译 | 示例

摘要

Grid has emerged recently as an integration infrastructure for the sharing and coordinated use of diverse resources in dynamic, distributed virtual organizations (VOs). A Data Grid is an architecture for the access, exchange, and sharing of data in the Grid environment. In this dissertation, role-based access control (RBAC) systems for heterogeneous data resources in Data Grid systems are proposed. The Open Grid Services Architecture - Data Access and Integration (OGSA-DAI) is a widely used framework for the integration of heterogeneous data resources in Grid systems.; However, in the OGSA-DAI system, access control causes substantial administration overhead for resource providers in VOs because each of them has to manage the authorization information for individual Grid users. Its identity-based access control mechanisms are severely inefficient and too complicated to manage because the direct mapping between users and privileges is transitory. To solve this problem, (1) the Community Authorization Service (CAS), provided by the Globus toolkit, and (2) the Shibboleth, an attribute authorization service, are used to support RBAC in the OGSA-DAI system. The Globus Toolkit is widely used software for building Grid systems.; Access control policies need to be specified and managed across multiple VOs. For this purpose, the Core and Hierarchical RBAC profile of the eXtensible Access Control Markup Language (XACML) is used; and for distributed administration of those policies, the Object, Metadata and Artifacts Registry (OMAR) is used. OMAR is based on the e-business eXtensible Markup Language (ebXML) registry specifications developed to achieve interoperable registries and repositories.; The RBAC systems allow quick and easy deployments, privacy protection, and the centralized and distributed management of privileges. They support scalable, interoperable and fine-grain access control services; dynamic delegation of rights; and user-role assignments. They also reduce the administration overheads for resource providers because they need to maintain only the mapping information from VO roles to local database roles. Resource providers maintain the ultimate authority over their resources. Moreover, unnecessary mapping and connections can be avoided by denying invalid requests at the VO level. Performance analysis shows that our RBAC systems add only a small overhead to the existing security infrastructure of OGSA-DAI.
机译:网格最近成为一种集成基础结构,用于在动态分布式虚拟组织(VO)中共享和协调使用各种资源。数据网格是一种用于在网格环境中访问,交换和共享数据的体系结构。本文提出了一种基于角色的访问控制(RBAC)系统,用于数据网格系统中的异构数据资源。开放网格服务体系结构-数据访问和集成(OGSA-DAI)是一种广泛使用的框架,用于在网格系统中集成异构数据资源。但是,在OGSA-DAI系统中,访问控制会给VO中的资源提供者带来可观的管理开销,因为它们每个人都必须管理单个Grid用户的授权信息。它的基于身份的访问控制机制效率极低,并且管理起来过于复杂,因为用户和特权之间的直接映射是暂时的。为了解决此问题,(1)由Globus工具包提供的社区授权服务(CAS),以及(2)属性授权服务Shibboleth用于在OGSA-DAI系统中支持RBAC。 Globus Toolkit是用于构建Grid系统的广泛使用的软件。需要在多个VO之间指定和管理访问控制策略。为此,使用了可扩展访问控制标记语言(XACML)的核心和分层RBAC配置文件。对于这些策略的分布式管理,使用对象,元数据和工件注册表(OMAR)。 OMAR基于电子商务可扩展标记语言(ebXML)注册表规范而开发,旨在实现可互操作的注册表和存储库。 RBAC系统允许快速,轻松地进行部署,保护隐私以及对权限进行集中和分布式管理。它们支持可扩展,可互操作和细粒度的访问控制服务;动态授权和用户角色分配。它们还减少了资源提供者的管理开销,因为它们只需要维护从VO角色到本地数据库角色的映射信息。资源提供者对其资源拥有最终的授权。此外,可以通过拒绝VO级别的无效请求来避免不必要的映射和连接。性能分析表明,我们的RBAC系统仅对OGSA-DAI的现有安全基础架构增加了很小的开销。

著录项

  • 作者

    Pereira, Anil L.;

  • 作者单位

    Wright State University.;

  • 授予单位 Wright State University.;
  • 学科 Computer Science.
  • 学位 Ph.D.
  • 年度 2007
  • 页码 103 p.
  • 总页数 103
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类 自动化技术、计算机技术;
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号