首页> 外文学位 >A security framework for distributed batch computing.
【24h】

A security framework for distributed batch computing.

机译:分布式批处理计算的安全框架。

获取原文
获取原文并翻译 | 示例

摘要

There is an assumption in the design and implementation of many distributed batch computing systems that once a task enters the system, the system can be fully trusted by all participants, even when the system spans administrative boundaries. As a result, execution hosts and other intermediaries have no way of independently confirming the origin of tasks, attackers have an incentive to attack the intermediaries who handle the tasks, and when results are returned to users, they have no way of determining where and how those results were computed. Users need to be able to specify policies that limit the actions their tasks can perform and the uses to which their delegated credentials can be put, and ways to link these policies to their jobs and credentials.;In this thesis, I address these shortcomings by introducing and analyzing a framework of mechanisms that can be used to reduce the trustworthiness requirements of components in the system. The framework protects execution hosts by making the association between a particular task and a particular user explicit rather than implicit. It protects end users by permitting them to specify a policy regarding task confidentiality and integrity to accompany their tasks. Finally, it protects intermediaries by making them less attractive to attackers. With relaxed trustworthiness requirements on intermediaries, the benefits of sharing tasks and resources between different administrative domains may be realized without relaxing security policies.
机译:许多分布式批处理计算系统的设计和实现中都假设一旦任务进入系统,即使系统跨越管理边界,所有参与者也可以完全信任该系统。结果,执行主机和其他中介没有办法独立地确认任务的来源,攻击者有动机去攻击处理任务的中介,并且当结果返回给用户时,他们无法确定地点和方式。这些结果是经过计算的。用户需要能够指定策略来​​限制其任务可以执行的操作以及可以委派其委派凭据的用途,以及将这些策略链接到其工作和凭据的方式。在本文中,我将通过以下方式解决这些缺点:介绍和分析可用于降低系统中组件的可信赖性要求的机制框架。该框架通过使特定任务和特定用户之间的关联显式而非隐式地保护执行主机。它允许最终用户指定有关任务机密性和完整性的策略来保护最终用户,以保护最终用户。最后,它通过降低中介对攻击者的吸引力来保护中介。通过放宽对中介机构的信任度要求,可以在不放松安全策略的情况下实现在不同管理域之间共享任务和资源的好处。

著录项

  • 作者

    Alderman, Ian D.;

  • 作者单位

    The University of Wisconsin - Madison.;

  • 授予单位 The University of Wisconsin - Madison.;
  • 学科 Computer Science.
  • 学位 Ph.D.
  • 年度 2010
  • 页码 112 p.
  • 总页数 112
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号