首页> 外文期刊>International journal of grid and high performance computing >Semantic-Based Access Control for Data Resources in Open Grid Services Architecture: Data Access and Integration (OGSA-DAI)
【24h】

Semantic-Based Access Control for Data Resources in Open Grid Services Architecture: Data Access and Integration (OGSA-DAI)

机译:开放式网格服务体系结构中基于语义的数据资源访问控制:数据访问和集成(OGSA-DAI)

获取原文
获取原文并翻译 | 示例
       

摘要

This paper proposes a semantic-based access control system for the data resources in the Open Grid Services Architecture - Data Access and Integration (OGSA-DAI). OGSA-DAI is a widely used middleware for integrating data resources in Grids. However, the identity-based access control in OGSA-DAI causes substantial overhead for the resource providers in virtual organizations (VOs), because the access control information of individual users has to be maintained by each resource provider. To solve these problems, the authors propose a semantic-based access control system using Shibboleth and ontology. Shibboleth, an attribute authorization service, is used to manage the user attributes, and the Web Ontology Language (OWL) is used to represent the ontology of the data resources and users. By using ontology, VOs can resolve the differences in their terminologies and specify access control policies based on concepts and user roles, instead of individual resources and user identities. As a result, the administration overhead of the resource providers is reduced considerably. In addition, the extensible Access Control Markup Language (XACML) is used to specify the access control policies uniformly across multiple Vos. The authors also developed an XACML policy administration tool that allows the administrators to create, update, and manage XACML policies. The performance analysis shows that our proposed system adds only a small overhead to the existing security mechanism of OGSA -DAI.
机译:本文提出了一种基于语义的访问控制系统,用于开放网格服务体系结构中的数据资源-数据访问和集成(OGSA-DAI)。 OGSA-DAI是一种广泛使用的中间件,用于在Grid中集成数据资源。但是,OGSA-DAI中基于身份的访问控制会给虚拟组织(VOs)中的资源提供者带来大量开销,因为每个用户都必须维护每个用户的访问控制信息。为了解决这些问题,作者提出了一种使用Shibboleth和本体的基于语义的访问控制系统。 Shibboleth是一种属性授权服务,用于管理用户属性,而Web本体语言(OWL)用于表示数据资源和用户的本体。通过使用本体,VO可以解决其术语上的差异,并基于概念和用户角色而不是单个资源和用户身份来指定访问控制策略。结果,大大减少了资源提供者的管理开销。另外,可扩展的访问控制标记语言(XACML)用于跨多个Vos统一指定访问控制策略。作者还开发了XACML策略管理工具,该工具允许管理员创建,更新和管理XACML策略。性能分析表明,我们提出的系统只增加了OGSA -DAI现有安全机制的少量开销。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号