首页> 外文期刊>Journal of Grid Computing >Managing Role-Based Access Control Policies for Grid Databases in OGSA-DAI Using CAS
【24h】

Managing Role-Based Access Control Policies for Grid Databases in OGSA-DAI Using CAS

机译:使用CAS管理OGSA-DAI中网格数据库的基于角色的访问控制策略

获取原文
获取原文并翻译 | 示例

摘要

In this paper, we present a role-based access control method for accessing databases through the Open Grid Services Architecture – Data Access and Integration (OGSA-DAI) framework. OGSA-DAI is an efficient Grid-enabled middleware implementation of interfaces and services to access and control data sources and sinks. However, in OGSA-DAI, access control causes substantial administration overhead for resource providers in virtual organizations (VOs) because each of them has to manage a role-map file containing authorization information for individual Grid users. To solve this problem, we used the Community Authorization Service (CAS) provided by the Globus Toolkit to support the role-based access control (RBAC) within OGSA-DAI. CAS uses the Security Assertion Markup Language (SAML). Our method shows that CAS can support a wide range of security policies using role-privileges, role hierarchies, and constraints. The resource providers need to maintain only the mapping information from VO roles to local database roles and the local policies in the role-map files, so that the number of entries in the role-map file is reduced dramatically. Also, unnecessary authentication, mapping and connections can be avoided by denying invalid requests at the VO level. Thus, our access control method provides increased manageability for a large number of users and reduces day-to-day administration tasks of the resource providers, while they maintain the ultimate authority over their resources. Performance analysis shows that our method adds very little overhead to the existing security infrastructure of OGSA-DAI.
机译:在本文中,我们提出了一种基于角色的访问控制方法,用于通过开放网格服务体系结构-数据访问和集成(OGSA-DAI)框架访问数据库。 OGSA-DAI是用于访问和控制数据源和接收器的接口和服务的高效的,基于网格的中间件实现。但是,在OGSA-DAI中,访问控制会给虚拟组织(VO)中的资源提供者带来大量管理开销,因为它们每个人都必须管理一个角色映射文件,其中包含针对各个Grid用户的授权信息。为了解决此问题,我们使用了Globus Toolkit提供的社区授权服务(CAS)来支持OGSA-DAI中基于角色的访问控制(RBAC)。 CAS使用安全性声明标记语言(SAML)。我们的方法表明,CAS可以使用角色特权,角色层次结构和约束来支持各种安全策略。资源提供者只需要维护角色映射文件中从VO角色到本地数据库角色和本地策略的映射信息,从而可以大大减少角色映射文件中的条目数。另外,通过拒绝VO级别的无效请求,可以避免不必要的身份验证,映射和连接。因此,我们的访问控制方法为大量用户提供了增强的可管理性,并减少了资源提供者的日常管理任务,同时他们保持了对其资源的最终授权。性能分析表明,我们的方法为OGSA-DAI的现有安全基础架构增加了很少的开销。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号