首页> 外文OA文献 >Experiences of Applying Advanced Grid Authorisation Infrastructures
【2h】

Experiences of Applying Advanced Grid Authorisation Infrastructures

机译:应用高级网格授权基础架构的经验

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

The widespread acceptance and uptake of Grid technology can only be achieved if it can be ensured that the security mechanisms needed to support Grid based collaborations are at least as strong as local security mechanisms. The predominant way in which security is currently addressed in the Grid community is through Public Key Infrastructures (PKI) to support authentication. Whilst PKIs address user identity issues, authentication does not provide fine grained control over what users are allowed to do on remote resources (authorisation). The Grid community have put forward numerous software proposals for authorisation infrastructures such as AKENTI [1], CAS [2], CARDEA [3], GSI [4], PERMIS [5,6,7] and VOMS [8,9]. It is clear that for the foreseeable future a collection of solutions will be the norm. To address this, the Global Grid Forum (GGF) have proposed a generic SAML based authorisation API which in principle should allow for fine grained control for authorised access to any Grid service. Experiences in applying and stress testing this API from a variety of different application domains are essential to give insight into the practical aspects of large scale usage of authorisation infrastructures. This paper presents experiences from the DTI funded BRIDGES project [10] and the JISC funded DyVOSE project [11] in using this API with Globus version 3.3 [12] and the PERMIS authorisation infrastructure.
机译:只有能够确保支持基于Grid的协作所需的安全机制至少与本地安全机制一样强大,才能实现Grid技术的广泛接受和接受。当前在网格社区中解决安全性的主要方法是通过公钥基础结构(PKI)支持身份验证。虽然PKI解决了用户身份问题,但身份验证并未对允许用户在远程资源(授权)上执行的操作提供精细的控制。网格社区为授权基础架构提出了许多软件建议,例如AKENTI [1],CAS [2],CARDEA [3],GSI [4],PERMIS [5,6,7]和VOMS [8,9]。显然,在可预见的将来,解决方案的收集将成为常态。为了解决这个问题,全球网格论坛(GGF)提出了一个基于SAML的通用授权API,该API原则上应允许对任何网格服务的授权访问进行细粒度控制。从各种不同的应用程序领域应用和压力测试此API的经验对于深入了解大规模使用授权基础结构的实际方面至关重要。本文介绍了DTI资助的BRIDGES项目[10]和JISC资助的DyVOSE项目[11]在将该API与Globus 3.3版[12]和PERMIS授权基础结构一起使用时的经验。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号