首页> 外文OA文献 >Using SAML and XACML for complex authorisation scenarios in dynamic resource provisioning
【2h】

Using SAML and XACML for complex authorisation scenarios in dynamic resource provisioning

机译:将SAML和XACML用于动态资源供应中的复杂授权方案

摘要

This paper presents ongoing research and current results on the development of flexible access control infrastructures for complex resource provisioning in grid-based collaborative applications and on-demand network services provisioning. The paper identifies basic resource provisioning models and specifies major requirements to authorisation (AuthZ) service infrastructure to support these models and focus on two main issues - AuthZ session support and policy expression for complex resource models. For the practical implementation, we investigate the use of two popular standards SAML and XACML for complex authorisation scenarios in dynamic resource provisioning across multiple administrative and security domains. The paper describes a proposed XML based AuthZ ticket format that is capable of supporting extended AuthZ session context. Additionally, the paper discusses what specific functionality should be added to existing grid-oriented authorization frameworks to handle dynamic domain-related security context including AuthZ session support. The paper is based on experiences gained from major grid based and grid oriented projects such as EGEE, NextGrid, Phosphorus and GigaPort research on network.
机译:本文介绍了有关基于网格的协作应用程序中的复杂资源供应和按需网络服务供应的灵活访问控制基础结构开发的正在进行的研究和当前结果。本文确定了基本的资源供应模型,并指定了对授权(AuthZ)服务基础结构的主要要求以支持这些模型,并着重于两个主要问题-AuthZ会话支持和复杂资源模型的策略表达。对于实际的实现,我们调查了在两个管理和安全域之间的动态资源供应中,两种流行的标准SAML和XACML在复杂授权方案中的使用情况。本文描述了一种建议的基于XML的AuthZ票证格式,该格式能够支持扩展的AuthZ会话上下文。此外,本文讨论了应将哪些特定功能添加到现有的面向网格的授权框架中,以处理与动态域相关的安全上下文,包括AuthZ会话支持。本文基于从大型基于网格和面向网格的项目(例如EGEE,NextGrid,Phosphorus和GigaPort网络研究)中获得的经验。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号