首页> 外文OA文献 >A holistic approach to network security in OGSA-based grid systems
【2h】

A holistic approach to network security in OGSA-based grid systems

机译:基于OGsa的网格系统中网络安全的整体方法

摘要

Grid computing technologies facilitate complex scientific collaborations between globally dispersed parties, which make use of heterogeneous technologies and computing systems. However, in recent years the commercial sector has developed a growing interest in Grid technologies. Prominent Grid researchers have predicted Grids will grow into the commercial mainstream, even though its origins were in scientific research. This is much the same way as the Internet started as a vehicle for research collaboration between universities and government institutions, and grew into a technology with large commercial applications. Grids facilitate complex trust relationships between globally dispersed business partners, research groups, and non-profit organizations. Almost any dispersed “virtual organization” willing to share computing resources can make use of Grid technologies. Grid computing facilitates the networking of shared services; the inter-connection of a potentially unlimited number of computing resources within a “Grid” is possible. Grid technologies leverage a range of open standards and technologies to provide interoperability between heterogeneous computing systems. Newer Grids build on key capabilities of Web-Service technologies to provide easy and dynamic publishing and discovery of Grid resources. Due to the inter-organisational nature of Grid systems, there is a need to provide adequate security to Grid users and to Grid resources. This research proposes a framework, using a specific brokered pattern, which addresses several common Grid security challenges, which include: Providing secure and consistent cross-site Authentication and Authorization; Single-sign on capabilities to Grid users; Abstract iii; Underlying platform and runtime security, and; Grid network communications and messaging security. These Grid security challenges can be viewed as comprising two (proposed) logical layers of a Grid. These layers are: a Common Grid Layer (higher level Grid interactions), and a Local Resource Layer (Lower level technology security concerns). This research is concerned with providing a generic and holistic security framework to secure both layers. This research makes extensive use of STRIDE - an acronym for Microsoft approach to addressing security threats - as part of a holistic Grid security framework. STRIDE and key Grid related standards, such as Open Grid Service Architecture (OGSA), Web-Service Resource Framework (WS-RF), and the Globus Toolkit are used to formulate the proposed framework.
机译:网格计算技术促进了全球分散的各方之间复杂的科学协作,这些协作利用了异构技术和计算系统。但是,近年来,商业领域对网格技术越来越感兴趣。著名的网格研究人员预测,即使网格起源于科学研究,网格也将成长为商业主流。这与Internet最初是大学和政府机构之间进行研究合作的工具并逐渐发展为具有大量商业应用的技术的方式相同。网格促进了全球分散的业务合作伙伴,研究小组和非营利组织之间的复杂信任关系。几乎任何愿意共享计算资源的分散的“虚拟组织”都可以利用Grid技术。网格计算有助于共享服务的联网; “网格”内可能无限数量的计算资源之间的互连是可能的。网格技术利用一系列开放标准和技术来提供异构计算系统之间的互操作性。较新的网格基于Web服务技术的关键功能,可以轻松,动态地发布和发现网格资源。由于网格系统的组织间性质,需要为网格用户和网格资源提供足够的安全性。这项研究提出了一种使用特定代理模式的框架,该框架解决了一些常见的Grid安全挑战,包括:提供安全且一致的跨站点身份验证和授权;网格用户的单点登录功能;摘要iii;基础平台和运行时安全性;以及网格网络通信和消息传递安全性。可以将这些网格安全挑战视为包含网格的两个(建议的)逻辑层。这些层是:公用网格层(较高级别的Grid交互)和本地资源层(较低级别的技术安全问题)。这项研究与提供通用的整体安全框架以保护两层安全有关。这项研究广泛使用STRIDE-微软解决安全威胁的方法的缩写-作为整体Grid安全框架的一部分。使用STRIDE和与网格相关的关键标准,例如开放网格服务体系结构(OGSA),Web服务资源框架(WS-RF)和Globus工具包,来制定建议的框架。

著录项

  • 作者

    Loutsios Demetrios;

  • 作者单位
  • 年度 2006
  • 总页数
  • 原文格式 PDF
  • 正文语种 English
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号