• DocumentCode
    2414951
  • Title

    Using SAML and XACML for Complex Authorisation Scenarios in Dynamic Resource Provisioning

  • Author

    Demchenko, Yuri ; Gommans, Leon ; De Laat, Cees

  • Author_Institution
    Syst. & Network Eng. Group, Amsterdam Univ.
  • fYear
    2007
  • fDate
    10-13 April 2007
  • Firstpage
    254
  • Lastpage
    262
  • Abstract
    This paper presents ongoing research and current results on the development of flexible access control infrastructures for complex resource provisioning in grid-based collaborative applications and on-demand network services provisioning. The paper identifies basic resource provisioning models and specifies major requirements to authorisation (AuthZ) service infrastructure to support these models and focus on two main issues - AuthZ session support and policy expression for complex resource models. For the practical implementation, we investigate the use of two popular standards SAML and XACML for complex authorisation scenarios in dynamic resource provisioning across multiple administrative and security domains. The paper describes a proposed XML based AuthZ ticket format that is capable of supporting extended AuthZ session context. Additionally, the paper discusses what specific functionality should be added to existing grid-oriented authorization frameworks to handle dynamic domain-related security context including AuthZ session support. The paper is based on experiences gained from major grid based and grid oriented projects such as EGEE, NextGrid, Phosphorus and GigaPort research on network
  • Keywords
    XML; authorisation; grid computing; resource allocation; AuthZ; Extensible Access Control Markup Language; SAML; Security Assertion Markup Language; XACML; access control; dynamic resource provisioning; grid-based collaborative applications; grid-oriented authorization; on-demand network services provisioning; Access control; Authentication; Authorization; Collaboration; Middleware; Resource management; Security; Systems engineering and theory; Web services; XML;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Availability, Reliability and Security, 2007. ARES 2007. The Second International Conference on
  • Conference_Location
    Vienna
  • Print_ISBN
    0-7695-2775-2
  • Type

    conf

  • DOI
    10.1109/ARES.2007.157
  • Filename
    4159811