• DocumentCode
    3503431
  • Title

    Using Workflow for Dynamic Security Context Management in Grid-based Applications

  • Author

    Demchenko, Yuri ; Gommans, Leon ; de Laat, Cees ; Taal, Arie ; Wan, Alfred ; Mulmo, Olle

  • Author_Institution
    Syst. & Network Eng. Group, Amsterdam Univ.
  • fYear
    2006
  • fDate
    28-29 Sept. 2006
  • Firstpage
    72
  • Lastpage
    79
  • Abstract
    This paper presents ongoing research and current results on the development of flexible access control infrastructures for complex resource provisioning in grid-based collaborative applications and on-demand network services provisioning. We investigate the use of workflow concepts for the required orchestration of multiple grid resources and/or services across multiple administrative and security domains. In particular, workflow execution and management tools can be used to track security context changes that are dependent on the application domain, execution stage defined policies, or user and/or service attributes. The paper discusses what specific functionality should be added to grid-oriented authorization frameworks to handle such dynamic service-related security contexts. As an example, the paper explains how such functionality can be achieved in the GAAA Authorization framework and GAAA toolkit. Suggestions are given about integration with the Globus Toolkit´s authorization framework. Additionally, the paper analyses what possibilities of expressing and handling dynamic security contexts are available in XACML and SAML, and how the VO concept can be used for managing dynamic security associations of users and resources. The paper is based on experiences gained from major grid based and grid oriented projects such as EGEE, NextGrid, Collaboratory.nl and GigaPort Research on Network
  • Keywords
    authorisation; grid computing; groupware; SAML; XACML; access control; authorization frameworks; collaborative applications; grid-based applications; on-demand network services; security context management; workflow execution; Access control; Application software; Authorization; Collaboration; Computer network management; Context-aware services; Grid computing; Middleware; Resource management; Security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Grid Computing, 7th IEEE/ACM International Conference on
  • Conference_Location
    Barcelona
  • Print_ISBN
    1-4244-0343-X
  • Electronic_ISBN
    1-4244-0344-8
  • Type

    conf

  • DOI
    10.1109/ICGRID.2006.311000
  • Filename
    4100457