• DocumentCode
    3503653
  • Title

    Toward an On-Demand Restricted Delegation Mechanism for Grids

  • Author

    Ahsant, Mehran ; Basney, Jim ; Mulmo, Olle ; Lee, Adam J. ; Johnsson, Lennart

  • Author_Institution
    Center for Parallel Comput., R. Inst. of Technol., Stockholm
  • fYear
    2006
  • fDate
    28-29 Sept. 2006
  • Firstpage
    152
  • Lastpage
    159
  • Abstract
    Grids are intended to enable cross-organizational interactions which makes grid security a challenging and non-trivial issue. In grids, delegation is a key facility that can be used to authenticate and authorize requests on behalf of disconnected users. In current grid systems there is a tradeoff between flexibility and security in the context of delegation. Applications must choose between limited or full delegation: on one hand, delegating a restricted set of rights reduces exposure to attack but also limits the flexibility/dynamism of the application; on the other hand, delegating all rights provides maximum flexibility but increases exposure. In this paper, we propose an on-demand restricted delegation mechanism, aimed at addressing the shortcomings of current delegation mechanisms by providing restricted delegation in a flexible fashion as needed for grid applications. This mechanism provides an ontology-based solution for tackling one the most challenging issues in security systems, which is the principle of least privileges. It utilizes a callback mechanism, which allows on-demand provisioning of delegated credentials in addition to observing, screening, and auditing delegated rights at runtime. This mechanism provides support for generating delegation credentials with a very limited and well-defined range of capabilities or policies, where a delegator is able to grant a delegatee a set of restricted and limited rights, implicitly or explicitly
  • Keywords
    authorisation; grid computing; message authentication; ontologies (artificial intelligence); organisational aspects; callback mechanism; cross-organizational interactions; grid security; on-demand restricted delegation; ontology; request authentication; request authorisation; Application software; Authorization; Computer science; Computer security; Concurrent computing; Disaster management; Grid computing; Information technology; Ontologies; Runtime;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Grid Computing, 7th IEEE/ACM International Conference on
  • Conference_Location
    Barcelona
  • Print_ISBN
    1-4244-0343-X
  • Electronic_ISBN
    1-4244-0344-8
  • Type

    conf

  • DOI
    10.1109/ICGRID.2006.311010
  • Filename
    4100467