DocumentCode
419379
Title
Using virtual organizations membership system with EDG´s grid security and database access
Author
Niinimaki, Marko ; White, John ; De Cerff, WimSom ; Hahkala, Joni ; Niemi, Tapio ; Pitkanen, Mikko
Author_Institution
Helsinki Inst. of Phys., CERN, Geneva, Switzerland
fYear
2004
fDate
30 Aug.-3 Sept. 2004
Firstpage
517
Lastpage
522
Abstract
We describe the European data grid´s (EDGs) Java security system and spitfire database access system giving special emphasis on the virtual organization technologies. These technologies create a feasible framework for authentication and authorization in distributed grid applications. A virtual organization (VO) is a collection of people in the same administrative domain. A user can belong to many virtual organizations and have a different role (user, client, administrator, ..). in each of them. An authorization of a user to different services within a VO is based on the user´s identity and a service called a virtual organization membership service (VOMS) that maps these identities with roles. The user proves his identity over the Internet using authentication process. The user normally authenticates using his credentials, which comprise of a certificate chain and a private key. In grid systems, the user usually authenticates using proxy credentials that are derived from the actual credentials. The proxy credentials comprise of the user´s certificate chain added with a proxy certificate and a proxy private key. In the proxy creation process, the user´s VO information, including groups and roles, is included into the proxy certificate. In order to use these proxy certificates with VO information we have created an authorization system and to demonstrate the usage we have extended the functionality spitfire, a relational database front end. This involves assigning the user a database role (read, write, update..). based on the VO information in his certificate. There is also a GUI for configuring the authorization service. The earth observation team´s database access for ozone profile validation is used here as an example of an application.
Keywords
Internet; Java; authorisation; graphical user interfaces; grid computing; relational databases; virtual enterprises; EDG grid security; GUI; Internet; Java security system; authentication process; authorization system; distributed grid application; ozone profile validation; proxy private key; relational database; spitfire database access system; user certificate; virtual organization; virtual organization membership service; Authentication; Authorization; Data security; Distributed databases; Grid computing; Internet; Java; Meteorology; Physics; Relational databases;
fLanguage
English
Publisher
ieee
Conference_Titel
Database and Expert Systems Applications, 2004. Proceedings. 15th International Workshop on
ISSN
1529-4188
Print_ISBN
0-7695-2195-9
Type
conf
DOI
10.1109/DEXA.2004.1333527
Filename
1333527
Link To Document