• DocumentCode
    1230004
  • Title

    Cooperative Secondary Authorization Recycling

  • Author

    Wei, Qiang ; Ripeanu, Matei ; Beznosov, Konstantin

  • Author_Institution
    Dept. of Electr. & Comput. Eng., Univ. of British Columbia, Vancouver, BC
  • Volume
    20
  • Issue
    2
  • fYear
    2009
  • Firstpage
    275
  • Lastpage
    288
  • Abstract
    As enterprise systems, Grids, and other distributed applications scale up and become increasingly complex, their authorization infrastructures--based predominantly on the request-response paradigm--are facing the challenges of fragility and poor scalability. We propose an approach where each application server recycles previously received authorizations and shares them with other application servers to mask authorization server failures and network delays. This paper presents the design of our cooperative secondary authorization recycling system and its evaluation using simulation and prototype implementation. The results demonstrate that our approach improves the availability and performance of authorization infrastructures. Specifically, by sharing authorizations, the cache hit rate--an indirect metric of availability--can reach 70 percent, even when only 10 percent of authorizations are cached. Depending on the deployment scenario, the average time for authorizing an application request can be reduced by up to a factor of two compared with systems that do not employ cooperation.
  • Keywords
    authorisation; grid computing; groupware; access control; authorization server failures; cooperative secondary authorization recycling; distributed applications; network delays; Access control; CSAR; Distributed Systems; Performance of Systems; SAAM; Security and Protection; access control; authorization recycling; cooperation.; cooperative secondary authorization recycling; cooperative security;
  • fLanguage
    English
  • Journal_Title
    Parallel and Distributed Systems, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1045-9219
  • Type

    jour

  • DOI
    10.1109/TPDS.2008.80
  • Filename
    4527241