• DocumentCode
    1416341
  • Title

    A national-scale authentication infrastructure

  • Author

    Butler, Randy ; Welch, Von ; Engert, Douglas ; Foster, Ian ; Tuecke, Steven ; Volmer, John ; Kesselman, Carl

  • Author_Institution
    Nat. Center for Supercomput. Applications, Illinois Univ., Urbana, IL, USA
  • Volume
    33
  • Issue
    12
  • fYear
    2000
  • fDate
    12/1/2000 12:00:00 AM
  • Firstpage
    60
  • Lastpage
    66
  • Abstract
    Participants in virtual organizations commonly need to share resources such as data archives, computer cycles, and networks, resources usually available only with restrictions based on the requested resource´s nature and the user´s identity. Thus, any sharing mechanism must have the ability to authenticate the user´s identity and determine whether the user is authorized to request the resource. Virtual organizations tend to be fluid, however, so authentication mechanisms must be flexible and lightweight, allowing administrators to quickly establish and change resource-sharing arrangements. Nevertheless, because virtual organizations complement rather than replace existing institutions, sharing mechanisms cannot change local policies and must allow individual institutions to maintain control over their own resources. Our group has created and deployed an authentication and authorization infrastructure that meets these requirements: the Grid Security Infrastructure (I. Foster et al., 1998). GSI offers secure single sign-ons and preserves site control over access policies and local security. It provides its own versions of common applications, such as FTP and remote login, and a programming interface for creating secure applications. Dozens of supercomputers and storage systems already use GSI, a level of acceptance reached by few other security infrastructures.
  • Keywords
    application program interfaces; authorisation; computer communications software; distributed processing; message authentication; FTP; GSI; Grid Security Infrastructure; access policies; authentication mechanisms; authorization infrastructure; computer cycles; data archives; local policies; local security; national-scale authentication infrastructure; programming interface; remote login; requested resource; resource sharing; resource-sharing arrangements; secure applications; secure single sign-ons; security infrastructures; sharing mechanism; site control; storage systems; supercomputers; user authentication; user identity; virtual organizations; Authentication; Authorization; Collaborative software; Computer networks; Educational institutions; Government; National security; Programming profession; Secure storage; Supercomputers;
  • fLanguage
    English
  • Journal_Title
    Computer
  • Publisher
    ieee
  • ISSN
    0018-9162
  • Type

    jour

  • DOI
    10.1109/2.889094
  • Filename
    889094