DocumentCode
1863733
Title
Fine-grained access control for GridFTP using SecPAL
Author
Humphrey, Marty ; Park, Sang-Min ; Feng, Jun ; Beekwilder, Norm ; Wasson, Glenn ; Hogg, Jason ; LaMacchia, Brian ; Dillaway, Blair
Author_Institution
Virginia Univ., Charlottesville
fYear
2007
fDate
19-21 Sept. 2007
Firstpage
217
Lastpage
225
Abstract
Grid access control policy languages today are generally one of two extremes: either extremely simplistic, or overly complex and challenging for even security experts to use. In this paper, we explicitly identify requirements for an access control policy language for grid data and then consider six specific data access use-cases that have been problematic in today\´s grids: attribute-based access, role-based access, "role-deny" access, impersonation-based access, delegation-based access, and capability-based access. We evaluate the security policy assertion language (SecPAL) against those requirements, specifically in the context of these six use-cases involving GridFTP.NET. We find that while some of these six use-cases are individually possible via existing Grid authorization systems, we believe that SecPAL uniquely offers a single approach that meets the requirements of a grid access control policy language, thereby creating support for a wide range of expanded scenarios for grid data access.
Keywords
access protocols; authorisation; grid computing; information retrieval; GridFTP.NET; attribute-based access; capability-based access; data access; data transfer protocol; delegation-based access; fine-grained access control; grid access control policy language; grid authorization system; impersonation-based access; role-based access; role-deny access; security policy assertion language; Access control; Access protocols; Authentication; Authorization; Computer science; Computer security; Data security;
fLanguage
English
Publisher
ieee
Conference_Titel
Grid Computing, 2007 8th IEEE/ACM International Conference on
Conference_Location
Austin, Texas
Print_ISBN
978-1-4244-1560-1
Electronic_ISBN
978-1-4244-1560-1
Type
conf
DOI
10.1109/GRID.2007.4354136
Filename
4354136
Link To Document