DocumentCode :
1897640
Title :
PEACE-VO: A Secure Policy-Enabled Collaboration Framework for Virtual Organizations
Author :
Li, Jianxin ; Huai, Jinpeng ; Hu, Chunming
Author_Institution :
Beihang Univ., Beijing
fYear :
2007
fDate :
10-12 Oct. 2007
Firstpage :
199
Lastpage :
208
Abstract :
The increasing complexity and dynamics of grid environments have posed great challenges for secure and privacy-preserving collaboration in a virtual organization. In this paper, we propose PEACE-VO, a secure policy-enabled collaboration framework for virtual organizations. PEACE-VO employs role mapping to define trust relationships across autonomous domains. Nevertheless, a critical issue emerges when the system applies role mapping, which is potential policy conflict in a local domain. We first develop two concepts to depict such possible conflicts within the collaboration policy. Next, we propose a fully distributed evaluation algorithm to detect potential policy conflicts, which does not require domains to disclose their full local security policies and therefore preserves critical domain privacy. Finally, we design two dedicated protocols for virtual organization management and authorization services, respectively. We have successfully implemented the PEACE-VO framework with two fundamental protocols, i.e., VO management protocol and service authorization protocol, in the CROWN grid. Comprehensive experimental study shows our approach is scalable and efficient.
Keywords :
authorisation; data privacy; grid computing; groupware; virtual enterprises; CROWN grid; PEACE-VO; dedicated protocols; distributed evaluation algorithm; grid environments; policy-enabled collaboration framework security; privacy-preserving collaboration; role mapping; service authorization protocol; virtual organization management; Access control; Algorithm design and analysis; Authorization; Computer science; International collaboration; Permission; Privacy; Protection; Protocols; Security;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Reliable Distributed Systems, 2007. SRDS 2007. 26th IEEE International Symposium on
Conference_Location :
Beijing
ISSN :
1060-9857
Print_ISBN :
0-7695-2995-X
Type :
conf
DOI :
10.1109/SRDS.2007.12
Filename :
4365696
Link To Document :
بازگشت