• DocumentCode
    2118330
  • Title

    Policy Based Access Control in Dynamic Grid-based Collaborative Environment

  • Author

    Demchenko, Y. ; Gommans, Leon ; Tokmakoff, Andrew ; Buuren, Rene Van

  • Author_Institution
    University of Amsterdam
  • fYear
    2006
  • fDate
    14-17 May 2006
  • Firstpage
    64
  • Lastpage
    73
  • Abstract
    This paper describes the design and development of a flexible, customer-driven, security infrastructure for Gridbased Collaborative Environments. The paper proposes further development of the access control model built around a service or resource provisioning agreement (e.g., an experiment or project) that is used as a basis for an instant access control policy definition and virtual association of users and resources. Workflow management technology is considered as a solution for dynamic security context management during the lifetime of an experiment. The paper analyses the required functionality and suggests extensions to the generic AAA Authorisation framework in order to support complex collaboration scenarios in dynamic virtualised environments. The paper provides implementation details on the use of XACML for fine-grained access control policy definition for complex resources and team-based role management, and SAML for secure credentials exchange. In addition, the paper discusses how the Virtual Organisations (VO) concept can be used for experiment-based dynamic security association management. The proposed technical solutions are intended to be compatible and interoperable with the current implementation of the Grid security middleware in the Globus Toolkit and gLite. The paper is based on experiences gained from major Grid-based and Gridoriented projects in collaborative applications and complex resource provisioning.
  • Keywords
    Grid-based Collaborative Environment; Policy-based access control; RBAC; SAML; XACML; workflow; Access control; Authorization; Collaboration; Collaborative work; Context-aware services; Middleware; Resource management; Security; Technology management; Web services; Grid-based Collaborative Environment; Policy-based access control; RBAC; SAML; XACML; workflow;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Collaborative Technologies and Systems, 2006. CTS 2006. International Symposium on
  • Print_ISBN
    0-9785699-0-3
  • Type

    conf

  • DOI
    10.1109/CTS.2006.59
  • Filename
    1644117