• DocumentCode
    2262684
  • Title

    The Design and Implementation of Standards-Based Grid Single Sign-On Using Federated Identity

  • Author

    Qiang, Weizhong ; Konstantinov, Aleksandr

  • Author_Institution
    Sch. of Comput. Sci. & Technol., Huazhong Univ. of Sci. & Technol., Wuhan, China
  • fYear
    2010
  • fDate
    1-3 Sept. 2010
  • Firstpage
    458
  • Lastpage
    464
  • Abstract
    Security infrastructure is one of the most challenging tasks in the development, integration and deployment of Grid middle wares. Even though the Grid community addresses the security issue through public key infrastructures (PKI) to support mutual authentication using X.509 certificates, maintaining X.509 credentials is not that easy for non-IT-experts, and has proved to be an obstacle for a more wide deployment of Grid technologies. The identity federation is an increasingly popular technology that can facilitate cross-domain single sign-on without requiring the users to maintain any credentials additional to their own institutional accounts. We believe that utilizing identity federation for Grid middle wares is a promising path for the Grid technology to get more widely used. This paper describes a single sign-on infrastructure developed as a part of the Nordu Grid ARC (Advanced Resource Connector) Grid middleware. It adopts the identity federation standard (SAML), as well as Web Service approach. It focuses on a single sign-on solution at the middleware level for users to access Grids by only using their frequently used accounts, without being bothered to maintain X.509 credentials. Users can use their username/password only to access Grids developed in ARC middleware, as well as access Grids developed in other middle wares that requires users to provide X.509 certificates. Moreover, the single sign-on for workflow-like Grid applications (in which intermediate entities act on behalf of users) is also supported. In addition, the performance of single sign-on solution is measured. We identify performance limitations of security-related services inside this solution, and analyse the ways to avoid the limitations. To our knowledge, the work presented in this paper is the first evaluated implementation that utilizes identity federation for Grid usage on the middleware level.
  • Keywords
    Web services; authorisation; grid computing; middleware; public key cryptography; NorduGrid ARC; Web service approach; X.509 certificate; advanced resource connector; federated identity; grid middleware; grid technology; identity federation standard; public key infrastructure; security infrastructure; security related service; standards based grid single sign-on; ARC; Grid middleware; Identity federation; Single Sign-on;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    High Performance Computing and Communications (HPCC), 2010 12th IEEE International Conference on
  • Conference_Location
    Melbourne, VIC
  • Print_ISBN
    978-1-4244-8335-8
  • Electronic_ISBN
    978-0-7695-4214-0
  • Type

    conf

  • DOI
    10.1109/HPCC.2010.91
  • Filename
    5581450