• DocumentCode
    2320259
  • Title

    Fine-Grained Access Control in the Chirp Distributed File System

  • Author

    Donnelly, Patrick ; Thain, Douglas

  • Author_Institution
    Dept. of Comput. Sci. & Eng., Univ. of Notre Dame, Notre Dame, IN, USA
  • fYear
    2012
  • fDate
    13-16 May 2012
  • Firstpage
    33
  • Lastpage
    40
  • Abstract
    Although the distributed file system is a widely used technology in local area networks, it has seen less use on the wide area networks that connect clusters, clouds, and grids. One reason for this is access control: existing file system technologies require either the client machine to be fully trusted, or the client process to hold a high value user credential, neither of which is practical in large scale systems. To address this problem, we have designed a system for fine-grained access control which dramatically reduces the amount of trust required of a batch job accessing a distributed file system. We have implemented this system in the context of the Chirp user-level distributed file system used in clusters, clouds, and grids, but the concepts can be applied to almost any other storage system. The system is evaluated to show that performance and scalability are similar to other authentication methods. The paper concludes with a discussion of integrating the authentication system into workflow systems.
  • Keywords
    authorisation; client-server systems; cloud computing; computer network security; distributed databases; grid computing; network operating systems; software performance evaluation; storage management; trusted computing; authentication system; batch job; chirp user-level distributed filesystem; client process; fine-grained access control; high value user credential; large scale systems; local area networks; performance evaluation; scalability; storage system; trust reduction; trusted client machine; wide area networks; workflow systems; Access control; Authentication; Chirp; Permission; Public key; Registers; Servers; authentication; distributed; filesystem; grid; proxy; ticket;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Cluster, Cloud and Grid Computing (CCGrid), 2012 12th IEEE/ACM International Symposium on
  • Conference_Location
    Ottawa, ON
  • Print_ISBN
    978-1-4673-1395-7
  • Type

    conf

  • DOI
    10.1109/CCGrid.2012.128
  • Filename
    6217402