• DocumentCode
    2387504
  • Title

    CredEx: user-centric credential management for grid and Web services

  • Author

    Del Vecchio, David ; Humphrey, Marty ; Basney, Jim ; Nagaratnam, Nataraj

  • Author_Institution
    Dept. of Comput. Sci., Virginia Univ., USA
  • fYear
    2005
  • fDate
    11-15 July 2005
  • Firstpage
    149
  • Abstract
    User authentication is a crucial security component for most computing systems. But since the security needs of different systems vary widely, authentication mechanisms are similarly diverse. In particular, independently-managed Web and grid services vary with regard to the type of security token (credential) used to prove user identity (username/password, X.509 signing, Kerberos, etc.). Forcing users to manage and present credentials manually for each service is tedious, error-prone and potentially insecure. In contrast, we present CredEx, an open-source, standards-based Web service that facilitates the secure storage of credentials and enables the dynamic exchange of different credential types using the WS-Trust token exchange protocol. With CredEx, a user can achieve single sign-on by acquiring a single (default) credential then dynamically exchanging that credential as needed for services that authenticate a different way. We describe the design and implementation of CredEx by focusing on its use in bridging password-based Web services and PKI-based grid services, illustrating how interoperability between these realms can be based upon the WS-Security and WS-Trust specifications.
  • Keywords
    Internet; authorisation; formal specification; grid computing; message authentication; open systems; public key cryptography; CredEx; Kerberos; PKI-based grid services; WS-Security specifications; WS-Trust specifications; Web services; X.509 signing; credential storage; interoperability; password; security token; token exchange protocol; user authentication; user-centric credential management; username; Application software; Authentication; Computer architecture; Computer science; Computer security; Java; Middleware; National security; Service oriented architecture; Web services;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Web Services, 2005. ICWS 2005. Proceedings. 2005 IEEE International Conference on
  • Print_ISBN
    0-7695-2409-5
  • Type

    conf

  • DOI
    10.1109/ICWS.2005.43
  • Filename
    1530793