Title :
CredEx: user-centric credential management for grid and Web services
Author :
Del Vecchio, David ; Humphrey, Marty ; Basney, Jim ; Nagaratnam, Nataraj
Author_Institution :
Dept. of Comput. Sci., Virginia Univ., USA
Abstract :
User authentication is a crucial security component for most computing systems. But since the security needs of different systems vary widely, authentication mechanisms are similarly diverse. In particular, independently-managed Web and grid services vary with regard to the type of security token (credential) used to prove user identity (username/password, X.509 signing, Kerberos, etc.). Forcing users to manage and present credentials manually for each service is tedious, error-prone and potentially insecure. In contrast, we present CredEx, an open-source, standards-based Web service that facilitates the secure storage of credentials and enables the dynamic exchange of different credential types using the WS-Trust token exchange protocol. With CredEx, a user can achieve single sign-on by acquiring a single (default) credential then dynamically exchanging that credential as needed for services that authenticate a different way. We describe the design and implementation of CredEx by focusing on its use in bridging password-based Web services and PKI-based grid services, illustrating how interoperability between these realms can be based upon the WS-Security and WS-Trust specifications.
Keywords :
Internet; authorisation; formal specification; grid computing; message authentication; open systems; public key cryptography; CredEx; Kerberos; PKI-based grid services; WS-Security specifications; WS-Trust specifications; Web services; X.509 signing; credential storage; interoperability; password; security token; token exchange protocol; user authentication; user-centric credential management; username; Application software; Authentication; Computer architecture; Computer science; Computer security; Java; Middleware; National security; Service oriented architecture; Web services;
Conference_Titel :
Web Services, 2005. ICWS 2005. Proceedings. 2005 IEEE International Conference on
Print_ISBN :
0-7695-2409-5
DOI :
10.1109/ICWS.2005.43