DocumentCode :
3144507
Title :
RBAC for High Performance Computing Systems Integration in Grid Computing and Cloud Computing
Author :
Pereira, Anil L.
Author_Institution :
Southwestern Oklahoma State Univ., Weatherford, OK, USA
fYear :
2011
fDate :
16-20 May 2011
Firstpage :
914
Lastpage :
921
Abstract :
This paper describes a Role-based Access Control (RBAC) mechanism for distributed High Performance Computing (HPC) systems that will facilitate scalable evaluation, management and enforcement of access control policies. The RBAC mechanism forms an enhanced security framework for Grids and Clouds that will allow for interoperability between technologies in the two domains. The mechanisms being proposed here are important because the current lack of software tools and security standards in accessing distributed HPC systems and transporting Large Data Sets can add immensely to overheads in data processing or data integration times. RBAC models make policy management scalable and by virtue of being modular allow for more sophisticated access control models to be integrated with them. This paper shows how existing security standards can be leveraged for the specification and management of RBAC policies with the aim to allow disparate applications, systems and security domains to interoperate. The extensible Access Control Markup Language (XACML) can be used for policy specification and management across disparate organizations and the Security Assertion Markup Language (SAML) can be used for authentication and authorization assertions across the same. Both standards can be leveraged to facilitate policy management and enforcement, and delegation of rights. Authorization servers like Shibboleth can be leveraged for use as RBAC system components.
Keywords :
authorisation; cloud computing; grid computing; message authentication; open systems; specification languages; RBAC mechanism; RBAC model; RBAC policy; Security Assertion Markup Language; XACML; access control policy; authentication; authorization; cloud computing; data integration; data processing; distributed HPC system; distributed high performance computing; eXtensible Access Control Markup Language; grid computing; interoperability; large data set; policy enforcement; policy management; policy specification; role-based access control; security framework; security standard; software tool; Authorization; Cloud computing; Computational modeling; Organizations; Standards;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Parallel and Distributed Processing Workshops and Phd Forum (IPDPSW), 2011 IEEE International Symposium on
Conference_Location :
Shanghai
ISSN :
1530-2075
Print_ISBN :
978-1-61284-425-1
Electronic_ISBN :
1530-2075
Type :
conf
DOI :
10.1109/IPDPS.2011.237
Filename :
6008938
Link To Document :
بازگشت