• DocumentCode
    3503745
  • Title

    OCSP for Grids: Comparing Prevalidation versus Caching

  • Author

    Luna, Jesus ; Manso, Oscar ; Medina, Manel

  • Author_Institution
    Dept. of Comput. Archit., Catalonia Polytech. Univ., Barcelona
  • fYear
    2006
  • fDate
    28-29 Sept. 2006
  • Firstpage
    184
  • Lastpage
    191
  • Abstract
    Nowadays the computational grid uses X.509 digital certificates for a wide variety of security-related tasks, ranging from user authentication to job execution´s delegation. However to ensure a comprehensive security framework such credentials need to be validated so that revoked, suspended and any other compromised certificate will not be allowed to access grid resources. To achieve such tasks great interest is being given to the online certificate status protocol (OCSP) in security workgroups from the global grid forum. In order to better understand the special requirements related with its use in previous work we introduced the Open GRid Ocsp API (OGRO), which provides OCSP support to the Globus toolkit 4. However that research concluded that the grid introduces some special requisites for OCSP´s performance and security. As a follow-up to that work, this paper provides a comprehensive performance comparison between the novel prevalidation and caching mechanisms proposed by the authors to further improve Grid-OCSP. In addition, research about security compliance of both mechanisms around the newest proxy revocation concept is also presented in this work
  • Keywords
    grid computing; protocols; security of data; Globus toolkit 4; X.509 digital certificate; application program interface; caching mechanism; comprehensive security framework; computational grid; global grid forum; grid resource access; online certificate status protocol; prevalidation mechanism; proxy revocation concept; security compliance; security workgroup; Access protocols; Authentication; Buildings; Certification; Computer architecture; Content management; Distributed computing; Grid computing; Information management; Security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Grid Computing, 7th IEEE/ACM International Conference on
  • Conference_Location
    Barcelona
  • Print_ISBN
    1-4244-0343-X
  • Electronic_ISBN
    1-4244-0344-8
  • Type

    conf

  • DOI
    10.1109/ICGRID.2006.311014
  • Filename
    4100471