Sciweavers

CONCURRENCY
2008

Coordinating access control in grid services

13 years 11 months ago
Coordinating access control in grid services
We describe how to control the cumulative use of distributed grid resources by using coordination aware policy decision points (coordinated PDPs) and an SQL database to hold "coordination" data. When access to a resource is granted, obligations in the security policy ensure that the coordination database is updated. The coordination database is a normal grid service, thereby providing distributed access to the coordinated PDPs. Access to the databases is secured by the Grid Security Infrastructure (GSI) and its own PDP, so that only authorized users (the coordinated PDPs) can access it. A coordinated PDP is imbedded into the Globus Toolkitv4 authorization chain as a custom PDP so that any grid service can be protected by a security policy that provides a coordination capability. Each coordinated PDP uses the services of an uncoordinated PDP to make its access control decisions, so that any existing stateless PDP can be supplemented with a coordination capability. We provide ...
David W. Chadwick, Linying Su, Romain Laborde
Added 09 Dec 2010
Updated 09 Dec 2010
Type Journal
Year 2008
Where CONCURRENCY
Authors David W. Chadwick, Linying Su, Romain Laborde
Comments (0)