Conference Proceeding

On Usage Control for GRID Services

Ist. di Inf. e Telematica, Consiglio Naz. delle Ric., Pisa, Italy
05/2009; DOI:10.1109/CSO.2009.479 In proceeding of: Computational Sciences and Optimization, 2009. CSO 2009. International Joint Conference on, Volume: 1
Source: IEEE Xplore

ABSTRACT In recent years, usage control has been proposed as a novel authorization solution for open, heterogeneous, distributed computer environments. Grid is a such environment providing services for seamless sharing and usage of heterogeneous computational resources. Researches have shown that usage control is a viable solution for authorization in Grid. Unfortunately, the implementation of continues usage control for Grid services is not widely presented. In this paper, we present a usage control model and focus on continuous control over Grid services. If a security policy is violated during a service execution, the service should be blocked or terminated. Our approach presents different levels of granularity and enforces coarse and finegrained usage control on generic and computational Grid services. Furthermore, we present an implementation of our prototype based on POLPA policy language and its reasoning authorization engine integrated into Grid services runtime component of Globus Toolkit. Our prototype is facilitated through implementation of service interfaces compliant with OGSA standard and can be easily plugged-in to existing Globus authorization infrastructure.

0 0
 · 
0 Bookmarks
 · 
26 Views

Keywords

approach presents different levels
 
authorization
 
coarse
 
computational Grid services
 
computer environments
 
finegrained usage control
 
Globus authorization infrastructure
 
Globus Toolkit
 
Grid services
 
Grid services runtime component
 
heterogeneous computational resources
 
novel authorization solution
 
POLPA policy language
 
reasoning authorization engine
 
recent years
 
service interfaces compliant
 
usage control
 
usage control model
 
viable solution