Native Code Security for Grid Services
نویسندگان
چکیده
In modern on demand grid computing scenarios, services from different organisations will potentially run on the same web service engine of a grid node. Secure isolation of data and code of different service instances is a vital requirement in such an environment, since mutual trust cannot be assumed between all involved parties. For Java based Grid applications the Java virtual machine offers sandboxing vacilities, however the common occurrence of native code (e.g. C/C++, Fortran) in business and scientific Grid applications leads to a number of security issues which are not handled by the basic Java security mechanisms. In this paper, we analyze the threat scenarios that emanate from native code in a service-oriented Grid scenario. A novel security architecture is presented, which enables a fine grained confinement of native components of Grid applications into a secure environment for protecting the hosting system as well as other service instances. Although our work focuses on Grid services, it is also relevant for any hosting scenario in which multiple web services using native code components are deployed in the same service container.
منابع مشابه
Native Code Security for Java Grid Services
In modern on demand grid computing scenarios, services from different organisations will potentially run on the same web service engine of a grid node. Secure isolation of data and code of different service instances is a vital requirement in such an environment, since mutual trust cannot be assumed between all involved parties. For Java based Grid applications the Java virtual machine offers s...
متن کاملMyGridFTP: A Zero-Deployment GridFTP Client Using the .NET Framework
Large-scale scientific and engineering applications are increasingly being hosted as Grid services using Globus middleware complying to the Open Grid Services Architecture (OGSA) framework. In order for users to fully embrace Grid applications, seamless access to Grid services is required. In working towards this aim we present the design and implementation of Grid clients that utilise the lang...
متن کاملIntegrating Legacy Authorization Systems into the Grid: A Case Study Leveraging AzMan and ADAM
While much of the Grid security community has focused on developing new authorization systems, the real challenge is often integrating legacy authorization systems with Grid software. The existing authorization system might not understand Grid authentication, might not scale to Grid-level usage, might not be able to understand the operations that are requested to be authorized, and might requir...
متن کاملA Lightweight Privacy-preserving Authenticated Key Exchange Scheme for Smart Grid Communications
Smart grid concept is introduced to modify the power grid by utilizing new information and communication technology. Smart grid needs live power consumption monitoring to provide required services and for this issue, bi-directional communication is essential. Security and privacy are the most important requirements that should be provided in the communication. Because of the complex design of s...
متن کاملMiddleware Framework for Secure Grid Application in Mobile Web Services Environment
Mobile Grid Service is the extension of Grid Service. It is defined as: it is an intelligent code service wandering in grid nodes to accomplish certain task and provide certain service. Mobile Grid Service provides a series of standard interfaces and conforms specific conventions to solve such problems as: mobile service discovery, dynamic service creation, lifetime management, notification, mo...
متن کامل