Naming and sharing resources across administrative boundaries

نویسندگان

  • Jonathan R. Howell
  • Robert Gray
  • Doug McIlroy
  • Margo Seltzer
  • Roger Sloboda
چکیده

I tackle the problem of naming and sharing resources across administrative boundaries. Conventional systems manifest the hierarchy of typical administrative structure in the structure of their own mechanism. While natural for communication that follows hierarchical patterns, such systems interfere with naming and sharing that cross administrative boundaries, and therefore cause headaches for both users and administrators. I propose to organize resource naming and security, not around administrative domains, but around the sharing patterns of users. The dissertation is organized into four main parts. First, I discuss the challenges and tradeoffs involved in naming resources and consider a variety of existing approaches to naming. Second, I consider the architectural requirements for user-centric sharing. I evaluate existing systems with respect to these requirements. Third, to support the sharing architecture, I develop a formal logic of sharing that captures the notion of restricted delegation. Restricted delegation ensures that users can use the same mechanisms to share resources consistently, regardless of the origin of the resource, or with whom the user wishes to share the resource next. A formal semantics gives unambiguous meaning to the logic. I apply the formalism to the Simple Public Key Infrastructure and discuss how the formalism either supports or discourages potential extensions to such a system. Finally, I use the formalism to drive a user-centric sharing implementation for distributed systems. I show how this implementation enables end-to-end authorization, a feature that makes heterogeneous distributed systems more secure and easier to audit. Conventionally, gateway services that bridge administrative domains, add abstraction, or translate protocols typically impede the flow of authorization information from client to server. In contrast, end-to-end authorization enables us to build gateway services that preserve authorization information, hence we reduce the size of the trusted computing base and enable more effective auditing. I demonstrate my implementation and show how it enables end-to-end authorization across various boundaries. I measure my implementation and argue that its performance tracks that of similar authorization mechanisms without end-to-end structure. I conclude that my user-centric philosophy of naming and sharing benefits both users and administrators.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Secure data sharing across portals: experiences from OneVRE.

Research and higher education are facing an on-going transformation of practice resulting in the need for effective collaboration and sharing of resources within and across disciplinary and geographical boundaries. Portal technologies and portal-based virtual research and learning environments (VREs and VLEs) already have become standard infrastructures within a large number of research communi...

متن کامل

Object Based Middleware for Grid Computing

Problem statement: “Grid” computing has emerged as an important new field, distinguished from conventional distributed computing by its focus on large-scale resource sharing, innovative applications and, in some cases, high-performance orientation. The role of middleware is to ease the task of designing, programming and managing distributed applications by providing a simple, consistent and int...

متن کامل

Distributed Modelling and Simulation for collaborative E-science in Grid Infrastructure

E-science is collaborative science that is made possible by the sharing across the Internet of resources that is often very compute intensive, often very data intensive and crosses organizational and administrative boundaries. The semantic grid annotates the grid with metadata describing the resources it makes available. Semantic grid aims to incorporate the advantages of the grid, semantic web...

متن کامل

Mash Me Up, Mash Me Down: Restructuring Email for Content Sharing and Collaboration in Distributed Teams

Distributed teams working across organizational boundaries often experience difficulties in sharing digital materials that are essential to their work. Although work deliverables require content co-production and exchange, we find that differing sociotechnical practices, user access restrictions to file servers and divergent naming and filing practices impede smooth workflow operations. In this...

متن کامل

User authentication and remote execution across administrative domains

A challenge in today's Internet is providing easy collaboration across administrative boundaries. Using and sharing resources between individuals in different administrative domains should be just as easy and secure as sharing them within a single domain. This thesis presents a new authentication service and a new remote login and execution utility that address this challenge. The authenticatio...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2000