Nutzerdefinierte Restriktion delegierter Privilegien im Grid-Computing

نویسنده

  • Stefan Piger
چکیده

This thesis analyses current Grid infrastructures regarding the implemented mechanisms for the delegation of user rights. The results of this analysis are subsequently employed to design an approach for the user-based restriction of delegated rights. Finally, a prototypical implementation of the approach based on a current Grid middleware package is presented. The Grid computing approach pursues the vision of inter-institutional computing and storage infrastructures using standardized access mechanisms. In the future, Grid infrastructures are envisioned to be enhanced by interconnecting existing computing environments with scientific instruments to simplify access to experimental and observational data for postprocessing. The core of Grid infrastructures is Grid middleware, which establishes an abstraction layer between the Grid and individual resources. Grid middlewares —in addition to providing standard interfaces— implement mechanisms to monitor participating systems and provide information about them. Furthermore, load-balancing between resources as well as accounting and billing functionalities are commonly provided. Due to their distributed nature and the availability of substantial resources, Grid infrastructures are attractive attack targets. To guarantee stable and reliable operation, advanced security mechanisms are implemented to establish mandatory encryption of communication connections and mutual authentication of users and services. The utilization of indirectly accessed resources by users requires the employment of delegation mechanisms. Current Grid infrastructures base their delegation functionality on proxy certificates which enable services to act in the users’ name and with the complete scope of their rights. To protect users, the lifetime of proxy certificates is limited. Should they be compromised however, a succesful attacker may act with the complete scope of the user’s right. Current Grid infrastructures offer no mechanisms to restrict the delegated rights. As a direct consequence of these shortcomings, disciplines with high security requirements are subject to tight restrictions in using inter-institutional Grid infrastructures. This in particular affects communities in the biological and medical disciplines which are subjected to strict data privacy regulations when working with personal data. Besides this, abuse of rights can cause negative repercussions for users when significant amounts of resources are consumed as resource usage is typically accounted and the user may be invoiced for it.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

3. Grid Workflow Workshop (GWW 2010)

Im Bereich des Grid Computing stehen Workflows im Fokus zahlreicher Projekte. Allein auf europäischer Ebene wurden und werden viele Projekte zur Entwicklung von geeigneten Werkzeugen, Sprachen und Laufzeitumgebungen für Workflows im GridComputing gefördert. Der dritte Grid Workflow Workshop adressiert sowohl wissenschaftliche als auch betriebliche Workflows im Umfeld des Grid-Computing. Diese d...

متن کامل

Vorwort: Betriebswirtschaftliche Anwendungen des Grid Computing

Entwicklung und Einsatz Grid-basierter betriebswirtschaftlicher Softwarelösungen werfen zahlreiche, bisher nur unzureichend untersuchte Fragen auf. Wann sollten Unternehmen den Einsatz von Grid-Technologien und -werkzeugen erwägen? Welche Vorund Nachteile, welche Chancen und Risiken sind mit einer solchen Entscheidung verbunden? Wie lassen sich Grid-basierte Systeme in bestehende Softwarelandsc...

متن کامل

PrivacyScore

PrivacyScore ist ein öffentliches Web-Portal, mit dem automatisiert überprüft werden kann, ob Webseiten gängige Mechanismen zum Schutz von Sicherheit und Privatheit korrekt implementieren. Im Gegensatz zu existierenden Diensten ermöglicht PrivacyScore, mehrere Webseiten in Benchmarksmiteinander zu vergleichen, die Ergebnisse differenziert und im Zeitverlauf zu analysieren sowie nutzerdefinierte...

متن کامل

Improving Mobile Grid Performance Using Fuzzy Job Replica Count Determiner

Grid computing is a term referring to the combination of computer resources from multiple administrative domains to reach a common computational platform. Mobile Computing is a Generic word that introduces using of movable, handheld devices with wireless communication, for processing data. Mobile Computing focused on providing access to data, information, services and communications anywhere an...

متن کامل

Improving Mobile Grid Performance Using Fuzzy Job Replica Count Determiner

Grid computing is a term referring to the combination of computer resources from multiple administrative domains to reach a common computational platform. Mobile Computing is a Generic word that introduces using of movable, handheld devices with wireless communication, for processing data. Mobile Computing focused on providing access to data, information, services and communications anywhere an...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2008