The Design, Development and Application of a Proxy Credential Auditing Infrastructure for Collaborative Research
نویسندگان
چکیده
Single sign-on and delegation of privileges are fundamental tenets upon which e-Infrastructures and Grid-based research more generally have been based. The realisation of single sign-on and delegation of privileges in accessing resources such as the UK e-Science National Grid Service (NGS http://www.ngs.ac.uk) and other national facilities is typically facilitated by X.509-based Public Key Infrastructures (PKI) and exploitation of proxy certificates. This model can be categorised by authentication-oriented access and usage of resources. It is the case however that proxy certificates, can potentially be obtained and abused by a malicious third party without the knowledge of the holder. There is currently no method for end users to detect such misuse. In this paper we describe a novel proxy auditing solution that addresses this issue directly. We describe the design and implementation of this solution and illustrate its application in widely distributed and heterogeneous research environments. We focus in particular on the needs and requirements of such a facility in the ESRC funded Data Management through eSocial Science (DAMES www.dames.org.uk) project, where secure access and monitoring of social simulations and associated data sets are required by the researchers and associated data providers.
منابع مشابه
Application of international energy efficiency standards for energy auditing in a University buildings
This study seeks to provide insights on understanding the contemporary problems of energy efficiency in Ukrainian universities by developing a comprehensive energy efficiency management framework that encompasses its participating subjects, objects and key drivers along with suggesting its implementation mechanism and tools. Emphasis should be given that the current situation of inefficient and...
متن کاملPRODUCT DEVELOPMENT IN PRODUCTION – NETWORKS
This paper presents an overview of new approaches in rapid product development in production networks from design points of view. The manufacturing industries are changing their focus to global sourcing as a means to improve performance and enhance competitiveness. Some partnerships created with this strategy improve product development through collaborative design. With the advent of e-Commerc...
متن کاملA Collaborative Stochastic Closed-loop Supply Chain Network Design for Tire Industry
Recent papers in the concept of Supply Chain Network Design (SCND) have seen a rapid development in applying the stochastic models to get closer to real-world applications. Regaring the special characteristics of each product, the stracture of SCND varies. In tire industry, the recycling and remanufacturing of scraped tires lead to design a closed-loop supply chain. This paper proposes a two-st...
متن کاملJoint Policy Management and Auditing in Virtual Organizations
A major problem facing organizations using gridcomputing models is the reluctance to participate in multiorganizational collaborative environments due to security concerns, such as unauthorized access, protection of intellectual property, and fair resource usage. The Joint control of Virtual Organizations (JoVO) framework enables multiple organizations to form a unified VO, with jointly agreed,...
متن کاملProxy Restrictions for Grid Usage
The scale and power of Grid infrastructures makes them an inviting target for attack. Even if the Grid software is secure the Grid infrastructure is vulnerable via operating system vulnerabilities and misconfiguration. One of the worst results of the exploit of these vulnerabilities is user proxy credential compromise. This paper describes a pragmatic and simple way, using proxy certificate ext...
متن کامل