Scalability Issues in PMI Delegation
نویسندگان
چکیده
The Canadian Department of National Defence (DND) is shifting its methods for the delegation and exercise of authority from paper-based to electronic-based means. DND has deployed a commercial PKI but there is no general technical solution presently employed by DND for access control or electronic authorization of workflow in distributed processing environments. The aim of this research is to show how an authorization system, or privilege management infrastructure (PMI), can be used to support business processes DND. The results are expected to be applicable to large enterprises in general. The research demonstrates how ITU-T standard X.509 can be used to support DND authority and delegation models. The investigation involves the analysis of the key authorizations within a specific DND problem domain. The X.509 standard and concepts from role-based access control form the basis of the PMI design. This involves the use of attribute certificates to control the specification and delegation of privileges. A novel interpretation of X.509 attribute certificates is proposed that provides separate hierarchies of responsibility for the management and delegation of roles. The results provide insight into, and quantification of, the complexity of the resulting delegation chains. The use of a roles based model for delegation is seen as being important to the scaling of PMI to service large enterprises with mature, complex authority structures. If the processing complexity can be managed, the flexibility of being able to model the actual privilege delegation paths in an organization is an advantage of a rolebased model.
منابع مشابه
1st Annual PKI Research Workshop---Proceedings
The Canadian Department of National Defence (DND) is shifting its methods for the delegation and exercise of authority from paper-based to electronic-based means. DND has deployed a commercial PKI but there is no general technical solution presently employed by DND for access control or electronic authorization of workflow in distributed processing environments. The aim of this research is to s...
متن کاملEnabling Attribute Delegation in Ubiquitous Environments
When delegation is implemented using the attribute certificates in a Privilege Management Infrastructure (PMI) [2, 11, 4], it is possible to reach a considerable level of distributed functionality. However, the approach is not flexible enough for the requirements of ubiquitous environments. The PMI can become a too complex solution for devices such as smartphones and PDAs, where resources are l...
متن کاملDesign of a Mobile Agent-Based Workflow Management System
This paper deals with several architectural issues on a mobile agent-based workflow management system(WFMS). We mainly focus on performance and scalability issues among various architectural issues. We point out three major design issues that are indispensable for designing a mobile agent-based WFMS and find solutions for the issues. We propose an efficient design strategy based on the solution...
متن کاملDyVOSE Project: Experiences in Applying Privilege Management Infrastructures
Privilege Management Infrastructures (PMI) are emerging as a necessary alternative to authorization through Access Control Lists (ACL) as the need for finer grained security on the Grid increases in numerous domains. The 2-year JISC funded DyVOSE Project has investigated applying PMIs within an e-Science education context. This has involved establishing a Grid Computing module as part of Glasgo...
متن کاملPMI: A Scalable Parallel Process-Management Interface for Extreme-Scale Systems
Parallel programming models on large-scale systems require a scalable system for managing the processes that make up the execution of a parallel program. The process-management system must be able to launch millions of processes quickly when starting a parallel program and must provide mechanisms for the processes to exchange the information needed to enable them communicate with each other. MP...
متن کامل