An Authorization Architecture Oriented to Engineering and Scientific Computation in Grid Environments
نویسندگان
چکیده
Large-scale scientific and engineering computation is normally accomplished through the interaction of collaborating groups and diverse heterogeneous resources. Grid computing is emerging as an applicable paradigm, whilst, there is a critical challenge of authorization in the grid infrastructure. This paper proposes a Parallelized Subtask-level Authorization Service architecture (PSAS) based on the least privilege principle, and presents a contextaware authorization approach and a flexible task management mechanism. The minimization of the privileges is conducted by decomposing the parallelizable task and re-allotting the privileges required for each subtask. The dynamic authorization is carried out by constructing a multi-value community policy and adaptively transiting the mapping. Besides applying a relevant management policy, a delegation mechanism collaboratively performs the authorization delegation for task management. In the enforcement mechanisms involved, the authors have extended the RSL specification and the proxy certificate, and have modified the Globus gatekeeper, jobmanager and the GASS library to allow authorization callouts. Therefore the authorization requirement of an application is effectively met in the presented architecture.
منابع مشابه
Authorization Strategies for Virtualized Environments in Grid Computing Systems
The development of adequate security solutions, and in particular of authentication and authorization techniques, for grid computing systems is a challenging task. Recent trends of service oriented architectures (SOA), where users access grids through a science gateway — a web service that serves as a portal between users of a virtual organizations (VO) and the various computation resources, fu...
متن کاملA Service Oriented Architecture for Authorization of Unknown Entities in a Grid Environment
In many cases, within distributed environments, authorization manifests itself in the form of existing trust relationships. Before pervasive computing can be successfully achieved, we may have to transcend the current notion of pre-established trust. This is not conducive to a low administrative overhead, nor is it realistic in a distributed environment, where processing may occur over a large ...
متن کاملPortable Tools for Interoperable Grids Modular Architectures and Software for Job and Workflow Management
The emergence of Grid computing infrastructures enables researchers to share resources and collaborate in more efficient ways than before, despite belonging to different organizations and being geographically distributed. While the Grid computing paradigm offers new opportunities, it also gives rise to new difficulties. This thesis investigates methods, architectures, and algorithms for a range...
متن کاملThe LEAD Portal: a TeraGrid gateway and application service architecture
The Linked Environments for Atmospheric Discovery (LEAD) Portal is a science application portal designed to enable effective use of Grid resources in exploring mesoscale meteorological phenomena. The aim of the LEAD Portal is to provide a more productive interface for doing experimental work by the meteorological research community, as well as bringing weather research to a wider class of users...
متن کاملA Generic Framework for Building Services and Scientific Workflows for the Grid
Web Service architectures have gained popularity in recent years because they allow software and services from various organizations to be combined easily to provide integrated and distributed applications. However, most applications developed and used by scientific communities are not Web Service oriented and there is a growing need to integrate them into Grid applications based on Web Service...
متن کامل