The access to Grid resources depends on policies defined by the administrators of the physical organizations and of the Grid middleware. This approach does not require support for access control in the middleware, but since changes in the access control policy of the Virtual Organization imply the involvement of one or more administrators, it lacks the flexibility needed in several Grid application scenarios. In this paper we propose a novel Cooperative Access Control model for Grid environments that increases the flexibility of the access control model offered by state-of-the-art Grid platforms without requiring changes in the middleware. The approach is based on collaboration among Grid users and allows them to exchange access permissions to Virtual Resources without the intervention of administrators. We also propose a solution based on Broadcast Encryption which allows to enforce a Cooperative Access Control model on Grids avoiding misuse and granting anonymity. Finally, we show that our solution can be defined on top of the access control mechanisms offered by state-of-the-art Grid middleware and illustrate how the proposed model has been implemented as a service in a service-oriented Grid environment.
Secure cooperative access control on grid
MERLO, ALESSIO
2012-01-01
Abstract
The access to Grid resources depends on policies defined by the administrators of the physical organizations and of the Grid middleware. This approach does not require support for access control in the middleware, but since changes in the access control policy of the Virtual Organization imply the involvement of one or more administrators, it lacks the flexibility needed in several Grid application scenarios. In this paper we propose a novel Cooperative Access Control model for Grid environments that increases the flexibility of the access control model offered by state-of-the-art Grid platforms without requiring changes in the middleware. The approach is based on collaboration among Grid users and allows them to exchange access permissions to Virtual Resources without the intervention of administrators. We also propose a solution based on Broadcast Encryption which allows to enforce a Cooperative Access Control model on Grids avoiding misuse and granting anonymity. Finally, we show that our solution can be defined on top of the access control mechanisms offered by state-of-the-art Grid middleware and illustrate how the proposed model has been implemented as a service in a service-oriented Grid environment.| File | Dimensione | Formato | |
|---|---|---|---|
|
1-s2.0-S0167739X12001574-main.pdf
non disponibili
Licenza:
NON PUBBLICO - Accesso privato/ristretto
Dimensione
831.53 kB
Formato
Adobe PDF
|
831.53 kB | Adobe PDF | Visualizza/Apri Richiedi una copia |
I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.
