Adaptive trust negotiation and access control for grids
- 1 January 2005
- conference paper
- Published by Institute of Electrical and Electronics Engineers (IEEE)
- p. 8 pp.-62
- https://doi.org/10.1109/grid.2005.1542724
Abstract
Access control in computational grids is typically provided by a combination of identity certificates and local accounts. This approach does not scale as the number of users and resources increase. Moreover, identity-based access control is not sufficient because users and resources may reside in different security domains and may not have pre-existing knowledge about one another. Trust negotiation is well-suited for grid computing because it allows participants to establish mutual trust based on attributes other than identity. The adaptive trust negotiation and access control (ATNAC) framework addresses the problem of access control in open systems by protecting itself from adversaries who may want to misuse, exhaust or deny service to resources. ATNAC is based on the GAA-API, which provides adaptive access control capturing dynamically changing system security requirements. The GAA-API utilizes TrustBuilder to establish a sufficient level of trust between the negotiating participants, based on the sensitivity of the access request and a suspicion level associated with the requester. A federated security context allows Grid participants to communicate their security appraisal and make judgments based on collective wisdom and the level of trust among them. We plan to apply ATNAC techniques to negotiation agreements in virtual organizations and P2P environments.Keywords
This publication has 11 references indexed in Scilit:
- Adaptive trust negotiation and access controlPublished by Association for Computing Machinery (ACM) ,2005
- /spl Xscr/-TNL: an XML-based language for trust negotiationsPublished by Institute of Electrical and Electronics Engineers (IEEE) ,2004
- Dynamic authorization and intrusion response in distributed systemsPublished by Institute of Electrical and Electronics Engineers (IEEE) ,2004
- Integrated access control and intrusion detection for web serversIEEE Transactions on Parallel and Distributed Systems, 2003
- The specification and enforcement of advanced security policiesPublished by Institute of Electrical and Electronics Engineers (IEEE) ,2003
- Decentralized trust managementPublished by Institute of Electrical and Electronics Engineers (IEEE) ,2002
- Negotiating trust in the WebIEEE Internet Computing, 2002
- SD3: a trust management system with certified evaluationPublished by Institute of Electrical and Electronics Engineers (IEEE) ,2002
- Access control meets public key infrastructure, or: assigning roles to strangersPublished by Institute of Electrical and Electronics Engineers (IEEE) ,2002
- A uniform framework for regulating service access and information release on the WebJournal of Computer Security, 2002