Security for Grid services
Top Cited Papers
- 23 January 2004
- proceedings article
- Published by Institute of Electrical and Electronics Engineers (IEEE)
Abstract
Grid computing is concerned with the sharing and coordinated use of diverse resources in distributed "virtual organizations." The dynamic and multi-institutional nature of these environments introduces challenging security issues that demand new technical approaches. In particular, one must deal with diverse local mechanisms, support dynamic creation of services, and enable dynamic creation of trust domains. We describe how these issues are addressed in two generations of the Globus Toolkit®. First, we review the Globus Toolkit version 2 (GT2) approach; then, we describe new approaches developed to support the Globus Toolkit version 3 (GT3) implementation of the Open Grid Services Architecture, aninitiative that is recasting Grid concepts within a service-oriented framework based on Web services. GT3's security implementation uses Web services security mechanisms for credential exchange and other purposes, and introduces a tight least-privilege model that avoids the need for any privileged network service.Keywords
All Related Versions
This publication has 9 references indexed in Scilit:
- A community authorization service for group collaborationPublished by Institute of Electrical and Electronics Engineers (IEEE) ,2003
- SNAP: A Protocol for Negotiating Service Level Agreements and Coordinating Resource Management in Distributed SystemsLecture Notes in Computer Science, 2002
- The PERMIS X.509 role based privilege management infrastructurePublished by Association for Computing Machinery (ACM) ,2002
- The Anatomy of the Grid: Enabling Scalable Virtual OrganizationsThe International Journal of High Performance Computing Applications, 2001
- A national-scale authentication infrastructureComputer, 2000
- A security architecture for computational gridsPublished by Association for Computing Machinery (ACM) ,1998
- A resource management architecture for metacomputing systemsLecture Notes in Computer Science, 1998
- Kerberos: an authentication service for computer networksIEEE Communications Magazine, 1994
- An architecture for practical delegation in a distributed systemPublished by Institute of Electrical and Electronics Engineers (IEEE) ,1990