DocumentCode
1826689
Title
Recovery mechanism of online certification chain in grid computing
Author
Li, Mingchu ; Ma, Jianbo ; Yao, Hongyan
Author_Institution
Sch. of Software, Dalian Univ. of Technol., China
fYear
2006
fDate
20-22 April 2006
Abstract
Proxy credentials are commonly used in security system when one entity wishes to grant some set of its privileges to another entity. Proxy credential chain is produced when new entities with proxy credentials use their proxy credentials to authenticate and establish secured connections with other entities in the same manner and are asked to wait for the completion of a task online. Due to network unstable, some middle node of the credential chain is not accessed by certain reasons, and, as a result, proxy credential chain problem occurs. The problem is an important research issue in grid security. In this paper, we explore the problem by using double signatures and applying X.509 proxy credential. We provides a method to create double signatures using data redundancy and to establish proxy credential chain with double signatures, and provide a recovery mechanism of proxy credential chain in grid when certificate chain broken problem occurs. We analyze the disadvantages of existing mechanism when the middle-node of the credentials chain was broken, and present a new scheme to extend the existing mechanism (including the description of new proxy credential format, the creation mechanism of proxy credentials and the strategy of validating). We also analyze the security of our new scheme.
Keywords
grid computing; message authentication; X.509 proxy credential; data redundancy; double signatures; grid computing; grid security; online certification chain; proxy credential chain recovery mechanism; Authentication; Certification; Collaboration; Computer science; Computer security; Data security; Distributed computing; Grid computing; National security; Public key; Certifucate Chain; Double signature; Grid security; Proxy certificate;
fLanguage
English
Publisher
ieee
Conference_Titel
Availability, Reliability and Security, 2006. ARES 2006. The First International Conference on
Print_ISBN
0-7695-2567-9
Type
conf
DOI
10.1109/ARES.2006.105
Filename
1625357
Link To Document