DocumentCode
2297816
Title
Improved Grid Security Posture through Multi-factor Authentication
Author
Hazlewood, Victor ; Kovatch, Patricia ; Ezell, Matthew ; Johnson, Matthew ; Redd, Patti
Author_Institution
Nat. Inst. for Comput. Sci., Univ. of Tennessee, Oak Ridge, TN, USA
fYear
2011
fDate
21-23 Sept. 2011
Firstpage
106
Lastpage
113
Abstract
While methods of securing communication over the Internet have changed from clear text to secure encrypted channels over the last decade, the basic username-password combination for authentication has remained the mainstay in academic research computing and grid environments. Security incidents affecting grids, such as the TeraGrid stakkato incident of 2004 and 2005, has demonstrated that the use of reusable passwords for authentication can be readily exploited and can lead to a widespread security incident across the grid [1, 2]. The University of Tennessee\´s National Institute for Computational Sciences (NICS) founded in 2008 has provided resources to the TeraGrid, including Kraken, a 1.17 petaflops Cray XT5, and has implemented and promoted the use of multi-factor authentication mechanisms since its founding. The benefits of use of this stronger authentication method has been higher productivity and resource availability for users due to no known user account compromises caused by stolen NICS user credentials that led to disabling accounts or system resources. NICS has been developing and experimenting with expanding our use of multi-factor authentication to the grid. NICS has integrated multi-factor authentication with our certificate authority so that users can now run my proxy and receive a multi-factor authenticated certificate. NICS is also exploring the federation of multi-factor authentication systems, with the goal of "one user, one token". This is especially important, as new grid resources, such as Blue Waters, will only allow multi-factor authentication, and we want the users to only carry one token, not many tokens. XSEDE, the TeraGrid successor, will also be deploying multi-factor authentication in addition to the other existing authentication methodologies. XSEDE will also work closely with science gateways and workflows to develop and maintain secure frameworks for the highest level of security possible.
Keywords
authorisation; grid computing; Blue Waters resource; Cray XT5; Internet; Kraken; TeraGrid; grid security posture; multifactor authentication system; reusable password; username-password combination; Authentication; Communities; Logic gates; Prototypes; Servers; GSI; MyProxy; federation of multi-factor authentication systems; one-time password; password; security;
fLanguage
English
Publisher
ieee
Conference_Titel
Grid Computing (GRID), 2011 12th IEEE/ACM International Conference on
Conference_Location
Lyon
ISSN
1550-5510
Print_ISBN
978-1-4577-1904-2
Type
conf
DOI
10.1109/Grid.2011.41
Filename
6076505
Link To Document