Title :
Least-Privilege-Based Access Control Model for Job Execution in Grid
Author :
Xue, Ke ; Tang, Shaohua ; Ge, Lina
Abstract :
In current Grid systems there is a tradeoff between flexibility and security in the context of delegation. Based on the traditional Role-Based-Access-Control module, in order to fulfill the "least privilege" principle, a new delegation model is proposed. This model introduces a task-policy based method to restrict the max privileges a task can delegate; combines static and dynamic delegation method to avoid task being interrupted by lack of privileges during execution; makes use of the credit card mechanism to ensure convenience and reduce risks.
Keywords :
Access control; Computer science; Computer security; Content addressable storage; Context modeling; Context-aware services; Credit cards; Data engineering; Data privacy; Protection;
Conference_Titel :
Data, Privacy, and E-Commerce, 2007. ISDPE 2007. The First International Symposium on
Conference_Location :
Chengdu
Print_ISBN :
978-0-7695-3016-1
DOI :
10.1109/ISDPE.2007.120