DocumentCode :
2552558
Title :
Policy-based access control in peer-to-peer grid systems
Author :
Da Silva, Juliano F. ; Gaspary, Luciano P. ; Barcellos, Marinho P. ; Detsch, André
Author_Institution :
UNISINOS Univ., Porto Alegre, Brazil
fYear :
2005
fDate :
13-14 Nov. 2005
Abstract :
Access control to resources is one of the most important requirements to be satisfied in grid systems that span over multiple administrative domains. Such a mechanism allows every institution taking part of a grid community to define and enforce policies for the use of their local resources by remote users. Despite the efforts of the research community to address this topic, existing approaches do not scale (e.g., in terms of communication overhead) for a large number of nodes (peers) providing resources, as these approaches rely on centralized servers to process access requests. Furthermore, they provide limited, large-grain policy specification functionality and are not committed to employing open, standardized formats to express policies. In this paper, we address these limitations by proposing PeGAC (peer-to-peer grid access control), a policy-based, distributed access control mechanism, which can be applied to P2P grid systems. In our proposal, policies are specified using the role-based access control model and coded using the extensible access control markup language. As a proof-of-concept we have integrated PeGAC into OurGrid, a middleware for the implementation of P2P grid systems. Preliminary results of experiments carried out at the resulting infrastructure show that our solution poses small communication and processing overhead, and can handle large policy repositories efficiently.
Keywords :
XML; authorisation; grid computing; middleware; peer-to-peer computing; OurGrid; PeGAC; access requests; authorization; distributed access control; extensible access control markup language; grid computing; middleware; peer-to-peer grid access control; peer-to-peer grid systems; policy-based access control; resource access control; role-based access control; Access control; Authorization; Communication system security; Computer crime; Content addressable storage; Grid computing; Peer to peer computing; Proposals; Resists; Scalability;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Grid Computing, 2005. The 6th IEEE/ACM International Workshop on
Print_ISBN :
0-7803-9492-5
Type :
conf
DOI :
10.1109/GRID.2005.1542731
Filename :
1542731
Link To Document :
بازگشت