• DocumentCode
    2606849
  • Title

    Authorization for metacomputing applications

  • Author

    Gheorghiu, G. ; Ryutov, T. ; Neuman, B.C.

  • Author_Institution
    Inf. Sci. Inst., Univ. of Southern California, Marina del Rey, CA, USA
  • fYear
    1998
  • fDate
    28-31 Jul 1998
  • Firstpage
    132
  • Lastpage
    139
  • Abstract
    One of the most difficult problems to be solved by metacomputing systems is to ensure strong authentication and authorization. The problem is complicated since the hosts involved in a metacomputing environment often span multiple administrative domains, each with its own security policy. This paper presents a distributed authorization model used by our resource allocation system, the Prospero resource manager. The main components of our design are extended access control lists (EACLs) and a general authorization and access application programming interface (GAA API). EACLs extend conventional ACLs to allow conditional restrictions on access rights. In the case of the Prospero resource manager, specific restrictions include limits on the computational resources to be consumed and on the characteristics of the applications to be executed by the system, such as name, version or endorser. The GAA API provides a general framework for applications to access the EACLs. We have built a prototype of the system
  • Keywords
    application program interfaces; authorisation; distributed processing; resource allocation; GAA API; Prospero resource manager; access rights; application characteristics; application programming interface; authentication; computational resource consumption limits; conditional restrictions; distributed authorization model; endorser; extended access control lists; metacomputing applications; multiple administrative domains; multiple security policies; name; prototype; resource allocation system; version; Access control; Authentication; Authorization; Computer networks; Gold; Metacomputing; Prototypes; Resource management; Security; Supercomputers;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    High Performance Distributed Computing, 1998. Proceedings. The Seventh International Symposium on
  • Conference_Location
    Chicago, IL
  • ISSN
    1082-8907
  • Print_ISBN
    0-8186-8579-4
  • Type

    conf

  • DOI
    10.1109/HPDC.1998.709965
  • Filename
    709965