Title :
UCGS: A Usage Control Approach for Grid Services
Author :
Mei, Yiduo ; Dong, Xiaoshe ; Wu, Weiguo ; Guan, Shangyuan ; Xu, Jing
Author_Institution :
Xi´´an Jiaotong Univ., Xi´´an
Abstract :
The dynamic and multi-institutional nature of the grid environments introduces challenging security issues that demand new technical approaches. But traditional access control models consider static authorization decisions based on subjects\´pre-assigned permissions on target objects and focus on a closed system, therefore, they are not suitable for the dynamic grid environments. To address the above problems, we propose UCGS, a novel usage control approach for grid services. Our approach is inspired by the usage control model (UCON). UCGS improves the security of the grid services by employing a continuous usage control of the grid services, monitoring the behavior of the subjects. It enables richer and finer-grained control over authorization and usage of grid services and resources than that of traditional access control models. "Blacklist", "unilateral contract" and "arbitrator" are introduced in UCGS to guarantee that a subject can not deny its obligations after service is complete, which contributes to maintain the normal order of the grid environments and the security and interests of the service providers.
Keywords :
authorisation; grid computing; access control models; arbitrator; blacklist; grid services; security issues; unilateral contract; usage control; Access control; Authorization; Computational intelligence; Contracts; Grid computing; Information security; Intrusion detection; Monitoring; Permission; Testing;
Conference_Titel :
Computational Intelligence and Security Workshops, 2007. CISW 2007. International Conference on
Conference_Location :
Harbin
Print_ISBN :
978-0-7695-3073-4
DOI :
10.1109/CISW.2007.4425539