DocumentCode :
2806158
Title :
Extending user-controlled security domain with TPM/TCG in Grid-based virtual collaborative environment
Author :
Demchenko, Yuri ; Gommans, Leon ; De Laat, Cees
Author_Institution :
Amsterdam Univ., Amsterdam
fYear :
2007
fDate :
25-25 May 2007
Firstpage :
57
Lastpage :
65
Abstract :
The paper proposes an integral approach to building multilayer security for Grid based virtual collaborative environment that leverages the general user-controlled complex resource provisioning (CRP-UC) model. The CRP-UC is considered as comprising of three layers: trusted computing platform, secure virtualised workspace, and collaborative/application session. The suggestions on the technology selection are provided for the first two layers: industry adopted Trusted Computing (TCG) platform, and Virtual Workspace Service (VWSS) developed in the framework of the Globus Toolkit. Solutions and implementation are proposed and discussed for the service/application authorisation session and security context management in multidomain applications based on the GAAA Authorisation Framework that can be used with the major service-oriented AuthZ framework. The current implementation of the XML-based authorisation ticket format is discussed and possible extensions to address wider user session management issues are suggested, in particular those related to the TCG-rooted chain of trust and session context negotiation. The paper is based on experiences gained from major Grid based and Grid oriented projects including EGEE, Phosphorus, Globus Toolkit.
Keywords :
XML; authorisation; grid computing; groupware; virtual reality; GAAA Authorisation Framework; Grid-based virtual collaborative environment; TPM/TCG; XML-based authorisation ticket format; secure virtualised workspace; trusted computing platform; user-controlled complex resource provisioning model; user-controlled security domain; virtual workspace service; Authorization; Collaboration; Collaborative work; Computer industry; Computer security; Data security; Grid computing; Middleware; Protection; Time sharing computer systems; Authorisation Session; Complex Resource Provisioning; Grid based Collaborative Environment; SAML; Trusted Computing Platform; User-controlled security model; Virtual Workspace Service; Virtualisation;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Collaborative Technologies and Systems, 2007. CTS 2007. International Symposium on
Conference_Location :
Orlando, FL
Print_ISBN :
978-0-9785699-1-4
Electronic_ISBN :
978-0-9785699-1-4
Type :
conf
DOI :
10.1109/CTS.2007.4621738
Filename :
4621738
Link To Document :
بازگشت