DocumentCode :
2953057
Title :
Policy-Driven Negotiation for Authorization in the Grid
Author :
Constandache, Ionut ; Olmedilla, Daniel ; Siebenlist, Frank
Author_Institution :
Duke Univ., Durham
fYear :
2007
fDate :
13-15 June 2007
Firstpage :
211
Lastpage :
220
Abstract :
In many grid services deployments, the clients and servers reside in different administrative domains. Hence, there is a requirement both to discover each other´s authorization policy, in order to be able to present the right assertions that allow access, and to reveal as little as possible of the access policy details to unauthorized parties. This paper describes a mechanism where the client and servers are semantically annotated with policies that protect their resources. These annotations specify both constraints and capabilities that are used during a negotiation to reason about and communicate the need to see certain credentials from the other party and to determine whether requested credentials can be obtained and revealed. The result of the negotiation is a state where both parties have satisfied their policy constraints for a subsequent interaction or where such interaction is disallowed by either or both. Furthermore, we present an implementation of a prototype, based on the PEERTRUST policy language, and a reasoning engine that is integrated in the Web services runtime component of the globus toolkit. The negotiation process is facilitated through the implementation of WSRF-compliant service interfaces for protocol message exchanges.
Keywords :
Web services; authorisation; grid computing; message passing; PEERTRUST policy language; WSRF-compliant service interfaces; Web services runtime component; access policy; client; globus toolkit; grid authorization; policy-driven negotiation; protocol message exchanges; reasoning engine; servers; Access control; Authentication; Authorization; Certification; Collaboration; Information security; Protection; Protocols; Public key; Scalability;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Policies for Distributed Systems and Networks, 2007. POLICY '07. Eighth IEEE International Workshop on
Conference_Location :
Bologna
Print_ISBN :
0-7695-2767-1
Type :
conf
DOI :
10.1109/POLICY.2007.36
Filename :
4262590
Link To Document :
بازگشت