• DocumentCode
    3238285
  • Title

    Authorisation infrastructure for on-demand network resource provisioning

  • Author

    Demchenko, Yuri ; Wan, Alfred ; Cristea, Mihai ; De Laat, Cees

  • Author_Institution
    Univ. of Amsterdam, Amsterdam
  • fYear
    2008
  • fDate
    Sept. 29 2008-Oct. 1 2008
  • Firstpage
    95
  • Lastpage
    103
  • Abstract
    High performance Grid applications require high speed network infrastructure that should be capable to provide network connectivity service on-demand. This paper presents results of the development of the Authorisation (AuthZ) infrastructure for on-demand multidomain network resource provisioning (NRP). We propose a general Complex Resource Provisioning (CRP) model that can be used as a basis for AuthZ infrastructure development providing a common abstraction for provisioning both network and Grid resources. This model allows common policy expressions, using single user sign-on credentials when requesting and accessing complex Grid-Network resources. The implementation described is based on the generic AAA Authorisation Framework (GAAA-AuthZ) and suggests a number of security mechanisms and components that extends GAAA-AuthZ to achieve consistent policy enforcement and security context management: Token Validation Service (TVS), AuthZ ticket used for AuthZ session management, a special XACML profile for NRP, reference model for policy obligations handling (OHRM). The proposed infrastructure and solutions are being implemented in the framework of the EU project Phosphorus and use authors experiences gained from the major Grid based and Grid oriented projects.
  • Keywords
    grid computing; resource allocation; AuthZ ticket; XACML profile; authorisation infrastructure; complex resource provisioning; grid-network resources; network connectivity service on-demand; network resource provisioning; on-demand network resource provisioning; security context management:; token validation service; Authorization; Context modeling; Context-aware services; Data security; Data visualization; High-speed networks; Humans; Middleware; Resource management; Throughput; AAA Authorisation Framework; Authorisation session; Complex Resource Provisioning; Multidomain Network Resource Provisioning; Token Validation Service; XACML;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Grid Computing, 2008 9th IEEE/ACM International Conference on
  • Conference_Location
    Tsukuba
  • Print_ISBN
    978-1-4244-2578-5
  • Electronic_ISBN
    978-1-4244-2579-2
  • Type

    conf

  • DOI
    10.1109/GRID.2008.4662787
  • Filename
    4662787