• DocumentCode
    3404336
  • Title

    Design and implementation of a Grid proxy auditing infrastructure

  • Author

    Kunz, Christopher ; Szongott, Christian ; Wiebelitz, Jan ; Grimm, Christian

  • Author_Institution
    Regional Comput. Center for Lower Saxony, Gottfried Wilhelm Leibniz Univ., Hannover, Germany
  • fYear
    2009
  • fDate
    9-11 Dec. 2009
  • Firstpage
    11
  • Lastpage
    18
  • Abstract
    Single sign-on and delegation of rights are key requirements for modern grid infrastructures. These requirements are usually facilitated by X.509 und private-key infrastructures (PKI) and proxy certificates. Proxy certificates, however, can be obtained and abused by a malicious third party. There is currently no method for end users to detect such abuse. We have designed a solution that enables a thorough auditing of grid proxy usage in Globus-based grids and implemented a service that accepts auditing information via a Web service interface and saves them to a back-end database. We introduce modifications to the grid security infrastructure that allow sending audit trails from within Globus components if the user desires to track credential usage. A Web-based front-end shows all logged information. With our approach, expert users can now closely monitor how their credentials are used after job submission. This will help build trust in grid infrastructures and delegated authentication and authorization.
  • Keywords
    Web services; authorisation; grid computing; message authentication; private key cryptography; Globus-based grid; Web service interface; authentication; authorization; grid proxy auditing infrastructure; grid security infrastructure; proxy certificate; Authentication; Authorization; Data security; Databases; File systems; Grid computing; Information security; Middleware; Protection; Web services;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    E-Science Workshops, 2009 5th IEEE International Conference on
  • Conference_Location
    Oxford
  • Print_ISBN
    978-1-4244-5946-9
  • Type

    conf

  • DOI
    10.1109/ESCIW.2009.5407982
  • Filename
    5407982