Title : 
Toward an On-Demand Restricted Delegation Mechanism for Grids
         
        
            Author : 
Ahsant, Mehran ; Basney, Jim ; Mulmo, Olle ; Lee, Adam J. ; Johnsson, Lennart
         
        
            Author_Institution : 
Center for Parallel Comput., R. Inst. of Technol., Stockholm
         
        
        
        
        
        
            Abstract : 
Grids are intended to enable cross-organizational interactions which makes grid security a challenging and non-trivial issue. In grids, delegation is a key facility that can be used to authenticate and authorize requests on behalf of disconnected users. In current grid systems there is a tradeoff between flexibility and security in the context of delegation. Applications must choose between limited or full delegation: on one hand, delegating a restricted set of rights reduces exposure to attack but also limits the flexibility/dynamism of the application; on the other hand, delegating all rights provides maximum flexibility but increases exposure. In this paper, we propose an on-demand restricted delegation mechanism, aimed at addressing the shortcomings of current delegation mechanisms by providing restricted delegation in a flexible fashion as needed for grid applications. This mechanism provides an ontology-based solution for tackling one the most challenging issues in security systems, which is the principle of least privileges. It utilizes a callback mechanism, which allows on-demand provisioning of delegated credentials in addition to observing, screening, and auditing delegated rights at runtime. This mechanism provides support for generating delegation credentials with a very limited and well-defined range of capabilities or policies, where a delegator is able to grant a delegatee a set of restricted and limited rights, implicitly or explicitly
         
        
            Keywords : 
authorisation; grid computing; message authentication; ontologies (artificial intelligence); organisational aspects; callback mechanism; cross-organizational interactions; grid security; on-demand restricted delegation; ontology; request authentication; request authorisation; Application software; Authorization; Computer science; Computer security; Concurrent computing; Disaster management; Grid computing; Information technology; Ontologies; Runtime;
         
        
        
        
            Conference_Titel : 
Grid Computing, 7th IEEE/ACM International Conference on
         
        
            Conference_Location : 
Barcelona
         
        
            Print_ISBN : 
1-4244-0343-X
         
        
            Electronic_ISBN : 
1-4244-0344-8
         
        
        
            DOI : 
10.1109/ICGRID.2006.311010