• DocumentCode
    469558
  • Title

    Distributed policy framework across multiple grid domains

  • Author

    Ciaschini, Vincenzo ; Ferraro, Andrea ; Forti, Alberto ; Ghiselli, Antonia ; Venturi, Valerio ; Gianoli, Alberto ; Luppi, Eleonora ; Stagni, Federico ; Tomassetti, Luca

  • Author_Institution
    CNAF-INFN, Bologna
  • Volume
    1
  • fYear
    2007
  • fDate
    Oct. 26 2007-Nov. 3 2007
  • Firstpage
    892
  • Lastpage
    897
  • Abstract
    A key feature of grid environment is the sharing of computing and storage: users operate on resources not directly owned by them. Often users working on the same research project are grouped in a virtual organization (VO) to use a common authorization policy on this resources. Many international experiments, however, use different Grid middleware platforms with their own authorization framework. This leads to interoperability problems for scientists of the same experiment, using their national Grid infrastructure. Usually VOs and resource providers share contracts to regulate resource usage. The enforcement of such arrangements needs an agreed interoperable authorization mechanism based on policies that can be written by VOs and resources providers. This process can be applied using a flexible and distributed policy framework, where complex relationships can be enforced being able to manage both policies created by VOs and policies created by Grid sites. G-PBox policy framework, in conjunction with VOMS Attribute Authority, is our proposal to represent, manage and distribute such policies in a transparent way. G-PBox approach is based on a set of XACML policies databases belonging separately to VOs and resource providers, each containing at least policies regarding it own organization. In this paper we describe how VO oriented tools like VOMS and G-PBox can be deployed across different VOs and resource providers. It will show how VO managers and sites administrators can set up agreed policies for resource sharing optimization and experiment computing prioritization, making best use of their time and resources. It will underline also that adoption of assertion and policy Grid standard, as SAML and XACML, provides an effective advantage in order to allow an accepted authentication and authorization interoperability among services of different Grid domains based on different mechanisms.
  • Keywords
    authorisation; grid computing; high energy physics instrumentation computing; open systems; G-PBox policy; SAML; VOMS attribute authority; XACML policies; authorization policy; distributed policy framework; grid infrastructure; grid middleware platforms; interoperability; multiple grid; virtual organization; Authorization; Contracts; Distributed computing; Grid computing; Information security; Middleware; Nuclear and plasma sciences; Proposals; Resource management; Service oriented architecture; Grid; authorization; interoperability; security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Nuclear Science Symposium Conference Record, 2007. NSS '07. IEEE
  • Conference_Location
    Honolulu, HI
  • ISSN
    1095-7863
  • Print_ISBN
    978-1-4244-0922-8
  • Electronic_ISBN
    1095-7863
  • Type

    conf

  • DOI
    10.1109/NSSMIC.2007.4436471
  • Filename
    4436471