• DocumentCode
    932508
  • Title

    Role-based access control for grid database services using the community authorization service

  • Author

    Pereira, Anil L. ; Muppavarapu, Vineela ; Chung, Soon M.

  • Author_Institution
    Dept. of Comput. Sci. & Eng., Wright State Univ., Dayton, OH
  • Volume
    3
  • Issue
    2
  • fYear
    2006
  • Firstpage
    156
  • Lastpage
    166
  • Abstract
    In this paper, we propose a role-based access control (RBAC) method for grid database services in open grid services architecture-data access and integration (OGSA-DAI). OGSA-DAI is an efficient grid-enabled middleware implementation of interfaces and services to access and control data sources and sinks. However, in OGSA-DAI, access control causes substantial administration overhead for resource providers in virtual organizations (VOs) because each of them has to manage a role-map file containing authorization information for individual grid users. To solve this problem, we used the community authorization service (CAS) provided by the globus toolkit to support the RBAC within the OGSA-DAI framework. The CAS grants the membership on VO roles to users. The resource providers then need to maintain only the mapping information from VO roles to local database roles in the role-map files, so that the number of entries in the role-map file is reduced dramatically. Furthermore, the resource providers control the granting of access privileges to the local roles. Thus, our access control method provides increased manageability for a large number of users and reduces day-to-day administration tasks of the resource providers, while they maintain the ultimate authority over their resources. Performance analysis shows that our method adds very little overhead to the existing security infrastructure of OGSA-DAI
  • Keywords
    authorisation; distributed databases; grid computing; middleware; community authorization service; data access; data integration; data source access; data source control; globus toolkit; grid database services; grid-enabled middleware; open grid services architecture; role-based access control; role-map file; virtual organizations; Access control; Authorization; Content addressable storage; Data analysis; Data security; Middleware; Performance analysis; Permission; Resource management; Transaction databases; Community Authorization Service (CAS); Grid database services; Open Grid Services Architecture-Data Access and Integration (OGSA-DAI); fine-grain authorization; role-based access control (RBAC).;
  • fLanguage
    English
  • Journal_Title
    Dependable and Secure Computing, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1545-5971
  • Type

    jour

  • DOI
    10.1109/TDSC.2006.26
  • Filename
    1632009