DocumentCode :
932508
Title :
Role-based access control for grid database services using the community authorization service
Author :
Pereira, Anil L. ; Muppavarapu, Vineela ; Chung, Soon M.
Author_Institution :
Dept. of Comput. Sci. & Eng., Wright State Univ., Dayton, OH
Volume :
3
Issue :
2
fYear :
2006
Firstpage :
156
Lastpage :
166
Abstract :
In this paper, we propose a role-based access control (RBAC) method for grid database services in open grid services architecture-data access and integration (OGSA-DAI). OGSA-DAI is an efficient grid-enabled middleware implementation of interfaces and services to access and control data sources and sinks. However, in OGSA-DAI, access control causes substantial administration overhead for resource providers in virtual organizations (VOs) because each of them has to manage a role-map file containing authorization information for individual grid users. To solve this problem, we used the community authorization service (CAS) provided by the globus toolkit to support the RBAC within the OGSA-DAI framework. The CAS grants the membership on VO roles to users. The resource providers then need to maintain only the mapping information from VO roles to local database roles in the role-map files, so that the number of entries in the role-map file is reduced dramatically. Furthermore, the resource providers control the granting of access privileges to the local roles. Thus, our access control method provides increased manageability for a large number of users and reduces day-to-day administration tasks of the resource providers, while they maintain the ultimate authority over their resources. Performance analysis shows that our method adds very little overhead to the existing security infrastructure of OGSA-DAI
Keywords :
authorisation; distributed databases; grid computing; middleware; community authorization service; data access; data integration; data source access; data source control; globus toolkit; grid database services; grid-enabled middleware; open grid services architecture; role-based access control; role-map file; virtual organizations; Access control; Authorization; Content addressable storage; Data analysis; Data security; Middleware; Performance analysis; Permission; Resource management; Transaction databases; Community Authorization Service (CAS); Grid database services; Open Grid Services Architecture-Data Access and Integration (OGSA-DAI); fine-grain authorization; role-based access control (RBAC).;
fLanguage :
English
Journal_Title :
Dependable and Secure Computing, IEEE Transactions on
Publisher :
ieee
ISSN :
1545-5971
Type :
jour
DOI :
10.1109/TDSC.2006.26
Filename :
1632009
Link To Document :
بازگشت