Skip to main content

GridShib and PERMIS Integration

Chadwick, David W., Novikov, A., Otenko, Alexander (2006) GridShib and PERMIS Integration. Campus-Wide Information Systems, 23 (4). pp. 297-308. ISSN 1065-0741. (doi:10.1108/10650740610704153) (KAR id:14402)

Language: English
Click to download this file (539kB) Preview
[thumbnail of GridShib_and_PERMIS_Integration.pdf]
This file may not be suitable for users of assistive technology.
Request an accessible format
Official URL:


This paper describes the results of our recent GridShibPERMIS project to provide policy-driven role-based access control decision making to Grid jobs, in which the users attributes are provided by a Shibboleth Identity Provider (IdP). The goal of the project is to integrate the identity-federation and attribute-assignment functions of Shibboleth with the policy- based enforcement function of PERMIS, in order to provide a flexible fine-grained authorisation system for Grid jobs running under Globus Toolkit v4. This was done by taking the GT4-Shibboleth integration performed in the United States with the PERMIS infrastructure built in the United Kingdom, and developing a GridShibPERMIS Context Handler. This allows for interoperability between GridShib and PERMIS by providing the required attribute extraction, conversion and transfer functions. As a result, the GridShibPERMIS project integrates the advantages of both Shibboleth cross-organisation identity federation and PERMIS policy-driven role-based access control and represents a new avenue of policy-based authorisation for Grids. The paper provides a brief overview of the technologies involved: GT4, Shibboleth and PERMIS, and presents how the three are combined to provide an efficient and simple fine- grained authorisation mechanism, having low implementation costs. The paper concludes with the lessons learned and plans for the future.

Item Type: Article
DOI/Identification number: 10.1108/10650740610704153
Uncontrolled keywords: GridShib, PERMIS
Subjects: Q Science > QA Mathematics (inc Computing science) > QA 76 Software, computer programming,
Divisions: Divisions > Division of Computing, Engineering and Mathematical Sciences > School of Computing
Depositing User: Mark Wheadon
Date Deposited: 24 Nov 2008 18:03 UTC
Last Modified: 09 Mar 2023 11:29 UTC
Resource URI: (The current URI for this page, for reference purposes)
Chadwick, David W.:
  • Depositors only (login required):

Total unique views for this document in KAR since July 2020. For more details click on the image.