Skip to main content
Kent Academic Repository

Coordinating access control in grid services

Chadwick, David W., Su, L., Laborde, Romain (2008) Coordinating access control in grid services. Concurrency and Computation: Practice and Experience, 20 (9). pp. 1071-1094. ISSN 1532-0626. (doi:10.1002/cpe.1284) (KAR id:14878)

Abstract

We describe how to control the cumulative use of distributed grid resources by using coordination-aware policy decision points (coordinated PDPs) and an SQL database to hold 'coordination' data. When access to a resource is granted, obligations in the security policy ensure that the coordination database is updated. The coordination database is a normal grid service providing distributed access to the coordinated PDPs. Access to the databases is secured by the grid security infrastructure (GSI) and its own PDP, so that only authorized users (the coordinated PDPs) can access it. A coordinated PDP is imbedded into the Globus Toolkitv4 authorization chain as a custom PDP so that any grid service can be protected by a security policy that provides a coordination capability. Each coordinated PDP uses the services of an uncoordinated PDP to make its access control decisions, so that any existing stateless PDP can be supplemented with a coordination capability. We provide performance results for the coordinated PDPs and compare these with two stateless PDPs. Virtually the entire performance penalty of using coordinated PDPs is accounted for by the heavy costs of using GSI to secure communications between the coordinated PDPs and the coordination database.

Item Type: Article
DOI/Identification number: 10.1002/cpe.1284
Additional information: Proceedings Paper Special Issue: Middleware for Grid Computing: Future Trends (MGC2006)
Uncontrolled keywords: PDP, coordinated access control, grid security
Subjects: Q Science > QA Mathematics (inc Computing science) > QA 75 Electronic computers. Computer science
Divisions: Divisions > Division of Computing, Engineering and Mathematical Sciences > School of Computing
Funders: Engineering and Physical Sciences Research Council (https://ror.org/0439y7842)
Depositing User: Suzanne Duffy
Date Deposited: 24 Feb 2009 18:22 UTC
Last Modified: 05 Nov 2024 09:49 UTC
Resource URI: https://kar.kent.ac.uk/id/eprint/14878 (The current URI for this page, for reference purposes)

University of Kent Author Information

Chadwick, David W..

Creator's ORCID: https://orcid.org/0000-0003-3145-055X
CReDIT Contributor Roles:

Su, L..

Creator's ORCID:
CReDIT Contributor Roles:
  • Depositors only (login required):

Total unique views for this document in KAR since July 2020. For more details click on the image.