Authorisation and identity mapping services for the Open Science Grid

Periodicals(2008)

引用 2|浏览0
暂无评分
摘要
An attribute-based authorisation infrastructure developed for the Open Science Grid (OSG) is presented. The infrastructure integrates existing identity-mapping and group-membership services using concepts prototyped in the PRIMA system. Authorisation scenarios for requests to compute and data resources are detailed. A new SAML obligated authorisation decision statement is introduced that attaches an XACML obligation to the authorisation decision. The use of obligations enables site-centralised, service-independent policy management. Authorisation decisions are enforced via a Workspace Service that creates constrained execution environments configured in accordance with the obligations and other attribute-based information. Finally, an experimental PRIMA authorisation service that extends and simplifies the infrastructure is described.
更多
查看译文
关键词
attribute-based authorisation infrastructure,attribute-based information,prima system,authorisation decision statement,workspace service,open science grid,experimental prima authorisation service,identity mapping service,authorisation scenario,authorisation decision,xacml obligation,grid computing,authorisation
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要