loading...
Using SAML and XACML for Complex Authorisation Scenarios in Dynamic Resource Provisioning
Vienna, Austria April 10-April 13
DOI Bookmark: http://doi.ieeecomputersociety.org/10.1109/ARES.2007.157The Second International Conference o ...
 This Article 
 
PDF
HTML
 
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
Yuri Demchenko, University of Amsterdam
Leon Gommans, University of Amsterdam
Cees de Laat, University of Amsterdam
This paper presents ongoing research and current results on the development of flexible access control infrastructures for complex resource provisioning in Grid-based collaborative applications and on-demand network services provisioning. The paper identifies basic resource provisioning models and specifies major requirements to Authorisation (AuthZ) service infrastructure to support these models and focus on two main issues ? AuthZ session support and policy expression for complex resource models. For the practical implementation, we investigate the use of two popular standards SAML and XACML for complex authorisation scenarios in dynamic resource provisioning across multiple administrative and security domains. The paper describes a proposed XML based AuthZ ticket format that is capable of supporting extended AuthZ session context. Additionally, the paper discusses what specific functionality should be added to existing Grid-oriented authorization frameworks to handle dynamic domainrelated security context including AuthZ session support. The paper is based on experiences gained from major Grid based and Grid oriented projects such as EGEE, NextGrid, Phosphorus and GigaPort Research on Network.
Citation:
Yuri Demchenko, Leon Gommans, Cees de Laat, "Using SAML and XACML for Complex Authorisation Scenarios in Dynamic Resource Provisioning," ares, pp.254-262, The Second International Conference on Availability, Reliability and Security (ARES'07), 2007
Usage of this product signifies your acceptance of the Terms of Use.


Suggestions