loading...
Using SAML and XACML for Complex Resource Provisioning in Grid Based Applications
Bologna, Italy June 13-June 15
DOI Bookmark: http://doi.ieeecomputersociety.org/10.1109/POLICY.2007.48Eighth IEEE International Workshop on ...
 This Article 
 
PDF
HTML
 
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
Yuri Demchenko, University of Amsterdam, Netherlands
Leon Gommans, University of Amsterdam, Netherlands
Cees de Laat, University of Amsterdam, Netherlands
This paper presents ongoing research and current results on the development of flexible access control infrastructure for complex resource provisioning (CRP) in Grid-based applications. The paper proposes a general CRP model and specifies major requirements to the Authorisation (AuthZ) service infrastructure to support multidomain CRP, focusing on two main issues -- policy expression for complex resource models and AuthZ session support. The paper provides suggestions about using XACML and its special profiles to describe access control policies to complex resources and briefly describes proposed XML based AuthZ ticket format to support extended AuthZ session context. Additionally, the paper discusses what specific functionality can be added to the gLite Java Authorisation Framework (gJAF), to handle dynamic security context including AuthZ session support. The paper is based on experiences gained from major Grid based and Grid oriented projects such as EGEE, Phosphorus and GigaPort Research on Network.
Citation:
Yuri Demchenko, Leon Gommans, Cees de Laat, "Using SAML and XACML for Complex Resource Provisioning in Grid Based Applications," policy, pp.183-187, Eighth IEEE International Workshop on Policies for Distributed Systems and Networks (POLICY'07), 2007
Usage of this product signifies your acceptance of the Terms of Use.