Nothing Special   »   [go: up one dir, main page]

skip to main content
article

A standards-based interoperable single sign-on framework in ARC Grid middleware

Published: 01 May 2012 Publication History

Abstract

Security infrastructure is one of the most challenging tasks in the development, integration and deployment of Grid middlewares. Even though the Grid community addresses the security issue through public key infrastructures (PKI) to support mutual authentication using X.509 certificates, maintaining X.509 credentials is not that easy for non-IT-experts, and has proved to be an obstacle for a more wide deployment of Grid technologies. The identity federation is an increasingly popular technology that can facilitate cross-domain single sign-on without requiring the users to maintain any credentials additional to their own institutional accounts. We believe that utilizing identity federation for Grid middlewares is a promising path for the Grid technology to get more widely used. This paper describes a single sign-on infrastructure developed as a part of the NorduGrid ARC (Advanced Resource Connector) Grid middleware. It adopts the identity federation standard (SAML), as well as other Web Service standards. It focuses on a single sign-on solution at the middleware level for users to access Grids by only using their frequently used accounts, without being bothered to maintain X.509 credentials. Users can use their username/password only to access Grids developed in ARC middleware, as well as access Grids developed in other middlewares that requires users to provide X.509 certificates. Moreover, the single sign-on for workflow-like Grid applications (in which intermediate entities act on behalf of users) is also supported. As an important aspect of single sign-on, authorization is also considered by implementing an attribute-based authorization using SAML standard. In addition, the performance of single sign-on solution is measured. We identify performance limitations of security-related services inside this solution, and analyse the ways to avoid the limitations. To our knowledge, the work presented in this paper is the first evaluated implementation that utilizes identity federation for Grid usage on the middleware level.

References

[1]
Ahsant M, Basney J, Mulmo O. Grid delegation protocol, UK workshop on grid security experiences, Oxford, 2004.
[2]
VOMS an authorization system for virtual organizations. In: First european across grids conference, santiago de compostela, February 13-14,
[3]
Identity federation and attribute-based authorization through the globus toolkit, shibboleth, gridshib, and myproxy. In: Proceeding of 5th annual PKI R&D workshop,
[4]
Authorization in grid computing. Information Security Technical Report. v10 i1. 33-40.
[5]
The PERMIS X.509 role based privilege management infrastructure. Future Generation Computer Systems. v19 i2. 277-289.
[6]
Design document of new version ARC. {https://www.knowarc.eu/documents/Knowarc_D1.1-1_07.pdf}.
[7]
eduPerson and eduOrg Object shema. {http://middleware.internet2.edu/eduperson/}.
[8]
Advanced resource connector middleware for lightweight computational grids. Future Generation Computer Systems. v23 i2. 219-240.
[9]
A security architecture for computational grids. In: ACM conference on computers and security, pp. 83-91.
[10]
gLite authorization framework. {https://twiki.cern.ch/twiki/bin/view/EGEE/AuthorizationFramework}.
[11]
Gridsite delegation service. {http://www.gridsite.org/wiki/Delegation_protocol}.
[12]
Hughes J. et al., Profiles for the OASIS Security Assertion Markup Language (SAML) V2.0, OASIS Standard. 2005.
[13]
{http://rnd.feide.no/simplesamlphp}.
[14]
KnowARC project. {https://www.knowarc.eu/}.
[15]
MyProxy Credential Management Service. {http://grid.ncsa.uiuc.edu/myproxy/}.
[16]
OASIS Security Assertion Markup Languages (SAML). {www.oasis-open.org/committees/security/}.
[17]
OASIS WS-Trust specification. {http://docs.oasis-open.org/ws-sx/ws-trust/200512}.
[18]
Scavo T, Welch V. A Grid authorization model for science gateways. International workshop on grid computing environments, 2007.
[19]
Sinnott RO, Jiang J, Watt J, Ajayi O. Shibboleth-based access to and usage of grid resources. In: Proceeding of 7th IEEE/ACM international conference on grid computing. Barcelona; September 2006.
[20]
SOAP Profile of XACML-SAML. {www.switch.ch/grid/support/documents/xacmlsaml.pdf}.
[21]
SWITCH Short Lived Credential Service. {http://www.switch.ch/Grid/slcs/}.
[22]
The Shibboleth Project. {http://shibboleth.internet2.edu/}.
[23]
Certificate-based access control for widely distributed resources. In: Proceedings of usenix security symposium,
[24]
Certificate-based authorization policy in a PKI environment. ACM transactions on information and system security(TISSEC). v6 i4. 566-588.
[25]
Using SAML-based VOMS for authorization within web services-based UNICORE grids. In: Proceedings of third UNICORE summit 2007 in springer Lecture Nnotes in Computer Science, euro-par parallel processing workshops, vol. 4854. pp. 112-120.
[26]
Watt J, Ajayi O, Jiang J, Koetsier J, Sinnott RO. A shibboleth-protected privilege management infrastructure for e-science education. In: Proceeding of sixth IEEE international symposium on cluster computing and the grid (CCGRID'06). Singapore; May 2006.
[27]
X.509 proxy certificate for dynamic delegation. In: Proceeding of the third annual PKI R&D workshop,
[28]
Attributes, anonymity, and access: shibboleth and globus integration to facilitate grid collaboration. In: Proceedings of fourth annual PKI R&D workshop,
[29]
XACML specifications. {http://www.oasis-open.org/specs/#xacmlv2.0}.

Cited By

View all

Recommendations

Comments

Please enable JavaScript to view thecomments powered by Disqus.

Information & Contributors

Information

Published In

cover image Journal of Network and Computer Applications
Journal of Network and Computer Applications  Volume 35, Issue 3
May, 2012
311 pages

Publisher

Academic Press Ltd.

United Kingdom

Publication History

Published: 01 May 2012

Author Tags

  1. ARC
  2. Grid middleware
  3. Identity federation
  4. Single sign-on

Qualifiers

  • Article

Contributors

Other Metrics

Bibliometrics & Citations

Bibliometrics

Article Metrics

  • Downloads (Last 12 months)0
  • Downloads (Last 6 weeks)0
Reflects downloads up to 12 Nov 2024

Other Metrics

Citations

Cited By

View all

View Options

View options

Get Access

Login options

Media

Figures

Other

Tables

Share

Share

Share this Publication link

Share on social media