Least-Privilege-Based Access Control Model for Job Execution in Grid

  • Authors:
  • Ke Xue;Shaohua Tang;Lina Ge

  • Affiliations:
  • -;-;-

  • Venue:
  • ISDPE '07 Proceedings of the The First International Symposium on Data, Privacy, and E-Commerce
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

In current Grid systems there is a tradeoff between flexibility and security in the context of delegation. Based on the traditional Role-Based-Access-Control module, in order to fulfill the "least privilege" principle, a new delegation model is proposed. This model introduces a task-policy based method to restrict the max privileges a task can delegate; combines static and dynamic delegation method to avoid task being interrupted by lack of privileges during execution; makes use of the credit card mechanism to ensure convenience and reduce risks.