Cacheable Decentralized Groups for Grid Resource Access Control

  • Authors:
  • Jeffrey Hemmes;Douglas Thain

  • Affiliations:
  • Department of Computer Science and Engineering, University of Notre Dame, Notre Dame, Indiana, USA. jhemmes@cse.nd.edu;Department of Computer Science and Engineering, University of Notre Dame, Notre Dame, Indiana, USA. dthain@cse.nd.edu

  • Venue:
  • GRID '06 Proceedings of the 7th IEEE/ACM International Conference on Grid Computing
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

Sharing data among collaborators in widely distributed systems remains a challenge due to limitations with existing methods for defining groups across administrative domain boundaries with various file systems. Groups in traditional systems are bound to particular domains or file systems using centralized storage locations either beyond ordinary users' ability to manage, inaccessible outside a closed system, or both. We present a method for users to independently create and manage groups on any networked workstation using global user identities and to control access to shared data and storage resources based on group membership, regardless of domain boundaries or underlying file systems. Decentralized groups are decoupled from shared user databases and centralized authentication servers through the use of a virtual user namespace. We describe how owners of shared resources can define security policies through the use of caching, and demonstrate how each caching policy represents tradeoffs between performance, scalability, and consistency.