Semantic-based authorization architecture for Grid

  • Authors:
  • Juan M. Marín Pérez;Jorge Bernal Bernabé;Jose M. Alcaraz Calero;Felix J. Garcia Clemente;Gregorio Martínez Pérez;Antonio F. Gómez Skarmeta

  • Affiliations:
  • Department of Information and Communications Engineering, University of Murcia, Facultad de Informatica,Campus de Espinardo, s/n, 30071 Murcia, Spain;Department of Information and Communications Engineering, University of Murcia, Facultad de Informatica,Campus de Espinardo, s/n, 30071 Murcia, Spain;Department of Information and Communications Engineering, University of Murcia, Facultad de Informatica,Campus de Espinardo, s/n, 30071 Murcia, Spain and Automated Infrastructure Lab, Hewlett Pack ...;Department of Information and Communications Engineering, University of Murcia, Facultad de Informatica,Campus de Espinardo, s/n, 30071 Murcia, Spain;Department of Information and Communications Engineering, University of Murcia, Facultad de Informatica,Campus de Espinardo, s/n, 30071 Murcia, Spain;Department of Information and Communications Engineering, University of Murcia, Facultad de Informatica,Campus de Espinardo, s/n, 30071 Murcia, Spain

  • Venue:
  • Future Generation Computer Systems
  • Year:
  • 2011

Quantified Score

Hi-index 0.00

Visualization

Abstract

There are a few issues that still need to be covered regarding security in the Grid area. One of them is authorization where there exist good solutions to define, manage and enforce authorization policies in Grid scenarios. However, these solutions usually do not provide Grid administrators with semantic-aware components closer to the particular Grid domain and easing different administration tasks such as conflict detection or resolution. This paper defines a proposal based on Semantic Web to define, manage and enforce security policies in a Grid scenario. These policies are defined by means of semantic-aware rules which help the administrator to create higher-level definitions with more expressiveness. These rules also permit performing added-value tasks such as conflict detection and resolution, which can be of interest in medium and large scale scenarios where different administrators define the authorization rules that should be followed before accessing a resource in the Grid. The proposed solution has been also tested providing some reasonable response times in the authorization decision process.