Nephele: Scalable Access Control for Federated File Services

  • Authors:
  • Giorgos Margaritis;Andromachi Hatzieleftheriou;Stergios V. Anastasiadis

  • Affiliations:
  • Department of Computer Science, University of Ioannina, Ioannina, Greece 45110;Department of Computer Science, University of Ioannina, Ioannina, Greece 45110;Department of Computer Science, University of Ioannina, Ioannina, Greece 45110

  • Venue:
  • Journal of Grid Computing
  • Year:
  • 2013

Quantified Score

Hi-index 0.00

Visualization

Abstract

The integration of storage resources across different administrative domains can serve as building block for the development of efficient collaboration environments. In order to improve application portability across such environments, we target data sharing facilities that securely span multiple domains at the filesystem rather than the application level. We introduce the hypergroup as an heterogeneous two-layer construct, where the upper layer consists of administrative domains and the lower layer of users from each participating domain. We use public keys to uniquely identify users and domains, but rely on credentials to securely bind users and domains with hypergroups. Each domain is responsible for authenticating its local users across the federation, and employs access control lists to specify the rights of individual users and hypergroups over local storage resources. In comparison to existing systems, we show both analytically and experimentally reduced transfer cost of remote authorizations and improved scalability properties.