TY - JOUR
T1 - Workflow-based authorization service in the grid
AU - Kim, Seung Hyun
AU - Kim, Kyong Hoon
AU - Kim, Jong
AU - Hong, Sung Je
AU - Kim, Sangwan
PY - 2004
Y1 - 2004
N2 - In a distributed environment, a specific right may be required while a task is controlled and processed. A user should delegate enough rights to a task for processing. Tasks cannot work correctly if delegated rights are insufficient, or security threats may occur if delegated rights are excessive. Restricted delegation is the step that delegates proper rights to a task, and that enables fine-grained authorization in the Grid. In this paper, we propose the WAS architecture as a method for supporting restricted delegation and rights management. In contrast to traditional architecture, the WAS architecture uses a workflow that describes the sequence of rights required for normal execution of a task. By using the workflow, the WAS architecture is able to check whether the task exercises allowed rights. The WAS architecture is implemented on Globus toolkit 2.0 and extended on Globus toolkit 3.0.
AB - In a distributed environment, a specific right may be required while a task is controlled and processed. A user should delegate enough rights to a task for processing. Tasks cannot work correctly if delegated rights are insufficient, or security threats may occur if delegated rights are excessive. Restricted delegation is the step that delegates proper rights to a task, and that enables fine-grained authorization in the Grid. In this paper, we propose the WAS architecture as a method for supporting restricted delegation and rights management. In contrast to traditional architecture, the WAS architecture uses a workflow that describes the sequence of rights required for normal execution of a task. By using the workflow, the WAS architecture is able to check whether the task exercises allowed rights. The WAS architecture is implemented on Globus toolkit 2.0 and extended on Globus toolkit 3.0.
KW - Fine-grained authorization service
KW - Grid security
KW - Restricted delegation
KW - Workflow-based authorization
UR - http://www.scopus.com/inward/record.url?scp=84855384707&partnerID=8YFLogxK
U2 - 10.1007/s10723-004-2080-1
DO - 10.1007/s10723-004-2080-1
M3 - Article
AN - SCOPUS:84855384707
SN - 1570-7873
VL - 2
SP - 43
EP - 55
JO - Journal of Grid Computing
JF - Journal of Grid Computing
IS - 1
ER -