Workflow-based authorization service in the grid

Seung Hyun Kim, Kyong Hoon Kim, Jong Kim, Sung Je Hong, Sangwan Kim

Research output: Contribution to journalArticlepeer-review

3 Scopus citations

Abstract

In a distributed environment, a specific right may be required while a task is controlled and processed. A user should delegate enough rights to a task for processing. Tasks cannot work correctly if delegated rights are insufficient, or security threats may occur if delegated rights are excessive. Restricted delegation is the step that delegates proper rights to a task, and that enables fine-grained authorization in the Grid. In this paper, we propose the WAS architecture as a method for supporting restricted delegation and rights management. In contrast to traditional architecture, the WAS architecture uses a workflow that describes the sequence of rights required for normal execution of a task. By using the workflow, the WAS architecture is able to check whether the task exercises allowed rights. The WAS architecture is implemented on Globus toolkit 2.0 and extended on Globus toolkit 3.0.

Original languageEnglish
Pages (from-to)43-55
Number of pages13
JournalJournal of Grid Computing
Volume2
Issue number1
DOIs
StatePublished - 2004

Keywords

  • Fine-grained authorization service
  • Grid security
  • Restricted delegation
  • Workflow-based authorization

Fingerprint

Dive into the research topics of 'Workflow-based authorization service in the grid'. Together they form a unique fingerprint.

Cite this