Flexible session management in a distributed environment

Flexible session management in a distributed environment
复制标题

分布式环境中灵活的会话管理

DOI:
10.1088/1742-6596/219/4/042017
复制
发表时间:
2010
期刊:
Journal of Physics: Conference Series
影响因子:
--
通讯作者:
I. Sfiligoi
I. Sfiligoi
中科院分区:
--
文献类型:
--
作者:
Z. Miller;D. Bradley;T. Tannenbaum;I. Sfiligoi

文献摘要

被引文献

相似文献

分布式系统使用的许多安全通信库,例如 SSL、TLS 和 Kerberos,未能明确区分身份验证、会话和通信层。在本文中,我们介绍了 Condor 高吞吐量计算软件使用的安全通信库 CEDAR,并介绍了 CEDAR 分离这些层所带来的分布式计算系统的优势。无论使用哪种身份验证方法,CEDAR 都会建立安全会话密钥,该密钥可以灵活地用于多种功能。我们演示了安全会话的分层方法如何避免网络身份验证中固有的往返和延迟。创建独特的会话管理层可以通过将会话委托给系统中的其他组件来进行优化,从而提高可扩展性。此会话委托创建了一条信任链​​,可减少建立安全连接的开销,并支持集中执行系统范围的安全策略。此外,基于 UDP 数据报的安全通道经常被现有库所忽视;我们展示了 CEDAR 的结构如何适应这一点。作为这项工作实用性的一个例子,我们展示了如何使用委托安全会话和 CEDAR 架构中固有的其他技术使 US CMS 能够满足在大规模、广域网格系统上部署 Condor 时的可扩展性要求。
Many secure communication libraries used by distributed systems, such as SSL, TLS, and Kerberos, fail to make a clear distinction between the authentication, session, and communication layers. In this paper we introduce CEDAR, the secure communication library used by the Condor High Throughput Computing software, and present the advantages to a distributed computing system resulting from CEDAR's separation of these layers. Regardless of the authentication method used, CEDAR establishes a secure session key, which has the flexibility to be used for multiple capabilities. We demonstrate how a layered approach to security sessions can avoid round-trips and latency inherent in network authentication. The creation of a distinct session management layer allows for optimizations to improve scalability by way of delegating sessions to other components in the system. This session delegation creates a chain of trust that reduces the overhead of establishing secure connections and enables centralized enforcement of system-wide security policies. Additionally, secure channels based upon UDP datagrams are often overlooked by existing libraries; we show how CEDAR's structure accommodates this as well. As an example of the utility of this work, we show how the use of delegated security sessions and other techniques inherent in CEDAR's architecture enables US CMS to meet their scalability requirements in deploying Condor over large-scale, wide-area grid systems.