Managing Dynamic User Communities in a Grid of Autonomous Resources

Managing Dynamic User Communities in a Grid of Autonomous Resources
复制标题

管理自治资源网格中的动态用户社区

DOI:
--
复制
发表时间:
2003
期刊:
ArXiv
影响因子:
--
通讯作者:
Károly Lörentey
Károly Lörentey
中科院分区:
--
文献类型:
--
作者:
R. Alfieri;R. Cecchini;V. Ciaschini;L. dell'Agnello;A. Gianoli;F. Spataro;F. Bonnassieux;Philippa J. Hopcroft;G. Lowe;L. Cornwall;J. Jensen;D. Kelsey;Á. Frohner;D. Groep;W. S. Cerff;Martijn Steenbakkers;G. Venekamp;D. Kouril;A. McNab;Olle Mulmo;Mika Silander;Joni Hahkala;Károly Lörentey

文献摘要

参考文献

被引文献

相似文献

网格计算的一个基本概念是创建虚拟组织(VO):一组资源消费者和提供者联合起来解决一个共同的问题。虚拟组织的典型例子包括围绕大型强子对撞机(LHC)实验形成的合作。迄今为止,网格计算的应用规模相对较小,将数十个用户链接到数十个资源,并且这些VO的管理主要是手动操作。随着大规模协作的推进,将150个县的1000个站点与10000多个用户联系起来,需要一个全面的自动化管理系统。它应该足够简单,不会阻止用户,同时确保本地网站的自主性。VO管理服务(VOMS)由欧盟DataGrid和DataTAG项目[1,2]开发,是一个用于管理虚拟组织中用户和资源授权的安全系统。它扩展了现有的网格安全基础设施[3]架构,嵌入了VO从属关系断言,可以由所有VO成员和资源提供者独立验证。在EU DataGrid项目中,用于作业提交、文件和数据库访问的网格服务配备了细粒度的授权系统,该系统考虑了VO成员资格。这也使资源所有者能够确保站点安全并执行本地访问策略。本文将介绍欧盟数据网格的安全体系结构,VO成员服务和本地站点执行机制本地中心授权服务(LCAS),本地证书映射服务(LCMAPS)和Java的信任和授权管理器。
One of the fundamental concepts in Grid computing is the creation of Virtual Organizations (VO's): a set of resource consumers and providers that join forces to solve a common problem. Typical examples of Virtual Organizations include collaborations formed around the Large Hadron Collider (LHC) experiments. To date, Grid computing has been applied on a relatively small scale, linking dozens of users to a dozen resources, and management of these VO's was a largely manual operation. With the advance of large collaboration, linking more than 10000 users with a 1000 sites in 150 counties, a comprehensive, automated management system is required. It should be simple enough not to deter users, while at the same time ensuring local site autonomy. The VO Management Service (VOMS), developed by the EU DataGrid and DataTAG projects[1, 2], is a secured system for managing authorization for users and resources in virtual organizations. It extends the existing Grid Security Infrastructure[3] architecture with embedded VO affiliation assertions that can be independently verified by all VO members and resource providers. Within the EU DataGrid project, Grid services for job submission, file- and database access are being equipped with fine- grained authorization systems that take VO membership into account. These also give resource owners the ability to ensure site security and enforce local access policies. This paper will describe the EU DataGrid security architecture, the VO membership service and the local site enforcement mechanisms Local Centre Authorization Service (LCAS), Local Credential Mapping Service(LCMAPS) and the Java Trust and Authorization Manager.
DOI: 10.12694/scpe.v3i3.192
发表时间: 2000
期刊: Parallel Distributed Comput. Pract.
影响因子: --
作者:
A. Marowka
通讯作者: A. Marowka