课题基金 / 基金详情

SCI: Collaborative Research: NMI DEVELOPMENT: Policy Controlled Attribute Framework

SCI: Collaborative Research: NMI DEVELOPMENT: Policy Controlled Attribute Framework
SCI:协作研究:NMI 开发:策略控制属性框架
批准号:
0438385
负责人:
Katarzyna Keahey
金额:
$59.55万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2004
资助国家:
美国
项目状态:
已结题
起止时间:
2004-12-01 至 2007-11-30

项目摘要

项目成果

Katarzyna Keahey的其他基金

相似基金

相关文献

中文摘要
翻译
该建议集成了GSI和Shibboleth,形成了一个强大的属性基础设施的校园环境,使用户属性的安全验证机构间的网格用户。该项目将提供一个框架,允许多组织协作中的参与者控制他们想要发布、共享和向其他各方透露的属性信息。这些参与方还将能够通过将其能力与服务的所需属性的共享策略相匹配来确定他们是否拥有访问服务的能力。将通过使用匿名公钥凭证来支持匿名交互,这些公钥凭证由客户端自行决定映射到客户端的身份。该项目充分利用并扩展了现有技术,主要是Internet2的Shibboleth,Globus Alliance的Globus Toolkit和NCSA的Gridtechnology Service。该框架将使用Shibboleth的属性授权服务(SAAS)及其属性发布策略来限制与其他方通信的属性。我们将通过与Globus Toolkit集成来实现Web服务访问,从而增强这些Shibboleth服务。为了实现匿名部署,将为网格安全服务开发一个模块,以允许经过身份验证的用户获得不会泄露其身份的公钥证书,但与网格安全基础设施完全兼容。最后,将开发和实现格式和协议,以表达、发布、共享和匹配与属性相关的策略和功能。
英文摘要
This proposal integrates GSI and Shibboleth to form a robust attribute infrastructure for campus environments to enable secure verification of user attributes by inter-institutional Grid users. This project will deliver a framework that allows participants in multi organizational collaborations to control the attribute information that they want to publish, share, and reveal to other parties. Those parties will be also be able to determine whether they possess the capabilities to access a service by matching their capabilities with the service's shared policy of required attributes. Pseudonymous interactions will be supported through the use of anonymous public key credentials that are mapped to the client's identity at the client's own discretion. The project substantially leverages on and extends existing technologies, primarily Internet2's Shibboleth, the Globus Alliance's Globus Toolkit, and NCSA's GridLogon Service. The framework will use Shibboleth's Attribute Authority service (SAAS) and its attribute release policies to restrict the attributes communicated to other parties. We will enhance these Shibboleth services by enabling Web services access through integration with the Globus Toolkit. To enable pseudonymous deployment, a module will be developed for the GridLogon service to allow authenticated users to obtain public key credentials that do not reveal their identity, yet are fully compatible with the Grid Security Infrastructure. Lastly, formats and protocols will be developed and implemented to express, publish, share, and match attribute-related policies and capabilities.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: Disciplinary Improvements: Repeto: Building a Network for Practical Reproducibility in Experimental Computer Science
  • 批准号:
    2226406
  • 项目类别:
    Standard Grant
  • 资助金额:
    $39.0万
  • 财政年份:
    2022
  • 负责人:
    Katarzyna Keahey
  • 依托单位:
Collaborative Research: CyberTraining: Implementation: Medium: FOUNT: Scaffolded, Hands-On Learning for a Data-Centric Future
  • 批准号:
    2230077
  • 项目类别:
    Standard Grant
  • 资助金额:
    $26.7万
  • 财政年份:
    2022
  • 负责人:
    Katarzyna Keahey
  • 依托单位:
CCRI: Medium: FLOTO: A Discovery Testbed for Measurement of Internet Access Networks
  • 批准号:
    2213821
  • 项目类别:
    Standard Grant
  • 资助金额:
    $156.52万
  • 财政年份:
    2022
  • 负责人:
    Katarzyna Keahey
  • 依托单位:
Collaborative Research: Chameleon Phase III: A Large-Scale, Reconfigurable Experimental Environment for Cloud Research
  • 批准号:
    2027170
  • 项目类别:
    Cooperative Agreement
  • 资助金额:
    $614.9万
  • 财政年份:
    2020
  • 负责人:
    Katarzyna Keahey
  • 依托单位:
海外基金