An Authorization Mechanism Based on Privilege Negotiation Policy in Grid

作者:Zhang Runlian*; Wu Xiaonian; Dong Xiaoshe; Guan Shangyuan
来源:10th IEEE International Conference on High Performance Computing and Communications, Dalian, China, 2008-09-25 To 2008-09-27.
DOI:10.1109/HPCC.2008.108

摘要

With the dynamic change of users and resources in different secure domains of Grid, the overall consistency of privileges defined would be broken. This would compromise Grid system and waste system overhead on dealing with the increasing grid jobs with invalid privileges. To address the problem, this paper proposes and authorization mechanism based on privilege negotiation policy. This mechanism can detect timely the change of privileges, negotiate automatically and resume quickly the overall consistency of privileges between different secure domains. The test result of the mechanism implementation shows that it shortens greatly the period of resuming the overall consistency of privileges between different secure domains when the consistency was broken. This reduces the number of grid jobs with invalid privileges. Thereby, it avoids wasting more system overhead of dealing with the increasing grid jobs with invalid privileges and improves system performance.

全文