Dynamically Authorized Role-Based Access Control for Grid Applications

来源 :Geo-Spatial Information Science | 被引量 : 0次 | 上传用户:juntao2010
下载到本地 , 更方便阅读
声明 : 本文档内容版权归属内容提供方 , 如果您对本文有版权争议 , 可与客服联系进行内容授权或下架
论文部分内容阅读
Grid computing is concerned with the sharing and coordinated use of diverse resources in distributed “virtual organizations”. The heterogeneous, dynamic and multi-domain nature of these environments makes challenging security issues that demand new technical approaches. Despite the recent advances in access control approaches applicable to Grid computing, there remain issues that impede the development of effective access control models for Grid applications. Among them there are the lack of context-based models for access control, and reliance on identity or capability-based access control schemes. An access control scheme that resolve these issues is presented, and a dynamically authorized role-based access control (D-RBAC) model extending the RBAC with context constraints is proposed. The D-RABC mechanisms dynamically grant permissions to users based on a set of contextual information collected from the system and user’s environments, while retaining the advantages of RBAC model. The implementation architecture of D-RBAC for the Grid application is also described. Grid computing is concerned with the sharing and coordinated use of diverse resources in distributed “virtual organizations.” The heterogeneous, dynamic and multi-domain nature of these environments makes challenging security issues that demand new technical approaches. Despite the recent advances in access control approaches applicable to Grid computing, there remain issues that impede the development of effective access control models for Grid applications. Among them there are the lack of context-based models for access control, and reliance on identity or capability-based access control schemes. An access control scheme that resolve these issues is presented, and a dynamically authorized role-based access control (D-RBAC) model extending the RBAC with context constraints is proposed. The D-RABC mechanisms dynamically grant permissions to users based on a set of contextual information collected from the system and user’s environments, while retaining the advantages of RBAC mod el. The implementation architecture of D-RBAC for the Grid application is also described.
其他文献
鸡西矿业集团公司张辰煤矿西三采区3
5月30日,Riverbed宣布推出改进广域网应用性能的Steelhead系列产品,通过优化与高延迟低带宽的广域网的交互方式,实现Riverbed的目标,即将绝大多数远程办公室的IT设备集中整合
In this paper, we initiate the study of identifying when and how a security attack detection problem can have a scalable solution. We use tools from Communicati
To solve the problem of the information share and services integration in population information system, we propose a multi-layer tree hierarchical architecture
(接上期)四、完善培训准备完善的培训准备是培训项目能否正常实施的基本要求,是职业培训市场开发成败的必需条件。完善培训准备包括开展培训项目必须落实的项目 (Continued)
2015年4月11日,第四届菠萝科学奖在杭州举行,共有10项科学研究项目摘得“殊荣”。让我们一起来盘点其中那些有趣的科学奖项。  科学菠萝奖——数学奖  还记得20世纪80年代的一个棒棒糖广告吗?小男孩向森林中的动物们请教一个问题:“棒棒糖需要舔多少口才能被完全吃掉?”动物们谁也无法给出答案。如今,已有人成功地解决了这个难题。纽约大学柯朗数学研究所通过研究得知,棒棒糖需要舔1000次才能被完全吃掉
“家庭是人生的第一学校,是生活和心灵的港湾。家庭理应成为孩子勇敢面对困难和逆境的强大思想后盾。”近期,高校接连发生了几起大学生的惨痛悲剧,我们在被这些事件深深震撼
二联和三联疗法治疗儿童HP感染胃炎 意大利的医务人员通过双盲、随机、多中心试验,观察应用三联疗法(兰索拉唑、阿莫西林、替硝唑)和二联疗法(阿莫西林、替硝唑)治疗一周对儿童HP感染的影响。结果表明:两种方案能达到同样的根除HP效果。无论是否根除HP,多数儿童治疗后症状很快消失或改善。但有HP感染的儿童,两年内上腹疼痛复发率高(Helicobacter,2004,9:293-301)。
为弘扬雷锋精神,让雷锋精神真正深入人心,本文从高校入手,探讨推动雷锋活动常态化的必要性与可行性,高校推进雷锋活动常态化具有的优势以及高校如何推动雷锋活动常态化。 In
若干次路过北京,无数次在圆明园前徘徊,我都不敢走进这个举世闻名的废墟。因为历史的悲惨,我一直怕着那份彻骨的痛楚。终于,我有勇气走进了圆明园。  园门照例是皇家园林的那种富丽堂皇的气派,只是游人很少,如我般慢慢随意前行的更是没有。照例是百看不厌的花、树、草,甚至月季在这里长成了我从没有见过的爬蔓状,搭成了小径,成了天然的门廊,硕大的花朵就在人的脸旁散发着芳香。我仔细寻找着被烧被毁的痕迹,但是没有,并