Abstract
In this paper, we propose an architecture to integrate authentication and authorization schemes for constructing a secure Grid system. In our proposed method, SAML (Security Assertion Markup Language) and XACML (eXtensible Access Control Markup Language) play key solution roles in integrating single sign-on and authorization. IBM and Microsoft are already leading in the standardization of security for Grid computing. Nevertheless, we recommended SAML as an alternative to the existing standard that they recommend. Therefore, our proposed architecture opens up the possibility of adopting a variety of single sign-on technologies in constructing secure Grid computing. Additionally, in order to implement access control, we recommended XACML, which gives Grid computing an efficient way to implement role-based access control.
Preview
Unable to display preview. Download preview PDF.
Similar content being viewed by others
References
OWASP (Open Web Application Security Project), http://www.owasp.org/document/topten.html
Globus Toolkit 4.0 Release Manuals, http://www.globus.org/toolkit/docs/4.0/security/prewsaa/Pre_WS_AA_Release_Notes.html
OASIS (Organization for the Advancement of Structured Information Standards), http://www.open-oasis.org
Pfitzmann, B., Waidner, B.: Token-based web Single Signon with Enabled Clients. IBM Research Report RZ 3458 (#93844) (November 2002)
eXtensible Access Control Markup Language (XACML) Version 1.0, http://www.oasis-open.org/committees/xacml/repository/
Mark, O., et al.: Web Services Security. McGraw-Hill/Osborne, New York (2003)
Bindings and Profiles for the OASIS Security Assertion Markup Language (SAML) V1.1, http://www.oasis-open.org/committees/security/
Jeong, J., Shin, D., Shin, D., Oh, H.: A Study on XML-based Single Sign-On System Supporting Mobile and Ubiquitous Service Environments. In: Yang, L.T., Guo, M., Gao, G.R., Jha, N.K. (eds.) EUC 2004. LNCS, vol. 3207, pp. 903–913. Springer, Heidelberg (2004)
Author information
Authors and Affiliations
Editor information
Editors and Affiliations
Rights and permissions
Copyright information
© 2006 Springer-Verlag Berlin Heidelberg
About this paper
Cite this paper
Jeong, J., Yu, W., Shin, D., Shin, D., Moon, K., Lee, J. (2006). Integration of Single Sign-On and Role-Based Access Control Profiles for Grid Computing. In: Zhou, X., Li, J., Shen, H.T., Kitsuregawa, M., Zhang, Y. (eds) Frontiers of WWW Research and Development - APWeb 2006. APWeb 2006. Lecture Notes in Computer Science, vol 3841. Springer, Berlin, Heidelberg. https://doi.org/10.1007/11610113_89
Download citation
DOI: https://doi.org/10.1007/11610113_89
Publisher Name: Springer, Berlin, Heidelberg
Print ISBN: 978-3-540-31142-3
Online ISBN: 978-3-540-32437-9
eBook Packages: Computer ScienceComputer Science (R0)