Loading…

Fine-grained access control for GridFTP using SecPAL

Grid access control policy languages today are generally one of two extremes: either extremely simplistic, or overly complex and challenging for even security experts to use. In this paper, we explicitly identify requirements for an access control policy language for grid data and then consider six...

Full description

Saved in:
Bibliographic Details
Main Authors: Humphrey, M., Sang-Min Park, Jun Feng, Beekwilder, N., Wasson, G., Hogg, J., LaMacchia, B., Dillaway, B.
Format: Conference Proceeding
Language:English
Subjects:
Online Access:Request full text
Tags: Add Tag
No Tags, Be the first to tag this record!
Description
Summary:Grid access control policy languages today are generally one of two extremes: either extremely simplistic, or overly complex and challenging for even security experts to use. In this paper, we explicitly identify requirements for an access control policy language for grid data and then consider six specific data access use-cases that have been problematic in today's grids: attribute-based access, role-based access, "role-deny" access, impersonation-based access, delegation-based access, and capability-based access. We evaluate the security policy assertion language (SecPAL) against those requirements, specifically in the context of these six use-cases involving GridFTP.NET. We find that while some of these six use-cases are individually possible via existing Grid authorization systems, we believe that SecPAL uniquely offers a single approach that meets the requirements of a grid access control policy language, thereby creating support for a wide range of expanded scenarios for grid data access.
ISSN:2152-1085
2152-1093
DOI:10.1109/GRID.2007.4354136