A security framework for a workflow-based grid development platform

Computer Standards & Interfaces - Tập 32 - Trang 230-245 - 2010
José L. Vivas1, Carmen Fernández-Gago1, Javier Lopez1, Andrés Benjumea1
1Department of Computer Science, Complejo Tecnológico, Campus de Teatinos, University of Malaga, 29071, Malaga, Spain

Tài liệu tham khảo

R. Alfieri, R. Cecchini, V. Ciaschini, L. dell’Agnello, A. Frohner, A. Gianoli, K. Lorentey, F. Spataro. VOMS: An authorization system for virtual organizations. Proceedings of the 1st European Across Grids Conference, Santiago de Compostela, Feb. 2003. Anderson, 1998, The steganographic file system, vol. 1525, 73 Androutsellis-Theotokis, 2004, A survey of peer-to-peer content distribution technologies, vol. 36, 4, 335 Atluri, 2001, Security for Workflow Systems, Information Security Technical Report, vol. 6, 2, 59 W. Bagga and R. Molva, Policy-based cryptography and applications, in 9th International Conference on Financial Cryptography and Data Security (FC'2005), 28 February–03 March 2005, Roseau, The Commonwealth of Dominica. Bajaj, 2006 Web Services Policy 1.2 — Attachment (WS-PolicyAttachment), W3C Member Submission, 2006. O. Berthold, H. Federrath, and S. Köpsell, Web Mixes: A system for Anonymous and Unobservable Internet Access. In Proceedings of Designing Privacy. Bhargava, 2004, MPEG video encryption algorithms, vol. 24 Boeyen, 2003, Liberty trust models guidelines A. Bullock and S. Benford. An Access Control Framework for Multi-user Collaborative Environments. In ACM GROUP. Phoenix, AZ. 1999. D.W. Chadwick, A. Otenko, E. Ball. Role-Based Access Control with 470 X.509 Attribute Certificates. IEEE Internet Computing, vol. 7, No 2, March-April 2003. D. Chadwick. Authorization in Grid Computing. Information Security Technical Report, Elsevier, 10(1)33:40, 2005. D. Chaum, Untraceable Electronic Mail, Return Addresses and Pseudonyms. Com. ACM 24, 84–88. Clarke, 2000, Freenet: a distributed anonymous information storage and retrieval system M. Covington, W. Long, S. Srinivasan, A. Dey, M. Ahamad, G.D. Abowd. Securing context-aware applications using environment roles. In ACM Symposium on Access Control Model and Technology. Chantilly, VA. 2001. Czerwinski, 1999, An architecture for a secure service discovery service GREDIA Integrated Architecture. www.gredia.eu. Dabek, 2001, Wide-area cooperative storage with CFS http://eu-datagrid.web.cern.ch/eu-datagrid/. http://datatag.web.cern.ch/datatag/. Dingledine, 2000, The FreeHaven project: distributed anonymous storage service, 67 Douceur, 2002, The Sybil attack P. Druschel and A. Rowstron, Past: A Large-Scale, Persistent Peer-to-Peer Storage Utility. In Proceedings of the Eight Workshop on Hot Topics in Operative Systems. www.earthsystemgrid.org. Foster, 1998, Software infrastructure for the I-WAY metacomputing experiment, Concurrency: Practice & Experience, 10, 567, 10.1002/(SICI)1096-9128(199806)10:7<567::AID-CPE366>3.0.CO;2-X Foster, 2001, The anatomy of the grid: enabling scalable virtual organizations, International Journal of High Performance Computing Applications, 15, 200, 10.1177/109434200101500302 Foster, 2002, The physiology of the grid M. Freedman, E. Sit, J. Cates, and R. Morris, Introducing Tarzan: A Peer to Peer Anonymizing Network Layer. In Proceedings of the 1st International Workshop on Peer-to-Peer Systems (IPTPS'02). The Freedom anonymity system. Web site http://www.fredom.net. Furht, 2004, Fundamentals of multimedia encryption techniques http://www.globus.org/. C.K. Georgiadus, I. Mavridis, G. Pangalos, R. Thomas. Flexible Team-Based Access Control Using Contexts. In ACM Symposium on Access Control Model and Technology. Chantilly, VA. 2001. http://www.ggf.org. https://forge.gridforum.org/sf/projects/ogsa-authz/. Grandison, 2000, A survey of trust in Internet applications Goldschlag, 1999, Onion routing for anonymous and private Internet connections, Comm. ACM, 42, 39, 10.1145/293411.293443 www.Gridalliance.org. Hand, 2002, Mnemosyne: peer-to-peer steganographic storage Harrison, 2003, Cryptographic access control in a distributed file system G. Herrmann, G. Pernul. Viewing business process security from different perspectives, in 11th International Bled Electronic Commerce Conference, Slovenia, 1998. Humphrey, 2005, Security for grids Sheary, 2000 Jøsang, 2007, A survey of trust and reputation systems for online service provision, Decision Support Systems, 43, 618, 10.1016/j.dss.2005.05.019 Kerschbaum, 2006, A trust-based reputation service for virtual organization formation, vol. 3986, 193 Kubiatowicz, 2000, Oceanstore: an architecture for global scale persistent storage von Laszewski, 2005, Towards reputable grids, vol. 6, 3, 95 Lepro, 2003, Cardea: Dynamic access control in distributed systems Liu, 2003, Selective encryption of multimedia content in distribution networks: challenges and new directions, 17 T.Y. Li, H. Zhu, K.Y. Lam, A Novel Two-Level Trust Model for Grid. International Conference on Information and Communications Security, ICICS 2003. S. Qing, D. Gollmann, and J. Zhou (Eds), LNCS 2836, pp: 214–225. M. Lorch, D.B. Adams, D. Kafura, M.S.R. Koneni, A. Rathi, S. Shah, The PRIMA System for Privilege Management, Authorization and Enforcement in Grid Environments. In Fourth International Workshop on Grid Computing, 2003. M. Lorch, B. Cowles, R. Baker, L. Gommans, P. Madsen, A. McNab, L. Ramakrishnan, K. Sankar, D. Skow, M.R. Thompson. Conceptual Grid Authorization Framework and Classification, Global Grid Forum, 23 November 2004, www.gridforum.org/documents/GFD.38.pdf. Martin, 2004, Bringing semantics to web services: the OWL-S approach MojoNation. The MojoNation web site, http://www.mojonation.net. http://www.globus.org/toolkit/security/myproxy/. Nadalin, 2006 The Open Grid Services Architecture, Version 1.0, Global Grid Forum, 29 January 2005. Object Management Group (OMG), 2003 ITU/ISO Recommendation. X.509 Information Technology Open Systems Interconnection — The Directory: Autentication Frameworks, 2000. Technical Corrigendum. ITU-T Recommendation X.509. Information Technology Open Systems Interconnection - The Directory: Public-Key and Attribute Certificate Frameworks, 2000. ISO/IEC 9594-8:2001. L. Pearlman, V. Welch, I. Foster, C. Kesselman, S. Tuecke, A Community Authorization Service for Group Collaboration, Proceedings of the 3rd International Workshop on Policies for Distributed Systems and Networks (POLICY’02), 2002. Pirretti, 2006, Secure attribute-based systems T. Priebe, E.B. Fernandez, J.I., Mehlau, G. Pernul. A Pattern System for Access Control. Proc. 18th Annual IFIP WG 11.3 Working Conference on Data and Application Security, Sitges, Spain, July 2004. Rabin, 1989, Efficient dispersal of information for security, load balancing and fault tolerance, J. ACM, 36, 335, 10.1145/62044.62050 Rhea, 2001, Maintenance-free global storage, IEEE Internet Compu., 40, 10.1109/4236.957894 Sahai, 2005, Fuzzy identity-based encryption, advances in cryptology-Eurocrypt'05, 457 Sandhu, 1994, Access control: principles and practice, IEEE Communications, 32, 40, 10.1109/35.312842 Sandhu, 1996, Role-based access control models, IEEE Computer, 29, 38, 10.1109/2.485845 Serjantov, 2002, Anonymizing censorship resistant systems http://www.shibboleth.internet2.edu. F. Siebenlist, V. Welch, S. Tuecke, I. Foster, N. Nagaratnam, P. Janson, J. Dayke and A. Nadalin. OGSA Security Roadmap, Global Grid Forum, Document 5, Open Grid Security Architecture Security Working Group, July 2003. B. Sotomayor, The Globus Toolkit 3 Programmer's Tutorial. Access Control with Gridmaps, http://www.casa-sotomayor.net/gt3-tutorial/multiplehtml/ch15.html. Treadwell, 2006, Open grid services architecture R. Thomas, R. Sandhu. Task-based Authorization Controls (TBAC): Models for active and enterprise-oriented authorization management. In Database Security XI: Status and Prospects, T.Y. Lin, X. Qian, Eds. North-Holland. 1997. R. Thomas. Team-based access control (TMAC). In Proceedings of 2nd ACM Workshop on Role-Based Access Control. Fairfax, VA. 13–19. 1997. M.R. Thompson, A. Essiari, S. Mudumbai. Certificate-Based Authorization Policy in a PKI Environment. ACM Transactions on Information and System Security (TISSEC), Volume 6, Issue 4 (Nov. 2003), pp 566-588. Trabelsi, 2006, Secure Web service discovery: overcoming challenges of ubiquitous computing S. Trabesi, Y. Roudier, J.C. Pazzaglia, Service Discovery: Reviewing Threats and Security Architectures, Research Report RR-07-197, Institute Eurecom, Mobile Communications Department. Trabelsi, 2007, Context-aware security policy for the service discovery Tueche, 2001, Internet X.509 public key infrastructure proxy certificate profile Vollbrecht, P. Calhoun, S. Farrell, L. Gommans, G. Gross, B. de Bruijn, C. de Laat, M. Holdrege, D. Spence. AAA Authorization Framework, RFC 2904. M. Waldman, A.D. Rubin, and L.F. Cranor, Publius: A Robust, Tamper-Evident, Censorship-Resistant Web Publishing System. In Proceedings of the 9th USENIX Security Symposium. WS-Discovery Specifications, http://msdn.microsoft.com/ws/2005/04/ws-discovery/. http://www.uddi.org. www.oasis-open.org/committees/wsn. www.globus.org/wsrf. Zhu, 2003, Facilitating secure ad-hoc service discovery in public environments F. Zhu, M. Mutka, and L. Ni, Prudent exposure: A private and user centric.