Cross-Domain Grid Authentication and Authorization Scheme Based on Trust Management and Delegation

Sunan Shen,Shaohua Tang
DOI: https://doi.org/10.1109/CIS.2008.185
2008-01-01
Abstract:As grid’s dynamic, distributed and open nature, the issue of mutual trust among grid entities is challenging, not only because of the entities in different domains, but also because the fact that those domains may deploy different security mechanisms. A federal authentication and authorization scheme based upon trust management and delegation is proposed. Different security domains can join in the federation through the interface that our approach provides. The establishment of trust relationship among domains is based on trust negotiation and PKI cross-certification. We make authorization relay on dynamic role translation and on delegation. The Security Assertion Markup Language (SAML) is adopted by exploiting its AttributeStatement to create Delegation Assertion for grid.
What problem does this paper attempt to address?