PRIMA - Privilege Management and Authorization in Grid Computing Environments

Computational grids and other heterogeneous, large-scale distributed systems require more powerful and more flexible authorization mechanisms to realize fine-grained access-control of resources. Computational grids are increasingly used for collaborative problem-solving and advanced science and engi...

Full description

Bibliographic Details
Main Author: Lorch, Markus
Other Authors: Computer Science
Format: Others
Published: Virginia Tech 2014
Subjects:
Online Access:http://hdl.handle.net/10919/26995
http://scholar.lib.vt.edu/theses/available/etd-04192004-092304/
id ndltd-VTETD-oai-vtechworks.lib.vt.edu-10919-26995
record_format oai_dc
spelling ndltd-VTETD-oai-vtechworks.lib.vt.edu-10919-269952020-09-26T05:30:32Z PRIMA - Privilege Management and Authorization in Grid Computing Environments Lorch, Markus Computer Science Kafura, Dennis G. Hicks, James O. Jr. Varadarajan, Srinidhi Ramakrishnan, Naren Ribbens, Calvin J. Distributed Systems Grid Security Computer Security Computational grids and other heterogeneous, large-scale distributed systems require more powerful and more flexible authorization mechanisms to realize fine-grained access-control of resources. Computational grids are increasingly used for collaborative problem-solving and advanced science and engineering applications. Usage scenarios for advanced grids require support for small, dynamic working groups, direct delegation of access privileges among users, procedures for establishing trust relationships without requiring organizational level agreements, precise management by individuals of their privileges, and retention of authority by resource providers. Existing systems fail to provide the necessary flexibility and granularity to support these scenarios. The reasons include the overhead imposed by required administrator intervention, coarse granularity that only allows for all-or-nothing access control decisions, and the inability to implement finer-grained access control without requiring trusted application code. PRIMA, the model and system developed in this research, focuses on management and enforcement of fine-grained privileges. The PRIMA model introduces novel approaches that can be used in place of, or in combination with existing access control mechanisms. PRIMA enables the users of a system to manage access to their own assets directly without the need for, and costs of intervention by technical personnel. System administrators benefit from more flexible and fine-grained definition of access privileges and policies. A novel access control decision and enforcement model with support for legacy applications has been developed. The model uses on-demand account leasing and implements expressive enforcement mechanisms built on existing low-overhead security primitives of the operating systems. The combination of the PRIMA components constitutes a comprehensive security model that facilitates highly dynamic authorization scenarios and increases security through least privilege access to resources. In summary, PRIMA mechanisms enable the use of fine-grained access rights, reduce administrative costs to resource providers, enable ad-hoc and dynamic collaboration scenarios, and provide improved security service to long-lived grid communities. Ph. D. 2014-03-14T20:10:03Z 2014-03-14T20:10:03Z 2004-04-16 2004-04-19 2004-04-28 2004-04-28 Dissertation etd-04192004-092304 http://hdl.handle.net/10919/26995 http://scholar.lib.vt.edu/theses/available/etd-04192004-092304/ dissertation-markus-lorch-2004-04-19.pdf In Copyright http://rightsstatements.org/vocab/InC/1.0/ application/pdf Virginia Tech
collection NDLTD
format Others
sources NDLTD
topic Distributed Systems
Grid Security
Computer Security
spellingShingle Distributed Systems
Grid Security
Computer Security
Lorch, Markus
PRIMA - Privilege Management and Authorization in Grid Computing Environments
description Computational grids and other heterogeneous, large-scale distributed systems require more powerful and more flexible authorization mechanisms to realize fine-grained access-control of resources. Computational grids are increasingly used for collaborative problem-solving and advanced science and engineering applications. Usage scenarios for advanced grids require support for small, dynamic working groups, direct delegation of access privileges among users, procedures for establishing trust relationships without requiring organizational level agreements, precise management by individuals of their privileges, and retention of authority by resource providers. Existing systems fail to provide the necessary flexibility and granularity to support these scenarios. The reasons include the overhead imposed by required administrator intervention, coarse granularity that only allows for all-or-nothing access control decisions, and the inability to implement finer-grained access control without requiring trusted application code. PRIMA, the model and system developed in this research, focuses on management and enforcement of fine-grained privileges. The PRIMA model introduces novel approaches that can be used in place of, or in combination with existing access control mechanisms. PRIMA enables the users of a system to manage access to their own assets directly without the need for, and costs of intervention by technical personnel. System administrators benefit from more flexible and fine-grained definition of access privileges and policies. A novel access control decision and enforcement model with support for legacy applications has been developed. The model uses on-demand account leasing and implements expressive enforcement mechanisms built on existing low-overhead security primitives of the operating systems. The combination of the PRIMA components constitutes a comprehensive security model that facilitates highly dynamic authorization scenarios and increases security through least privilege access to resources. In summary, PRIMA mechanisms enable the use of fine-grained access rights, reduce administrative costs to resource providers, enable ad-hoc and dynamic collaboration scenarios, and provide improved security service to long-lived grid communities. === Ph. D.
author2 Computer Science
author_facet Computer Science
Lorch, Markus
author Lorch, Markus
author_sort Lorch, Markus
title PRIMA - Privilege Management and Authorization in Grid Computing Environments
title_short PRIMA - Privilege Management and Authorization in Grid Computing Environments
title_full PRIMA - Privilege Management and Authorization in Grid Computing Environments
title_fullStr PRIMA - Privilege Management and Authorization in Grid Computing Environments
title_full_unstemmed PRIMA - Privilege Management and Authorization in Grid Computing Environments
title_sort prima - privilege management and authorization in grid computing environments
publisher Virginia Tech
publishDate 2014
url http://hdl.handle.net/10919/26995
http://scholar.lib.vt.edu/theses/available/etd-04192004-092304/
work_keys_str_mv AT lorchmarkus primaprivilegemanagementandauthorizationingridcomputingenvironments
_version_ 1719340566390505472