Fine-Grain Access Control Using Shibboleth for the Storage Resource Broker

In this paper, we propose a fine-grain access control system for data resources in the Storage Resource Broker (SRB). The SRB is a Data Grid management system, which can integrate heterogeneous data resources of virtual organizations (VOs). The SRB stores the access control information of individual users in the Metadata Catalog (MCAT) database. However, because of the specific MCAT schema, this information can only be used by the SRB applications. If VOs also have many non-SRB applications, each with its own storage format for user access control information, it creates a scalability problem with regard to administration. To solve this problem, we use Shibboleth, which is an attribute authorization service. By using Shibboleth, the authentication and access control information of the user can be obtained from the user's home institution. Thus, the administration overhead is reduced because the access control information of individual users is now managed by the user's home institution alone, not by MCAT or applications. The use of Shibboleth allows access control decisions to be made based on the user attributes such as role memberships and institutional affiliation, instead of the identity. Thus, our system provides scalable and fine-grain access control and allows privacy protection. Performance analysis shows that our system adds only a small overhead to the existing security infrastructure of the SRB.

[1]  Marty Humphrey,et al.  Security for Grids , 2005, Proceedings of the IEEE.

[2]  Reagan Moore,et al.  The SDSC storage resource broker , 2010, CASCON.

[3]  Dennis G. Kafura,et al.  First experiences using XACML for access control in distributed systems , 2003, XMLSEC '03.

[4]  Robert L. Grossman,et al.  Data integration in a bandwidth-rich world , 2003, CACM.

[5]  Reagan Moore,et al.  MySRB and SRB - components of a Data Grid , 2002, Proceedings 11th IEEE International Symposium on High Performance Distributed Computing.

[6]  Ian T. Foster,et al.  A National-Scale Authentication Infrastructur , 2000, Computer.

[7]  Von Welch,et al.  A Grid Authorization Model for Science Gateways , 2007, GCE 2007.

[8]  Mark Baker,et al.  Emerging grid standards , 2005, Computer.

[9]  Reagan Moore,et al.  MySRB & SRB: Components of a Data Grid , 2002 .