|
| This Article | ||
| ||
| Share | ||
| Bibliographic References | ||
| Add to: | ||
| | ||
| Search | ||
| ||
2008 Fourth IEEE International Conference on eScience
Communicating Security Assertions over the GridFTP Control Channel
December 07-December 12
ISBN: 978-0-7695-3535-7
| ASCII Text | x | ||
| Rajkumar Kettimuthu, Liu Wantao, Frank Siebenlist, Ian Foster, "Communicating Security Assertions over the GridFTP Control Channel," eScience, IEEE International Conference on, pp. 426-427, 2008 Fourth IEEE International Conference on eScience, 2008. | |||
| BibTex | x | ||
| @article{ 10.1109/eScience.2008.108, author = {Rajkumar Kettimuthu and Liu Wantao and Frank Siebenlist and Ian Foster}, title = {Communicating Security Assertions over the GridFTP Control Channel}, journal ={eScience, IEEE International Conference on}, volume = {0}, year = {2008}, isbn = {978-0-7695-3535-7}, pages = {426-427}, doi = {http://doi.ieeecomputersociety.org/10.1109/eScience.2008.108}, publisher = {IEEE Computer Society}, address = {Los Alamitos, CA, USA}, } | |||
| RefWorks Procite/RefMan/Endnote | x | ||
| TY - CONF JO - eScience, IEEE International Conference on TI - Communicating Security Assertions over the GridFTP Control Channel SN - 978-0-7695-3535-7 SP426 EP427 A1 - Rajkumar Kettimuthu, A1 - Liu Wantao, A1 - Frank Siebenlist, A1 - Ian Foster, PY - 2008 KW - GridFTP KW - Security assertion KW - Data movement in Portal environments VL - 0 JA - eScience, IEEE International Conference on ER - | |||
The GridFTP [1] protocol defines a general-purpose mechanism for secure, reliable, high-performance data movement. GridFTP has been widely used for efficiently transferring large volumes of data. GSI is the commonly used security mechanism for GridFTP transfers. In portal environments multiple users logon and initiate third-party data transfers between two remote nodes. Typically, all of these users belong to the same virtual organization and use a common community credential to authenticate with Grid services. Each user will have different access permissions on the end hosts and their permissions are typically embedded into the community credential as SAML assertions. Even though all the users share the community credential, the embedded SAML assertions make the credential for each user unique. Thus a separate GridFTP session needs to be established for each user’s transfer request. Each session needs to be authenticated and authorized, which involves a significant overhead. In this work, we develop a mechanism to reduce the security overhead in authenticating and authorizing the users to perform GridFTP transfers in portal environments. The objective is to provide the GridFTP clients with the ability to specify a SAML-assertion per GridFTP data transfer command while reusing the existing established session between the client and the GridFTP server. We add a new SITE command to achieve this functionality. We implement the new command on the Globus GridFTP server, add new API to the GridFTP client library and enhance the authorization callout on the server to process SAML assertion on a per command basis.
Index Terms:
GridFTP, Security assertion, Data movement in Portal environments
Citation:
Rajkumar Kettimuthu, Liu Wantao, Frank Siebenlist, Ian Foster, "Communicating Security Assertions over the GridFTP Control Channel," escience, pp.426-427, 2008 Fourth IEEE International Conference on eScience, 2008
Usage of this product signifies your acceptance of the Terms of Use.
