Jong Kim, Pohang University of Science and Technology (POSTECH)
Sung-Je Hong, Pohang University of Science and Technology (POSTECH)
Sangwan Kim, Korea Institute of Science and Technology Information (KISTI)
In a distributed environment, specific rights may be required while a task is controlled and processed. A user should delegate enough rights to a task for processing. Tasks cannot work correctly if delegated rights are insufficient, or security threats may occur if delegated rights are excessive. Restricted delegation is the step that delegates proper rights to a task, and that enables fine-grained authorization in Grid. In this paper, we propose WAS architecture as the method for supporting restricted delegation and rights management. In contrast to traditional architecture, WAS architecture uses a workflow that describes the sequence of rights required for normal execution of a task. By using the workflow, WAS architecture is able to check whether the task exercises allowed rights. WAS architecture is implemented on Globus toolkit 2.0.
Index Terms:
Grid security, fine-grained authorization service, restricted delegation
Citation:
Seung-Hyun Kim, Jong Kim, Sung-Je Hong, Sangwan Kim, "Workflow-based Authorization Service in Grid," grid, pp.94, Fourth International Workshop on Grid Computing, 2003