loading...
 This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
First International Conference on Availability, Reliability and Security (ARES'06)
Recovery Mechanism of Online Certification Chain in Grid Computing
Vienna, Austria
April 20-April 22
ISBN: 0-7695-2567-9
MingChu LI, Dalian University of Technology
Hongyan YAO, Dalian University of Technology
Jianbo MA, Tianjin University
Proxy credential are commonly used in security system when one entity wishes to grant some set of its privileges to another entity. Proxy credential chain is produced when new entities with proxy credentials use their proxy credentials to authenticate and establish secured connections with other entities in the same manner and are asked to wait for the completion of a task online. Due to network unstable, some middle node of the credential chain is not accessed by certain reasons, and, as a result, proxy credential chain problem occurs. The problem is an important research issue in Grid security. In this paper, we explore the problem by using double signatures and applying X.509 proxy credential. We provides a method to create double signatures using data redundancy and to establish proxy credential chain with double signatures, and provide a recovery mechanism of proxy credential chain in Grid when certificate chain broken problem occurs. We analyze the disadvantages of existing mechanism when the middle-node of the credentials chain was broken, and present a new scheme to extend the existing mechanism (including the description of new proxy credential format, the creation mechanism of proxy credentials and the strategy of validating). We also analyze the security of our new scheme.
Index Terms:
Grid security, Proxy certificate, Certifucate Chain, Double signature
Citation:
MingChu LI, Hongyan YAO, Jianbo MA, "Recovery Mechanism of Online Certification Chain in Grid Computing," ares, pp.558-562, First International Conference on Availability, Reliability and Security (ARES'06), 2006
Usage of this product signifies your acceptance of the Terms of Use.