Enhanced CAS Certificate for Metadata-Based Access Control in Grids

Sang M. Park, Soon Myoung Chung · 2008

This paper presents an enhanced design of the community authorization service (CAS) which supports centralized, fine-grain access control by managing the memberships, service types, resource objects and security policies of a virtual organization (VO). The current CAS provides fundamental solutions regarding user privacy, authentication and authorization, but it has some limitations due to its centralized management of the security policies of a VO, in terms of scalability, flexibility and interoperability. We enhanced the CAS to support diverse security requirements within a dynamic grid computing environment by enabling the CAS server to publish a proxy certificate embedding additional attributes of users. It allows the service providers to support customized services by analyzing the attributes of users and security policies.

Read the paper · More papers on PaperTik