Explicit Trust Delegation: Security for dynamic Grids
David Snelling, SVEN VAN DEN BERGHE, Vivian Qian Li · Fujitsu Scientific and Technical Journal · 2004
This paper addresses the issue of how to build dynamic Grids without using the non-standard proxy extensions that cause concern within the security community. The approach allows commonly available security tools and libraries to invoke requests (on the client side) and respond (on the server side) using only well-established security protocols. This description is made in the context of the UNICORE Grid infrastructure. UNICORE is known to have a strong, respected security model, but at the cost of not supporting some dynamic Grid capabilities. The discussion shows how UNICORE could be enhanced using Explicit Trust Delegation to provide dynamic capabilities, hitherto only possible in Grids supporting a proxy-based security model. We show how this approach provides a smooth migration path to proposed work on Virtual Organizations.