A security architecture for the ALICE Grid Services

Steffen Schreiner · 2012

Globally distributed research cyberinfrastructures, like the ALICE Grid Services, need to provide traceability and accountability of operations and internal interactions.This document presents a new security architecture for the ALICE Grid Services, allowing to establish non-repudiation with respect to creatorship and ownership of Grid files and jobs.It is based on mutually authenticated and encrypted communication using X.509 Public Key Infrastructure and the Transport Layer Security (TLS) protocol.Introducing certified Grid file entries and signed Grid jobs by implementing a model of Mediated Definite Delegation it allows to establish long-term accountability concerning Grid jobs and files.Initial submissions as well as any alteration of Grid jobs are becoming verifiable and can be traced back to the originator.The architecture has been implemented as a prototype along with the development of a new central Grid middleware, called jAliEn.

Read the paper · More papers on PaperTik