|
ABSTRACT
As distributed applications such as Grid and enterprise systems scale up and become increasingly complex, their authorization infrastructures-based predominantly on the request-response paradigm-are facing challenges in terms of fragility and poor scalability. We propose an approach where each application server caches previously received authorizations at its secondary decision point and shares them with other application servers to mask authorization server failures and network delays.This paper presents the design of our cooperative secondary authorization recycling system and its evaluation using simulation and prototype implementation. The results demonstrate that our approach improves the availability of authorization infrastructures while preserving their performance characteristics. Specifically, by sharing authorizations, the cache hit rate.an indirect metric of availability.can reach 70%, even when only 10% of authorizations are cached. Depending on the deployment scenario, the performance in terms of the average time for authorizing an application request can be reduced by up to 30%.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
|
| |
2
|
D. E. Bell and L. J. LaPadula. Secure computer systems: Mathematical foundations. Technical Report ESD-TR-74-244, MITRE, March 1973.
|
 |
3
|
|
 |
4
|
|
 |
5
|
|
| |
6
|
|
 |
7
|
Manuel Costa , Jon Crowcroft , Miguel Castro , Antony Rowstron , Lidong Zhou , Lintao Zhang , Paul Barham, Vigilante: end-to-end containment of internet worms, Proceedings of the twentieth ACM symposium on Operating systems principles, October 23-26, 2005, Brighton, United Kingdom
|
 |
8
|
|
| |
9
|
L. G. DeMichiel, L. U. Yalcinalp, and S. Krishnan. Enterprise JavaBeans Specification, Version 2.0. Sun Microsystems, 2001.
|
| |
10
|
Entrust. getaccess design and administration guide. Technical report, Entrust, September 20 1999.
|
| |
11
|
S. Gadde, J. Chase, and M. Rabinovich. A taste of crispy Squid. In Proceedings of the 1998 Workshop on Internet Server Performance, pages 129--136, June 1998.
|
 |
12
|
|
| |
13
|
|
| |
14
|
|
 |
15
|
|
| |
16
|
M. Locasto, S. Sidiroglou, and A. D. Keromytis. Software self-healing using collaborative application communities. In Proceedings of the Internet Society (ISOC) Symposium on Network and Distributed Systems Security (NDSS 2006), pages 95--106, San Diego, CA, 2006.
|
| |
17
|
P. J. Mazzuca. Access control in a distributed decentralized network: an XML approach to network security using XACML and SAML. Technical report, Dartmouth College, Computer Science, Spring 2004.
|
| |
18
|
Netegrity. Siteminder concepts guide. Technical report, Netegrity, 2000.
|
| |
19
|
|
| |
20
|
OMG. CORBAservices: Common object services specification, security service specification v1.8, 2002.
|
| |
21
|
|
| |
22
|
Securant. Unified access management: A model for integrated web security. Technical report, Securant Technologies, June 25 1999.
|
| |
23
|
G. H. Stowe. A secure network node approach to the policy decision point in distributed access controlw. Technical report, Dartmouth College, Computer Science, June 2004.
|
| |
24
|
W. Vogels. How wrong can you be? Getting lost on the road to massive scalability. In Middleware Conference, Toronto, October 20 2004.
|
 |
25
|
|
| |
26
|
Von Welch , Frank Siebenlist , Ian Foster , John Bresnahan , Karl Czajkowski , Jarek Gawor , Carl Kesselman , Sam Meder , Laura Pearlman , Steven Tuecke, Security for Grid Services, Proceedings of the 12th IEEE International Symposium on High Performance Distributed Computing, p.48, June 22-24, 2003
|
| |
27
|
XACML-TC. OASIS eXtensible Access Control Markup Language (XACML) version 1.0. OASIS Standard, 18 February 2003.
|
CITED BY
|
|
Qiang Wei , Jason Crampton , Konstantin Beznosov , Matei Ripeanu, Authorization recycling in RBAC systems, Proceedings of the 13th ACM symposium on Access control models and technologies, June 11-13, 2008, Estes Park, CO, USA
|
|