摘要
网格环境中的授权问题是网格安全的一个研究热点。社区授权服务CAS是网格安全基础设施GSI中的授权机制,鉴于社区授权服务CAS授权机制中提供各种服务的Resource只能粗粒度地授权给CAS服务器,很难细粒度地控制客户权限,本文提出了一种新的授权模型,采用了SPKI电子证书进行授权。与CAS相比,该模型授权更加灵活,通过委托授权增强了系统的可扩展性,而且能够细粒度地控制用户权限。
Resource on authorization problem in grid environment is a hot topic in grid security. The Community Au thorization Service, GAS, is an authorization mechanism of Grid Security Infrastructure, GSI. For resources in CAS authorization mechanism can only provide a course-grained authorization to CAS server, which is difficult to control authorization of client. A new authorization model which adopts SPKI certificate is proposed. Compared with CAS, this authorization model is more flexible, it improves scalability of the authorization system using delegation and can give fine-grained access control to client.
出处
《计算机科学》
CSCD
北大核心
2006年第12期75-77,共3页
Computer Science