2009 Fifth International Conference on Information Assurance and Security 2009
DOI: 10.1109/ias.2009.163
|View full text |Cite
|
Sign up to set email alerts
|

Shibboleth Access for Resources on the National Grid Service (SARoNGS)

Abstract: The National Grid Service (NGS) provides access to compute and data resources for UK academics. Currently users are required to have an X.509 certificate from the UK eScience Certification Authority (CA) or one of its international peers to access the NGS. The CA must satisfy the requirements for internationally agreed assurance levels and some users find the processes of obtaining and managing certificates difficult. Shibboleth, an implementation of federation identity-based authentication, has been widely de… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
2
1

Citation Types

0
8
0

Year Published

2011
2011
2014
2014

Publication Types

Select...
4
2
1

Relationship

0
7

Authors

Journals

citations
Cited by 11 publications
(8 citation statements)
references
References 8 publications
0
8
0
Order By: Relevance
“…SAML assertions are used in UNICORE infrastructures, GridShib [21] allows applying SAML assertions in Globus Toolkit infrastructures, and SAML is supported by various security infrastructures like the open-source software Shibboleth. The latter provides federated and scalable access to DCIs and is widely used (e.g., in the Swiss grid infrastructure [22], in a UK grid infrastructure [23]). Currently, no standard has evolved for cloud infrastructures like Amazon EC2 [24].…”
Section: Security Infrastructuresmentioning
confidence: 99%
“…SAML assertions are used in UNICORE infrastructures, GridShib [21] allows applying SAML assertions in Globus Toolkit infrastructures, and SAML is supported by various security infrastructures like the open-source software Shibboleth. The latter provides federated and scalable access to DCIs and is widely used (e.g., in the Swiss grid infrastructure [22], in a UK grid infrastructure [23]). Currently, no standard has evolved for cloud infrastructures like Amazon EC2 [24].…”
Section: Security Infrastructuresmentioning
confidence: 99%
“…Thus, a significant part of the authorization in SARoNGS takes place within the grid resource provider's service whereas ACD assumes the role of a delegated authorization decision maker for those resources. The SARoNGS model is essentially the VOMS model [6] with Shibboleth presented to the user and the grid X.509 Certificates hidden [13]. The advantages of ACD over SARoNGS are that the VO members' activities can be more tightly controlled (helping VO-based security) and managed (delegating responsibility for usability to the VO and the AHE).…”
Section: Related Workmentioning
confidence: 99%
“…There are certainly precedents for the concept of VOs used in ACD whereby users invoke either their local credentials or a dedicated username and password, such as in the 'community account' system provided by TeraGrid [28] and SARoNGS [13] offered by NGS. For instance, the community account system allows scientists to access grid resources using a dedicated username and password via a Web portal.…”
Section: Related Workmentioning
confidence: 99%
See 1 more Smart Citation
“…ac.uk/ca. Whilst other authentication models have also been explored including federated authentication models of access and usage based upon the Internet2 Shibboleth technology [2] in JISC funded projects such as SHEBANGS [3], ShibGrid [4] and SARONGS [5], the primary and most commonly adopted authentication model by the research community is still based upon X.509 PKI-based authentication where users acquire and maintain their own X.509 certificates and use them to create proxy credentials when submitted jobs or accessing data on resources such as the NGS. We note also that the UK e-Science CA also issues host certificates that can be used for similar purposes.…”
Section: Introductionmentioning
confidence: 99%