Audited credential delegation - a user-centric identity management solution for computational grid environments

Haidar, A. N. and Zasada, Stefan J. and Coveney, P. V. and Abdallah, Ali E. and Beckles, B. (2010) Audited credential delegation - a user-centric identity management solution for computational grid environments. In: Information Assurance and Security (IAS), 2010 Sixth International Conference. IEEE Conference Publications, pp. 222-227. ISBN 978-1-4244-7409-7

Full text not available from this repository. (Request a copy)


One major problem faced by end-users and administrators of computational grid environments arise in connection with the usability of the security mechanisms usually deployed in these environments, in particular identity management. Many of the existing computational grid environments use Public Key Infrastructure (PKI) and X.509 digital certificates as a corner stone for their security architectures. However, security solutions based on PKI have to be usable to be effective otherwise they will not provide the intended protection. This paper presents the Audited Credential Delegation (ACD), a user-centric security identity management solution that accommodates users and resource providers security requirements including authentication, authorisation and auditing security goals from the design level. The proposed architecture removes any association between users and digital certificates, which is the source of the grid usability problem, while addressing resource providers concerns with regards to accountability. A prototype of this architecture has been implemented in Java and Web Services technologies using the recommendations of the Open Web Application Security consortium (OWASP) for developing secure software. It is currently being tested on TeraGrid, NGS and DEISA grid infrastructures and a detailed usability study is underway.

Item Type: Book Section
Uncontrolled Keywords: Logic gates, Authentication, Authorization, Servers, Usability, Middleware ,National Grid Service, audited credential delegation, computational grid environments, security mechanisms, public key infrastructure, X.509 digital certificates, ACD, user-centric security identity management, resource provider security, authorisation, authentication, grid usability problem, Java, Web services, open Web application security consortium, OWASP, TeraGrid, NGS, DEISA grid infrastructures
Subjects: CAH11 - computing > CAH11-01 - computing > CAH11-01-01 - computer science
Divisions: Faculty of Computing, Engineering and the Built Environment
Faculty of Computing, Engineering and the Built Environment > School of Computing and Digital Technology
Depositing User: Oana-Andreea Dumitrascu
Date Deposited: 06 Apr 2017 14:35
Last Modified: 22 Mar 2023 12:02

Actions (login required)

View Item View Item


In this section...