A Mediated Definite Delegation Model allowing for Certified Grid Job Submission
Steffen Schreiner, Latchezar Betev, Costin Grigoras, Maarten Litmaath

TL;DR
This paper introduces a mediated definite delegation model for Grid computing that enhances security, accountability, and traceability in multi-user job submissions, addressing limitations of existing delegation methods.
Contribution
It proposes a novel mediated delegation model enabling context-sensitive privilege assignment with improved security and traceability, and presents a prototype implementation for certified Grid jobs.
Findings
Enhanced security against identity theft and forgery
Improved accountability and traceability in job submissions
Prototype demonstrates practical feasibility and security benefits
Abstract
Grid computing infrastructures need to provide traceability and accounting of their users" activity and protection against misuse and privilege escalation. A central aspect of multi-user Grid job environments is the necessary delegation of privileges in the course of a job submission. With respect to these generic requirements this document describes an improved handling of multi-user Grid jobs in the ALICE ("A Large Ion Collider Experiment") Grid Services. A security analysis of the ALICE Grid job model is presented with derived security objectives, followed by a discussion of existing approaches of unrestricted delegation based on X.509 proxy certificates and the Grid middleware gLExec. Unrestricted delegation has severe security consequences and limitations, most importantly allowing for identity theft and forgery of delegated assignments. These limitations are discussed and…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsDistributed and Parallel Computing Systems · Advanced Data Storage Technologies · Scientific Computing and Data Management
