Author Login Editor-in-Chief Peer Review Editor Work Office Work

Computer Engineering ›› 2007, Vol. 33 ›› Issue (01): 170-172. doi: 10.3969/j.issn.1000-3428.2007.01.059

• Security Technology • Previous Articles     Next Articles

Grids Policy Deployment and Authentication Mechanism Based on SAML

PEI Yanqin, YANG Shoubao, FANG Xiangming, GUO Leitao   

  1. (Department of Computer Science, University of Science and Technology of China, Hefei 230026)
  • Received:1900-01-01 Revised:1900-01-01 Online:2007-01-05 Published:2007-01-05

基于SAML的网格策略部署和认证机制

裴艳琴,杨寿保,房向明,郭磊涛   

  1. (中国科技大学计算机科学技术系,合肥 230026)

Abstract: A new access control model based on security assertion markup language(SAML) is added to campus grid system. Workflow of access control and the authorization service are discussed. The attribute-based access control policy and the security assertion mapping solution are also adopted in this system. It integrates with the portal, which is in charge of the interface between resource consumers and resource providers. It shows more flexibility and reliability.

Key words: Security assertion markup language(SAML), Assertion, Attribute-based access control(ABAC), Policy, Deployment

摘要: 引进了安全断言标记语言技术,采用基于属性的访问控制策略和安全断言映射方法,讨论了访问控制的流程及相关的授权、认证服务,为校园网格引入了一种访问控制模型,该模型和网格中资源提供者与消费者之间的界面——Portal充分集成,提高了访问的灵活性和可靠性。

关键词: 安全断言标记语言技术, 断言, 基于属性的访问控制, 策略, 部署