计算机工程与应用 ›› 2007, Vol. 43 ›› Issue (5): 130-132.

• 网络、通信与安全 • 上一篇    下一篇

网格环境下多域间的认证机制研究

戴怡 杨庚   

  1. 南京邮电大学
  • 收稿日期:2006-03-10 修回日期:1900-01-01 出版日期:2007-02-11 发布日期:2007-02-11
  • 通讯作者: 戴怡

Research on Multi-Domain Authentication Mechanism In Grid

  • Received:2006-03-10 Revised:1900-01-01 Online:2007-02-11 Published:2007-02-11

摘要: 随着网格技术的出现与应用,其安全问题也已成为人们研究的重点。网格操作系统Globus 的安全体系架构GSI(Globus Security Infrastructure)为我们提供了单个认证域下安全问题的解决方案,但基于网格的广域特性,如何解决其多个域间的安全认证是目前亟待解决的问题。本文首先简单介绍了GSI 的安全认证机制,然后在此模型基础上引入域间映射的思想,提出了一种用于多个认证域间相互认证的方法,完善了网格环境中的安全认证机制。文章最后详细介绍了该方法的实现过程。

关键词: 网格, 网格安全体系架构, 多域认证, 映射

Abstract: With the appearance and application of Grid technology, the security problem becomes the emphasis of grid research. Globus Security Infrastructure (a security component in Globus) provides us a solution in single authentication domain. Currently, how to resolve the authentication across domains is the most important security problem in the large-scale grid. In this paper, authentication mechanism of GSI is introduced firstly. Then, the multi-domain authentication method based on mapping is proposed. Grid security performance can be improved by this new mechanism. High-level implementation of this new mechanism is shown in detailed at the end of the paper.

Key words: Grid, Globus Security Infrastructure, Multi-Domain authentication, Mapping