Distributed Security Architectures   

Distributed Systems Department
NERSC Division
Lawrence Berkeley National Laboratory

LBL logo


The overall goal of this project is to provide assured, policy-based access control for computer mediated resources such as data archives and instrument systems, that operate in wide area network environments; grid services such as network monitoring, computing resources and data transfer; and potentially fine-grained, object method level access control (such as might be used to implement method access in the WebDAV protocol).

We propose to continue investigating and implementing practical solutions to the security needs of distributed systems based on the emerging PKI standards and implementations. In particular, to provide a modular authorization service that compares a requestor's authenticated X.509 identity certificate with a set of signed policy documents describing the access policy for the requested resource. These policy documents are created and maintained by stakeholders for the resource, independent of the resource server platform.

In addition future work will focus on integrating our authorization mechanism with the core of emerging standards such as the IETF's Proxy certificates with rights restrictions, the XML access and policy languages: SAML and XACML, and the Grid services (WSRF) authorization standards. We plan to expand the Akenti policy implementation in order to integrate it with a grid monitoring system and to provide access control for secure multicast groups.

For more infomation see the 2-page project summary prepared for the March 2004 SciDAC PI's meeting.


People

Staff: Abdelilah Essiari Keith Beattie Mary R. Thompson

Project Information


Quarterly Reports

  Proposal June 2001
4Q01 Jul-Sep, 2001 html     pdf
1Q02 Oct-Dec, 2001 html     pdf
2Q02 Jan-Mar, 2002 html     pdf
3Q02 Apr-Jun, 2002 html     pdf
4Q02 Jul-Sep, 2002 html     pdf
1Q03 Oct-Dec, 2002 html     pdf
2Q03 Jan-Mar, 2003 html     pdf
3Q03 Apr-Jun, 2003 html     pdf
4Q03 July-Sept., 2003 html     pdf
1Q04 Oct-Dec, 2003 html     pdf

Related Projects

Secure and Reliable Group Communication Investigating protocols for secure group memberships and developing a prototype using Akenti access control to determine who may be allowed to join a group.
A Scalable and Secure Peer-to-Peer Information Sharing Tool A project to explore protocols for secure group memberships and secure and reliable group communication.
National Fusion Collaboratory A SciDAC collaboratory which is deploying Akenti security tools.
National Internet Measurment Infrastructure A scabale, dynamic and secure system to measure the globalinternet performance.


Page last modified: Friday, 27-Feb-2004 11:02:34 PST Credits:Distributed Security research and development is funded by the U.S. Dept. of Energy, Office of Science, Office of Advanced Scientific Computing Research, Mathematical, Information, and Computational Sciences Division. Privacy and site security notice to Users

Security Homepage
DSD Homepage
LBNL Homepage