A High Performance UCON and Semantic-Based Authorization Framework for Grid Computing

Authors

  • Maizura Ibrahim Malaysian Nuclear Agency, Malaysia
  • Hamidah Ibrahim Universiti Putra Malaysia, Malaysia
  • Azizol Abdullah Universiti Putra Malaysia, Malaysia
  • Rohaya Latip Universiti Putra Malaysia, Malaysia

DOI:

https://doi.org/10.32890/jict2016.15.1.9

Keywords:

Grid computing, UCON, security policy, ontology, semantic web, grid authorization

Abstract

Authorization infrastructures are an important and integral part of grid computing which facilitate access control functions to protect resources. This paper presents an authorization framework that combines the usage control (UCON) model with semantic web technology. To our knowledge, an authorization framework that combines both the UCON and semantic web technology in one framework has not yet been previously proposed. As the UCON model combines traditional access control, trust management and digital rights management in a grid authorization infrastructure, its adoption enhances the capability of the authorization. However, UCON-based authorization presents a problem in controlling the policy granularity and minimizing the authorization overhead due to complexity in the policies inherited from the UCON model. The growing number of users and resources in the grid makes this problem even worse. We use the semantic web technology to provide a way to automatically manage the rules in the policies, hence keeping the granularity under control. To minimize the authorization overhead, a new mechanism to reduce the number of policy checks is proposed in this paper. Our simulation result shows that the proposed mechanism provides a 63% reduction in rule checking compared to previous methods.

 

References

Alfieri, R., Cecchini, R., Ciaschini, V., & Agnello, L. (2005). From gridmap-file to VOMS: Managing authorization in a grid environment. Future Generation Computer Systems, 21(4), 549–558. doi:10.1016/j. future.2004.10.006

Bumpu, W., Sweitzer, J., Thompson, P., Westerine, A., & Williams, R. (2000). Common information model: Implementing the object model for enterprise management. John Wiley & Sons. http://jict.uum.edu.my

Cakrabarti, A. (2007). Grid computing security. New York, New York, USA: Springer-Verlag Berlin Heidelberg.

Chadwick, D. W., & Otenko, O. (2003). The PERMIS X. 509 role based privilege management infrastructure. Future Generation Computer Systems, 19(2), 277–289.

Chen, H., Perich, F., Finin, T., & Joshi, A. (2004). SOUPA: Standard ontology for ubiquitous and pervasive applications. In Proceedings of the First Annual International Conference on Mobile and Ubiquitous Systems: Networking and Services (MobiQuitous’04) (pp. 258–267).

Cody, E., Sharman, R., Rao, R. H., & Upadhyaya, S. (2008). Security in grid computing: A review and synthesis. Journal Decision Support Systems, 44(44), 749–764. doi:10.1016/j.dss.2007.09.007

Foster, I., Kesselman, C., Tsudik, G., & Tuecke, S. (1998). A security architecture for computational grids. In The 5th ACM Conference on Computer & Communication Security (CCS’98) (pp. 83 –92). San Francisco, CA USA: ACM Press. doi:10.1145/288090.288111

Foster, Ian & Kesselman, C. (Eds.) (2004). The Grid: Blueprint for a new computing infrastructure (2nd ed.). San Francisco, CA USA: Morgan Kaufmann Publishers.

Horrocks, I., Patel-Schneider, P. F., Boley, H., Tabet, S., Grosof, B., & Dean, M. (2004). SWRL: A semantic web rule language combining OWL and RuleML. W3C. Retrieved from http://www.w3.org/Submission/SWRL/

Ibrahim, M., Hamdan, S. N., Ibrahim, H., Abdullah, A., & Latip, R. (2012). Intergrid security policy integration framework based on UCON toward Journal of ICT, 15, No. 1 (June) 2016, pp: 183– federated grid access control. In Proceedings of the International Conference on Informatics and Applications (ICIA2012) (pp. 205–212).

Ibrahim, M., Ibrahim, H., Abdullah, A., & Latip, R. (2014). Enhancing the performance of advanced fine-grained grid authorization system. Journal of Computer Science, 10(12), 2576–2583. doi:10.3844/ jcssp.2014.2576.2583

Kaiiali, M., Wankar, R., Rao, C. R. R., Agarwal, A., & Buyya, R. (2013). Grid authorization graph. Future Generation Computer Systems, 29(8), http://jict.uum.edu.my 1909–1918. doi:10.1016/j.future.2013.04.010

Lorch, M., Cowles, B., Baker, R., Gommans, L., Madsen, P., McNab, A., … Thompson, M. R. (2004). GFD-1.038 Conceptual Grid Authorization Framework and Classification. Global Grid Forum.

Marín Pérez, J. M., Bernabé, J. B., Alcaraz Calero, J. M., Garcia Clemente, F. J., Pérez, G. M., & Gómez Skarmeta, A. F. (2011). Semantic-based authorization architecture for Grid. Future Generation Computer Systems, 27(1), 40–55. doi:10.1016/j.future.2010.07.008

Martinelli, F., & Mori, P. (2010). On usage control for GRID systems. Future Generation Computer Systems, 26(7), 1032–1042. doi:10.1016/j. future.2009.12.005

Pearlman, L., Welch, V., Foster, I., Kesselman, C., & Tuecke, S. (2002). A community authorization service for group collaboration. In Proceedings of Third International Workshop on Policies for Distributed Systems and Networks (POLICY’02) (pp. 50–59). doi:10.1109/ POLICY.2002.1011293

Sandhu, R. (n.d.). The PEI framework for application-centric security. In Proceedings of 5th IEEE International Conference on Collaborative Computing: Networking, Applications and Worksharing (CollaborateCom), Crystal City, Virginia. (pp. 1–5).

Stagni, F. (2009). On usage control for data Grids: Models, architectures, and specifications control. University of Ferrara, Italy.

Thompson, M. R., Essiari, A., & Mudumbai, S. (2003). Certificate-based authorization policy in a PKI environment. ACM Transactions on Information and System Security, 6(4), 566–588. doi:10.1145/950191.950196 Journal of ICT, 15, No. 1 (June) 2016, pp: 183–

Welch, V., Siebenlist, F., Foster, I., Bresnahan, J., Czajkowski, K., Gawor, J., … Tuecke, S. (2003). Security for Grid services. In Proceedings of the 12th IEEE International Symposium on High Performance Distributed Computing, 2003 (pp. 48–57). IEEE Comput. Soc. doi:10.1109/ HPDC.2003.1210015

W3C OWL Working Group. (2012). OWL 2 web ontology language: Document overview. W3C. Retrieved from http://www.w3.org/TR/ owl2-overview/ http://jict.uum.edu.my

Xing, W., Dikaiakos, M. D. M. D., & Sakellariou, R. (2006). A Core Grid Ontology for the Semantic Grid. In Proceedings of the Sixth IEEE International Symposium on Cluster Computing and the Grid (CCGRID’06) (pp. 178–184). Ieee. doi:10.1109/CCGRID.2006.3

Yuhanis, Y., Madi, M., & Hassan, S. (2012). Dynamic replication strategy based on exponential model and dependency relationships in data Grid. Journal of Information and Communication Technology, 11, 193–206.

Zhang, X., Nakae, M., Covington, M. J., & Sandhu, R. (2008). A usage-based authorization framework for collaborative computing systems. ACM Transactions on Information and System Security, 11(1(3), 1–36. doi:10.1145/1133058.1133084

Zhang, X., Parisi-Presicce, F., Sandhu, R., & Park, J. (2005). Formal model and policy specification of usage control. ACM Transactions on Information and System Security, 8(4), 351–387. doi:10.1145/1108906.1108908

Downloads

Published

25-05-2016

How to Cite

Ibrahim, M., Ibrahim, H., Abdullah, A., & Latip, R. (2016). A High Performance UCON and Semantic-Based Authorization Framework for Grid Computing. Journal of Information and Communication Technology, 15(1), 183-202. https://doi.org/10.32890/jict2016.15.1.9

Research impact

Harvested 2026-09-06
2 citations, from OpenAlex — the highest of the sources checked

Counts differ between services because each indexes a different body of literature. None of them is the whole picture.

Identifiers DOI 10.32890/jict2016.15.1.9 OpenAlex W182808631

Most read articles by the same author(s)