管理网格中动态用户社区
摘要
网格计算的一个基本概念是创建虚拟组织 (VO):一组资源消费者和提供者联合起来解决一个常见问题。典型的虚拟组织示例包括围绕大型强子对碰撞 (LHC) 实验形成的合作。迄今为止,网格计算已在相对较小的规模上应用,将数十个用户链接到十几个资源上,VO 的管理是 largely 手动的操作。随着大型合作的发展,将超过 10000 个用户与 1000 个 sites 跨越 150 个国家链接,需要一个全面的自动化管理系统。它应该足够简单,以免阻止用户,同时确保本地 site 自主性。由欧洲数据网格 (EU DataGrid) 和 DataTAG 项目开发的 VO Management Service (VOMS) 是一个受安全保护的系统,用于管理虚拟组织中用户和资源的授权。它将现有的 Grid Security Infrastructure 架构扩展引入嵌入式 VO 成员资格断言,这些断言可由所有 VO 成员和资源提供方独立验证。在欧洲数据网格项目中,针对作业提交、文件和数据库访问的网格服务正在配备细粒度授权系统,这些系统考虑 VO 成员资格。这些系统还使资源拥有者能够确保 site 安全并执行本地访问策略。本文将描述欧洲数据网格安全架构、VO 成员服务以及本地 site 强制机制 Local Centre Authorization Service (LCAS)、Local Credential Mapping Service (LCMAPS) 以及 Java Trust and Authorization Manager。
引用
@article{arxiv.cs/0306004,
title = {Managing Dynamic User Communities in a Grid of Autonomous Resources},
author = {R. Alfieri and R. Cecchini and V. Ciaschini and L. dell'Agnello and A. Gianoli and F. Spataro and F. Bonnassieux and P. Broadfoot and G. Lowe and L. Cornwall and J. Jensen and D. Kelsey and A. Frohner and D. L. Groep and W. Som de Cerff and M. Steenbakkers and G. Venekamp and D. Kouril and A. McNab and O. Mulmo and M. Silander and J. Hahkala and K. Lhorentey},
journal= {arXiv preprint arXiv:cs/0306004},
year = {2010}
}
备注
Talk from the 2003 Computing in High Energy and Nuclear Physics (CHEP03), La Jolla, Ca, USA, March 2003, 7 pages, LaTeX, 5 eps figures. PSN TUBT005