格子计算涉及在“分布式的虚拟组织”分享和多样的资源的协调使用。异构,动态并且这些环境的多域自然做要求新技术途径的挑战性的安全问题。尽管有在对格子计算适用的存取控制途径的最近的进展,在那里仍然是阻碍控制为格子应用程序建模的有效存取的开发的问题。在那里的 Amongthem 在基于 orcapability 的存取控制策划的身份上是为存取控制,和信赖的基于上下文的模型的缺乏。存取控制策划那决定这些问题被介绍,并且动态地授权的基于角色的存取控制(D-RBAC ) 当模特儿扩大 RBACwith 上下文限制被建议。D-RABC 机制动态地基于从系统和用户的环境收集的一套上下文的信息同意权限到用户,当保留 RBAC 模型的优点时。为 Gridapplication 的 D-RBAC 的实现建筑学也被描述。
Grid computing is concerned with the sharing and coordinated use of diverse resources in distributed "virtual organizations". The heterogeneous, dynamic and multi-domain nature of these environments makes challenging security issues that demand new technical approaches. Despite the recent advances in access control approaches applicable to Grid computing, there remain issues that impede the development of effective access control models for Grid applications. Among them there are the lack of context-based models for access control, and reliance on identity or capability-based access control schemes. An access control scheme that resolve these issues is presented, and a dynamically authorized role-based access control (D-RBAC) model extending the RBAC with context constraints is proposed. The D-RABC mechanisms dynamically grant permissions to users based on a set of contextual information collected from the system and user's environments, while retaining the advantages of RBAC model. The implementation architecture of D-RBAC for the Grid application is also described.