Beyond X.509: token-based authentication and authorization for HEP

X.509 certificates and VOMS have proved to be a secure and reliable solution for authentication and authorization on the Grid, but also showed usability issues and required the development of ad-hoc services and libraries to support VO-based authorization schemes in Grid middleware and experiment co...

Full description

Bibliographic Details
Main Authors: Ceccanti Andrea, Vianello Enrico, Caberletti Marco, Giacomini Francesco
Format: Article
Language:English
Published: EDP Sciences 2019-01-01
Series:EPJ Web of Conferences
Online Access:https://www.epj-conferences.org/articles/epjconf/pdf/2019/19/epjconf_chep2018_09002.pdf
_version_ 1818613798029754368
author Ceccanti Andrea
Vianello Enrico
Caberletti Marco
Giacomini Francesco
author_facet Ceccanti Andrea
Vianello Enrico
Caberletti Marco
Giacomini Francesco
author_sort Ceccanti Andrea
collection DOAJ
description X.509 certificates and VOMS have proved to be a secure and reliable solution for authentication and authorization on the Grid, but also showed usability issues and required the development of ad-hoc services and libraries to support VO-based authorization schemes in Grid middleware and experiment computing frameworks. The need to move beyond X.509 certificates is recognized as an important objective in the HEP R&D roadmap for software and computing, to overcome the usability issues of the current AAI and embrace recent advancement in web technologies widely adopted in industry, but also to enable the secure composition of computing and storage resources provisioned across heterogeneous providers in order to meet the computing needs of HL-LHC. A flexible and usable AAI based on modern web technologies is a key enabler of such secure composition and has been a major topic of research of the recently concluded INDIGO-DataCloud project. In this contribution, we present an integrated solution, based on the INDIGO-DataCloud Identity and Access Management service that demonstrates how a next generation, token-based VO-aware AAI can be built in support of HEP computing use cases, while maintaining compatibility with the existing, VOMS-based AAI used by the Grid.
first_indexed 2024-12-16T16:07:50Z
format Article
id doaj.art-adcbea2bf0dc4a9c878e61e74cc7c245
institution Directory Open Access Journal
issn 2100-014X
language English
last_indexed 2024-12-16T16:07:50Z
publishDate 2019-01-01
publisher EDP Sciences
record_format Article
series EPJ Web of Conferences
spelling doaj.art-adcbea2bf0dc4a9c878e61e74cc7c2452022-12-21T22:25:18ZengEDP SciencesEPJ Web of Conferences2100-014X2019-01-012140900210.1051/epjconf/201921409002epjconf_chep2018_09002Beyond X.509: token-based authentication and authorization for HEPCeccanti AndreaVianello EnricoCaberletti MarcoGiacomini FrancescoX.509 certificates and VOMS have proved to be a secure and reliable solution for authentication and authorization on the Grid, but also showed usability issues and required the development of ad-hoc services and libraries to support VO-based authorization schemes in Grid middleware and experiment computing frameworks. The need to move beyond X.509 certificates is recognized as an important objective in the HEP R&D roadmap for software and computing, to overcome the usability issues of the current AAI and embrace recent advancement in web technologies widely adopted in industry, but also to enable the secure composition of computing and storage resources provisioned across heterogeneous providers in order to meet the computing needs of HL-LHC. A flexible and usable AAI based on modern web technologies is a key enabler of such secure composition and has been a major topic of research of the recently concluded INDIGO-DataCloud project. In this contribution, we present an integrated solution, based on the INDIGO-DataCloud Identity and Access Management service that demonstrates how a next generation, token-based VO-aware AAI can be built in support of HEP computing use cases, while maintaining compatibility with the existing, VOMS-based AAI used by the Grid.https://www.epj-conferences.org/articles/epjconf/pdf/2019/19/epjconf_chep2018_09002.pdf
spellingShingle Ceccanti Andrea
Vianello Enrico
Caberletti Marco
Giacomini Francesco
Beyond X.509: token-based authentication and authorization for HEP
EPJ Web of Conferences
title Beyond X.509: token-based authentication and authorization for HEP
title_full Beyond X.509: token-based authentication and authorization for HEP
title_fullStr Beyond X.509: token-based authentication and authorization for HEP
title_full_unstemmed Beyond X.509: token-based authentication and authorization for HEP
title_short Beyond X.509: token-based authentication and authorization for HEP
title_sort beyond x 509 token based authentication and authorization for hep
url https://www.epj-conferences.org/articles/epjconf/pdf/2019/19/epjconf_chep2018_09002.pdf
work_keys_str_mv AT ceccantiandrea beyondx509tokenbasedauthenticationandauthorizationforhep
AT vianelloenrico beyondx509tokenbasedauthenticationandauthorizationforhep
AT caberlettimarco beyondx509tokenbasedauthenticationandauthorizationforhep
AT giacominifrancesco beyondx509tokenbasedauthenticationandauthorizationforhep