Beyond X.509: token-based authentication and authorization for HEP
X.509 certificates and VOMS have proved to be a secure and reliable solution for authentication and authorization on the Grid, but also showed usability issues and required the development of ad-hoc services and libraries to support VO-based authorization schemes in Grid middleware and experiment co...
Main Authors: | , , , |
---|---|
Format: | Article |
Language: | English |
Published: |
EDP Sciences
2019-01-01
|
Series: | EPJ Web of Conferences |
Online Access: | https://www.epj-conferences.org/articles/epjconf/pdf/2019/19/epjconf_chep2018_09002.pdf |
_version_ | 1818613798029754368 |
---|---|
author | Ceccanti Andrea Vianello Enrico Caberletti Marco Giacomini Francesco |
author_facet | Ceccanti Andrea Vianello Enrico Caberletti Marco Giacomini Francesco |
author_sort | Ceccanti Andrea |
collection | DOAJ |
description | X.509 certificates and VOMS have proved to be a secure and reliable solution for authentication and authorization on the Grid, but also showed usability issues and required the development of ad-hoc services and libraries to support VO-based authorization schemes in Grid middleware and experiment computing frameworks. The need to move beyond X.509 certificates is recognized as an important objective in the HEP R&D roadmap for software and computing, to overcome the usability issues of the current AAI and embrace recent advancement in web technologies widely adopted in industry, but also to enable the secure composition of computing and storage resources provisioned across heterogeneous providers in order to meet the computing needs of HL-LHC. A flexible and usable AAI based on modern web technologies is a key enabler of such secure composition and has been a major topic of research of the recently concluded INDIGO-DataCloud project. In this contribution, we present an integrated solution, based on the INDIGO-DataCloud Identity and Access Management service that demonstrates how a next generation, token-based VO-aware AAI can be built in support of HEP computing use cases, while maintaining compatibility with the existing, VOMS-based AAI used by the Grid. |
first_indexed | 2024-12-16T16:07:50Z |
format | Article |
id | doaj.art-adcbea2bf0dc4a9c878e61e74cc7c245 |
institution | Directory Open Access Journal |
issn | 2100-014X |
language | English |
last_indexed | 2024-12-16T16:07:50Z |
publishDate | 2019-01-01 |
publisher | EDP Sciences |
record_format | Article |
series | EPJ Web of Conferences |
spelling | doaj.art-adcbea2bf0dc4a9c878e61e74cc7c2452022-12-21T22:25:18ZengEDP SciencesEPJ Web of Conferences2100-014X2019-01-012140900210.1051/epjconf/201921409002epjconf_chep2018_09002Beyond X.509: token-based authentication and authorization for HEPCeccanti AndreaVianello EnricoCaberletti MarcoGiacomini FrancescoX.509 certificates and VOMS have proved to be a secure and reliable solution for authentication and authorization on the Grid, but also showed usability issues and required the development of ad-hoc services and libraries to support VO-based authorization schemes in Grid middleware and experiment computing frameworks. The need to move beyond X.509 certificates is recognized as an important objective in the HEP R&D roadmap for software and computing, to overcome the usability issues of the current AAI and embrace recent advancement in web technologies widely adopted in industry, but also to enable the secure composition of computing and storage resources provisioned across heterogeneous providers in order to meet the computing needs of HL-LHC. A flexible and usable AAI based on modern web technologies is a key enabler of such secure composition and has been a major topic of research of the recently concluded INDIGO-DataCloud project. In this contribution, we present an integrated solution, based on the INDIGO-DataCloud Identity and Access Management service that demonstrates how a next generation, token-based VO-aware AAI can be built in support of HEP computing use cases, while maintaining compatibility with the existing, VOMS-based AAI used by the Grid.https://www.epj-conferences.org/articles/epjconf/pdf/2019/19/epjconf_chep2018_09002.pdf |
spellingShingle | Ceccanti Andrea Vianello Enrico Caberletti Marco Giacomini Francesco Beyond X.509: token-based authentication and authorization for HEP EPJ Web of Conferences |
title | Beyond X.509: token-based authentication and authorization for HEP |
title_full | Beyond X.509: token-based authentication and authorization for HEP |
title_fullStr | Beyond X.509: token-based authentication and authorization for HEP |
title_full_unstemmed | Beyond X.509: token-based authentication and authorization for HEP |
title_short | Beyond X.509: token-based authentication and authorization for HEP |
title_sort | beyond x 509 token based authentication and authorization for hep |
url | https://www.epj-conferences.org/articles/epjconf/pdf/2019/19/epjconf_chep2018_09002.pdf |
work_keys_str_mv | AT ceccantiandrea beyondx509tokenbasedauthenticationandauthorizationforhep AT vianelloenrico beyondx509tokenbasedauthenticationandauthorizationforhep AT caberlettimarco beyondx509tokenbasedauthenticationandauthorizationforhep AT giacominifrancesco beyondx509tokenbasedauthenticationandauthorizationforhep |