Скачать презентацию PGI — Information Security in the UNICORE Grid Скачать презентацию PGI — Information Security in the UNICORE Grid

7ab0c3f688d78a8a75f85294873cfd1e.ppt

  • Количество слайдов: 11

PGI - Information Security in the UNICORE Grid Middleware Morris Riedel (FZJ – Jülich PGI - Information Security in the UNICORE Grid Middleware Morris Riedel (FZJ – Jülich Supercomputing Centre & DEISA) PGI Co-Chair …and many others… © 2008 Open Grid Forum

OGF IPR Policies Apply • • • “I acknowledge that participation in this meeting OGF IPR Policies Apply • • • “I acknowledge that participation in this meeting is subject to the OGF Intellectual Property Policy. ” Intellectual Property Notices Note Well: All statements related to the activities of the OGF and addressed to the OGF are subject to all provisions of Appendix B of GFD-C. 1, which grants to the OGF and its participants certain licenses and rights in such statements. Such statements include verbal statements in OGF meetings, as well as written and electronic communications made at any time or place, which are addressed to: • • • the OGF plenary session, any OGF working group or portion thereof, the OGF Board of Directors, the GFSG, or any member thereof on behalf of the OGF, the ADCOM, or any member thereof on behalf of the ADCOM, any OGF mailing list, including any group list, or any other list functioning under OGF auspices, the OGF Editor or the document authoring and review process Statements made outside of a OGF meeting, mailing list or other function, that are clearly not intended to be input to an OGF activity, group or function, are not subject to these provisions. Excerpt from Appendix B of GFD-C. 1: ”Where the OGF knows of rights, or claimed rights, the OGF secretariat shall attempt to obtain from the claimant of such rights, a written assurance that upon approval by the GFSG of the relevant OGF document(s), any party will be able to obtain the right to implement, use and distribute the technology or works when implementing, using or distributing technology based upon the specification(s) under openly specified, reasonable, nondiscriminatory terms. The working group or research group proposing the use of the technology with respect to which the proprietary rights are claimed may assist the OGF secretariat in this effort. The results of this procedure shall not affect advancement of document, except that the GFSG may defer approval where a delay may facilitate the obtaining of such assurances. The results will, however, be recorded by the OGF Secretariat, and made available. The GFSG may also direct that a summary of the results be included in any GFD published containing the specification. ” OGF Intellectual Property Policies are adapted from the IETF Intellectual Property Policies that support the Internet Standards Process. © 2008 Open Grid Forum 2

Outline © 2008 Open Grid Forum 3 Outline © 2008 Open Grid Forum 3

Outline • UNICORE Security 101 • Follow-up from OGF 23 (with regard to delegation…) Outline • UNICORE Security 101 • Follow-up from OGF 23 (with regard to delegation…) © 2008 Open Grid Forum 4

UNICORE Security 101 © 2008 Open Grid Forum 5 UNICORE Security 101 © 2008 Open Grid Forum 5

UNICORE Security 101 • Certificates (Normal Setup) TLS • Full X. 509 Certificates • UNICORE Security 101 • Certificates (Normal Setup) TLS • Full X. 509 Certificates • Certificates (Interoperability package) TLS • X. 509 Proxy Certificates should be used if - and only if – used in conjunction with… • Attribute-based Authorization ( not pure Identity-based Auth. Z) • Restricted impersonification vs. full impersonification problem • Transport of Attributes for attribute-based Auth. Z • SAML Assertions (i. e. roles, VO, etc. ) in SOAP Header • (Attributes in proxy extensions may be implemented, but not recommended since SAML is the new more flexible technology) • Authorization Decisions • UNICORE User Database (simple yes / no decisions) based on full X. 509/X. 509 DN • XACML-based policy descriptions (used to enable more finegrained attribute-based authorization) © 2008 Open Grid Forum 6

Follow-up from OGF 23 © 2008 Open Grid Forum 7 Follow-up from OGF 23 © 2008 Open Grid Forum 7

Follow-up from OGF 23 (1) • Big picture in (many) GIN production Grids & Follow-up from OGF 23 (1) • Big picture in (many) GIN production Grids & efforts OASIS WS-Security Extension SOAP Message IETF TLS SOAP Header SOAP Body OGF BES OGF JSDL + Ext. Proxy VO Support Extensions for attributes and restrictions attributes OGSA-Auth. Z Delegation of Rights restictions/constraints © 2008 Open Grid Forum 8 SAML Assertion Attribute Statement element Contraints element

Follow-up from OGF 23 (2) • OGF 23: Co-Located with the BEin. GRID Industry Follow-up from OGF 23 (2) • OGF 23: Co-Located with the BEin. GRID Industry Days • GIN Session Security Profile • Interoperability/interoperation often leads to delegation • http: //www. ogf. org/gf/event_schedule/index. php? id=1213 • Taking requirements from industry/commercial providers into account, most urgent topics are security (i. e. delegation) • Why? • Sustainability plans of GIN infrastructures are mostly related to commercial providers or industry players • Security Challenges • Most Grid and e-science infrastructures operate on a security paradigm of “full impersonification delegation of rights” • “If I delegate someone to buy me a toaster he is actually allowed to buy me a car – there are no restrictions what exactly to do” © 2008 Open Grid Forum 9

Follow-up from OGF 23 (3) • Outcomes of this session…we understood the problem • Follow-up from OGF 23 (3) • Outcomes of this session…we understood the problem • Proxies are not bad standard • But the way proxies are used on the infrastructures is “bad” • Restrictions within proxies can be added into proxy extensions Proxy extension with restrictions • SAML assertions are not bad standard • SAML assertions have same drawback when no constraints are provided • Restrictions within SAML assertions can be coded in SAML assertions contraints parts © 2008 Open Grid Forum 10 SAML Assertion contraints element

Follow-up from OGF 23 (4) • Solution is restriction/constrained delegation of rights • Works Follow-up from OGF 23 (4) • Solution is restriction/constrained delegation of rights • Works for both technologies, proxies and SAML assertions • Challenge: So far no world-wide agreement of how this constraints/restrictions look like – only minor efforts • Time to think about it: Several software providers start implementing their own solutions • ARC develops an own solutions as proxy solutions • UNICORE develops SOAPActions+Attributes as XACML policies within SAML assertions contraint elements • g. Lite has several efforts in this context • It’s time for an OGF standard otherwise we have several different solutions • Idea: Working together with security experts of OGF • How exactly can we define this restrictions/contraints © 2008 Open Grid Forum 11