Cargando…
The security model of the ALICE next generation Grid framework
JAliEn (Java-AliEn) is the ALICE next generation Grid framework which will be used for the top-level distributed computing resources management during the LHC Run 3 and onward. While preserving an interface familiar to the ALICE users, its performance and scalability are an order of magnitude better...
Autores principales: | , , , |
---|---|
Lenguaje: | eng |
Publicado: |
2019
|
Materias: | |
Acceso en línea: | https://dx.doi.org/10.1051/epjconf/201921403042 http://cds.cern.ch/record/2701499 |
_version_ | 1780964599054467072 |
---|---|
author | Martinez Pedreira, Miguel Grigoras, Costin Yurchenko, Volodymyr Melnik Storetvedt, Maksim |
author_facet | Martinez Pedreira, Miguel Grigoras, Costin Yurchenko, Volodymyr Melnik Storetvedt, Maksim |
author_sort | Martinez Pedreira, Miguel |
collection | CERN |
description | JAliEn (Java-AliEn) is the ALICE next generation Grid framework which will be used for the top-level distributed computing resources management during the LHC Run 3 and onward. While preserving an interface familiar to the ALICE users, its performance and scalability are an order of magnitude better than the currently used framework. To implement the JAliEn security model, we have developed the so-called Token Certificates – short lived full Grid certificates, generated by central services automatically or on the client’s request. Token Certificates allow fine-grained control over user/client authorization, e.g. filtering out unauthorized requests based on the client’s type: end user, job agent, jobpayload. These and other parameters (like job ID) are encrypted in the token by the issuing service and cannot be altered.The client-side security implementation is further described in aspects of the interaction between user jobs and job agents. User jobs will use JAliEn tokens for authentication and authorization by the central JAliEn services. These tokens are passed from the job agent through a pipe stream, not stored on disk and thus readily available only to the intended job process. The level of isolation of user payloads is further improved by running them in containers. While JAliEn doesn't rely on X.509 proxies, the backward compatibility is kept to assure interoperability with services that require them. |
id | oai-inspirehep.net-1760940 |
institution | Organización Europea para la Investigación Nuclear |
language | eng |
publishDate | 2019 |
record_format | invenio |
spelling | oai-inspirehep.net-17609402022-08-10T12:24:34Zdoi:10.1051/epjconf/201921403042http://cds.cern.ch/record/2701499engMartinez Pedreira, MiguelGrigoras, CostinYurchenko, VolodymyrMelnik Storetvedt, MaksimThe security model of the ALICE next generation Grid frameworkComputing and ComputersJAliEn (Java-AliEn) is the ALICE next generation Grid framework which will be used for the top-level distributed computing resources management during the LHC Run 3 and onward. While preserving an interface familiar to the ALICE users, its performance and scalability are an order of magnitude better than the currently used framework. To implement the JAliEn security model, we have developed the so-called Token Certificates – short lived full Grid certificates, generated by central services automatically or on the client’s request. Token Certificates allow fine-grained control over user/client authorization, e.g. filtering out unauthorized requests based on the client’s type: end user, job agent, jobpayload. These and other parameters (like job ID) are encrypted in the token by the issuing service and cannot be altered.The client-side security implementation is further described in aspects of the interaction between user jobs and job agents. User jobs will use JAliEn tokens for authentication and authorization by the central JAliEn services. These tokens are passed from the job agent through a pipe stream, not stored on disk and thus readily available only to the intended job process. The level of isolation of user payloads is further improved by running them in containers. While JAliEn doesn't rely on X.509 proxies, the backward compatibility is kept to assure interoperability with services that require them.oai:inspirehep.net:17609402019 |
spellingShingle | Computing and Computers Martinez Pedreira, Miguel Grigoras, Costin Yurchenko, Volodymyr Melnik Storetvedt, Maksim The security model of the ALICE next generation Grid framework |
title | The security model of the ALICE next generation Grid framework |
title_full | The security model of the ALICE next generation Grid framework |
title_fullStr | The security model of the ALICE next generation Grid framework |
title_full_unstemmed | The security model of the ALICE next generation Grid framework |
title_short | The security model of the ALICE next generation Grid framework |
title_sort | security model of the alice next generation grid framework |
topic | Computing and Computers |
url | https://dx.doi.org/10.1051/epjconf/201921403042 http://cds.cern.ch/record/2701499 |
work_keys_str_mv | AT martinezpedreiramiguel thesecuritymodelofthealicenextgenerationgridframework AT grigorascostin thesecuritymodelofthealicenextgenerationgridframework AT yurchenkovolodymyr thesecuritymodelofthealicenextgenerationgridframework AT melnikstoretvedtmaksim thesecuritymodelofthealicenextgenerationgridframework AT martinezpedreiramiguel securitymodelofthealicenextgenerationgridframework AT grigorascostin securitymodelofthealicenextgenerationgridframework AT yurchenkovolodymyr securitymodelofthealicenextgenerationgridframework AT melnikstoretvedtmaksim securitymodelofthealicenextgenerationgridframework |