Cargando…

The security model of the ALICE next generation Grid framework

JAliEn (Java-AliEn) is the ALICE next generation Grid framework which will be used for the top-level distributed computing resources management during the LHC Run 3 and onward. While preserving an interface familiar to the ALICE users, its performance and scalability are an order of magnitude better...

Descripción completa

Detalles Bibliográficos
Autores principales: Martinez Pedreira, Miguel, Grigoras, Costin, Yurchenko, Volodymyr, Melnik Storetvedt, Maksim
Lenguaje:eng
Publicado: 2019
Materias:
Acceso en línea:https://dx.doi.org/10.1051/epjconf/201921403042
http://cds.cern.ch/record/2701499
_version_ 1780964599054467072
author Martinez Pedreira, Miguel
Grigoras, Costin
Yurchenko, Volodymyr
Melnik Storetvedt, Maksim
author_facet Martinez Pedreira, Miguel
Grigoras, Costin
Yurchenko, Volodymyr
Melnik Storetvedt, Maksim
author_sort Martinez Pedreira, Miguel
collection CERN
description JAliEn (Java-AliEn) is the ALICE next generation Grid framework which will be used for the top-level distributed computing resources management during the LHC Run 3 and onward. While preserving an interface familiar to the ALICE users, its performance and scalability are an order of magnitude better than the currently used framework. To implement the JAliEn security model, we have developed the so-called Token Certificates – short lived full Grid certificates, generated by central services automatically or on the client’s request. Token Certificates allow fine-grained control over user/client authorization, e.g. filtering out unauthorized requests based on the client’s type: end user, job agent, jobpayload. These and other parameters (like job ID) are encrypted in the token by the issuing service and cannot be altered.The client-side security implementation is further described in aspects of the interaction between user jobs and job agents. User jobs will use JAliEn tokens for authentication and authorization by the central JAliEn services. These tokens are passed from the job agent through a pipe stream, not stored on disk and thus readily available only to the intended job process. The level of isolation of user payloads is further improved by running them in containers. While JAliEn doesn't rely on X.509 proxies, the backward compatibility is kept to assure interoperability with services that require them.
id oai-inspirehep.net-1760940
institution Organización Europea para la Investigación Nuclear
language eng
publishDate 2019
record_format invenio
spelling oai-inspirehep.net-17609402022-08-10T12:24:34Zdoi:10.1051/epjconf/201921403042http://cds.cern.ch/record/2701499engMartinez Pedreira, MiguelGrigoras, CostinYurchenko, VolodymyrMelnik Storetvedt, MaksimThe security model of the ALICE next generation Grid frameworkComputing and ComputersJAliEn (Java-AliEn) is the ALICE next generation Grid framework which will be used for the top-level distributed computing resources management during the LHC Run 3 and onward. While preserving an interface familiar to the ALICE users, its performance and scalability are an order of magnitude better than the currently used framework. To implement the JAliEn security model, we have developed the so-called Token Certificates – short lived full Grid certificates, generated by central services automatically or on the client’s request. Token Certificates allow fine-grained control over user/client authorization, e.g. filtering out unauthorized requests based on the client’s type: end user, job agent, jobpayload. These and other parameters (like job ID) are encrypted in the token by the issuing service and cannot be altered.The client-side security implementation is further described in aspects of the interaction between user jobs and job agents. User jobs will use JAliEn tokens for authentication and authorization by the central JAliEn services. These tokens are passed from the job agent through a pipe stream, not stored on disk and thus readily available only to the intended job process. The level of isolation of user payloads is further improved by running them in containers. While JAliEn doesn't rely on X.509 proxies, the backward compatibility is kept to assure interoperability with services that require them.oai:inspirehep.net:17609402019
spellingShingle Computing and Computers
Martinez Pedreira, Miguel
Grigoras, Costin
Yurchenko, Volodymyr
Melnik Storetvedt, Maksim
The security model of the ALICE next generation Grid framework
title The security model of the ALICE next generation Grid framework
title_full The security model of the ALICE next generation Grid framework
title_fullStr The security model of the ALICE next generation Grid framework
title_full_unstemmed The security model of the ALICE next generation Grid framework
title_short The security model of the ALICE next generation Grid framework
title_sort security model of the alice next generation grid framework
topic Computing and Computers
url https://dx.doi.org/10.1051/epjconf/201921403042
http://cds.cern.ch/record/2701499
work_keys_str_mv AT martinezpedreiramiguel thesecuritymodelofthealicenextgenerationgridframework
AT grigorascostin thesecuritymodelofthealicenextgenerationgridframework
AT yurchenkovolodymyr thesecuritymodelofthealicenextgenerationgridframework
AT melnikstoretvedtmaksim thesecuritymodelofthealicenextgenerationgridframework
AT martinezpedreiramiguel securitymodelofthealicenextgenerationgridframework
AT grigorascostin securitymodelofthealicenextgenerationgridframework
AT yurchenkovolodymyr securitymodelofthealicenextgenerationgridframework
AT melnikstoretvedtmaksim securitymodelofthealicenextgenerationgridframework