Langella Stephen, Hastings Shannon, Oster Scott, Pan Tony, Sharma Ashish, Permar Justin, Ervin David, Cambazoglu B Barla, Kurc Tahsin, Saltz Joel
Department of Biomedical Informatics, The Ohio State University, 3184 Graves Hall, 333 West 10th Ave., Columbus, OH 43210, USA.
J Am Med Inform Assoc. 2008 May-Jun;15(3):363-73. doi: 10.1197/jamia.M2662. Epub 2008 Feb 28.
To develop a security infrastructure to support controlled and secure access to data and analytical resources in a biomedical research Grid environment, while facilitating resource sharing among collaborators.
A Grid security infrastructure, called Grid Authentication and Authorization with Reliably Distributed Services (GAARDS), is developed as a key architecture component of the NCI-funded cancer Biomedical Informatics Grid (caBIG). The GAARDS is designed to support in a distributed environment 1) efficient provisioning and federation of user identities and credentials; 2) group-based access control support with which resource providers can enforce policies based on community accepted groups and local groups; and 3) management of a trust fabric so that policies can be enforced based on required levels of assurance.
GAARDS is implemented as a suite of Grid services and administrative tools. It provides three core services: Dorian for management and federation of user identities, Grid Trust Service for maintaining and provisioning a federated trust fabric within the Grid environment, and Grid Grouper for enforcing authorization policies based on both local and Grid-level groups.
The GAARDS infrastructure is available as a stand-alone system and as a component of the caGrid infrastructure. More information about GAARDS can be accessed at http://www.cagrid.org.
GAARDS provides a comprehensive system to address the security challenges associated with environments in which resources may be located at different sites, requests to access the resources may cross institutional boundaries, and user credentials are created, managed, revoked dynamically in a de-centralized manner.
开发一种安全基础设施,以支持在生物医学研究网格环境中对数据和分析资源进行可控且安全的访问,同时促进协作人员之间的资源共享。
一种名为“具有可靠分布式服务的网格认证与授权”(GAARDS)的网格安全基础设施,被开发为美国国立癌症研究所资助的癌症生物医学信息学网格(caBIG)的关键架构组件。GAARDS旨在在分布式环境中支持:1)用户身份和凭证的高效配置与联合;2)基于组的访问控制支持,资源提供者可据此基于社区认可的组和本地组实施策略;3)信任结构的管理,以便能基于所需的保证级别实施策略。
GAARDS被实现为一套网格服务和管理工具。它提供三项核心服务:用于管理和联合用户身份的多里安(Dorian)、用于在网格环境中维护和配置联合信任结构的网格信任服务,以及用于基于本地和网格级别的组实施授权策略的网格分组器(Grid Grouper)。
GAARDS基础设施既可以作为独立系统使用,也可以作为caGrid基础设施的一个组件。可通过http://www.cagrid.org获取有关GAARDS的更多信息。
GAARDS提供了一个全面的系统,以应对与以下环境相关的安全挑战:资源可能位于不同站点、访问资源的请求可能跨越机构边界,以及用户凭证以分散方式动态创建、管理和撤销。