透過您的圖書館登入
IP:3.142.197.212
  • 期刊

A Novel Certificate-based Authentication Hybrid Broker Model Using Multi-party Key Agreement in Data Grids

運用於資料網格中多方密鑰協議之憑證認證及授權之混合式資源代理模型

摘要


資料協同配置(Co-allocation)架構,實現了可透過網路同時傳輸從多個站台平行下載檔案資源,以達到共享的目的,此一新開發的技術,利用多個副本透過建立多個連接並聯以進行檔案資料下載。從而提高了單一伺服器的傳輸效率,進而緩解網路擁塞問題。在我們之前提出以協同配置(Co-allocation)和提供資源代理功能為基礎的增強式動態預測調整機制模型(Anticipative Recursively Adjusting Mechanism plus:ARAM+)中,已包含服務分配,資源發現,作業調度,作業監控和資料存取等機制;然而,此一架構所面臨最大的挑戰,在於使用傳統的公開金鑰基礎結構(PKI)作為網格群組間成員之認證機制,換句話說,它只能做到網格間(inter-grid)的通訊安全,對於網格內(intra-grid)的內部攻擊(internal attacks)則無法抵擋。為了克服以上問題,我們提出一個新的透過多方密鑰協議,以憑證授權和認證為基礎之混合式資源代理模型的協同分配傳輸網格架構。我們設計了一個所謂的資源中介代理,稱為“Resource broker ”,當每次動態資源群組形成時便自動產生,並負責群組成員監督及工作分配以分擔資源中介(Service broker)的工作量。此外,我們還提出了“多方密鑰協議協定”提供一個安全的內部網路資源中介的溝通。實驗結果證明,我們的方法提供了更可靠的性能與各種負載服務,以及克服了單一資源中介故障與各種可能的攻擊。

並列摘要


Several recent studies have demonstrated that co-allocation techniques can improve network bandwidth and network transfer times by concurrently utilizing as many data grid replicas as possible. In our previous work, the anticipative recursively adjusting mechanism plus (ARAM+) model, It was based on co-allocation strategies and decentralized service broker, which provide comprehensive capabilities of data access for users' application. Although most of current grid systems use traditional PKI to authenticate grid members as also to secure resource allocation to them, it only provides the security of inter-grid communication. However, the challenges of co-allocation architectures continue to lie in the secured intra-grid communication against internal attacks. It is presented in this paper a new certificate-based authentication hybrid broker model by using multi-party key agreement for redundant parallel file transfer in ARAM+ model, where we designed and implemented service broker agent called ”resource broker”, that takes over the works of job monitoring of the service broker for each dynamic resource-group. Moreover, the multi-party key agreement protocol is used to provide security services for resource-group communications. Experimental results show that our approach achieves dependable performance with various loads of services, broker failures and possible attacks.

參考文獻


Allcock B, Bester J, Bresnahan J, Chervenak A, Foster I, Kesselman C. et al. Data management and transfer in high-performance computational grid environments. Parallel Computing 2002;28:749–771.
Czajkowski K, Foster I, Kesselman C. Resource co-allocation in computational grids. In: Proceeding of the 8th IEEE international symposium on high performance distributed computing (HPDC-8 ’99), August 1999.
Czajkowski K, Fitzgerald S, Foster I, Kesselman C. Grid information services for distributed resource sharing, In: Proc.10th IEEE international symposium on high-performance distributed computing (HPDC-10 ’01), August 2001.
Foster I, Kesselman C, Tuecke S. The anatomy of the grid: enabling scalable virtual organizations. In: Proceedings of the first IEEE/ACM international symposium; 2001. p. 200–22.
Hoschek W, Jaen-Martinez J, Samar A, Stockinger H, Stockinger K. DatA manage- ment in an international datA grid project. In: Proceedings of The first IEEE/ ACM international workshop on grid computing, Bangalore, India; 2000.

延伸閱讀