250 likes | 343 Views
Comparison of different security infrastructure implementations. Olle Mulmo, KTH. Before we take the next step forward…. Stop and take a breath Look at what people have done so far Try to compare Be ignorant to technology details. State of the world. 3 rd party. RA. Org. Org. Org. gw.
E N D
Comparison of different security infrastructure implementations Olle Mulmo, KTH
Before wetake the next step forward… • Stop and take a breath • Look at what people have done so far • Try to compare • Be ignorant to technology details
State of the world 3rd party RA Org Org Org gw gw gw
Analyzed Characteristics • Underlying Assumptions • Usage scenario • Lifetime & scale of operations • Setup • Trust anchors • Commitments
Analyzed Characteristics (cont) • Registration • Bootstrap for a resource provider • Bootstrap for a user • Security concerns • Local control • Privacy • Audit • Acceptance
Analyzed Characteristics (cont) • Dynamics • Setup & Registration “lightweight”? • Adding/removing a user • Adding/removing a member org • Handling Lusers and Loosers
Scenarios • Unique ID & VO affiliation • Federation / gateway model • VO control + sandboxing
trust VO msg Unique ID & VO affiliation (#1) 3rd party RA Org Org Org gw gw gw VO VO
trust VO msg Unique ID & VO affiliation (#2) 3rd party RA Org Org Org gw gw gw VO VO
trust VO msg Unique ID & VO affiliation (#3) 3rd party RA Org Org Org gw gw gw VO VO
Unique ID & VO affiliation • Different trust sources for AuthN and AuthZ • Local control • Allows for widely different levels of operational trust
trust ?? VO msg Federation / gateway model (#1) 3rd party RA Org Org Org gw gw gw
trust VO msg Federation / gateway model (#2) 3rd party RA Org Org Org gw gw gw
Federation / gateway model • Organizational based trust • Assumptions on infrastructure • Higher demands on operational trust
trust VO msg VO control + sandboxing 3rd party RA Org Org Org VO
trust VO msg VO control + sandboxing 3rd party RA Org Org Org VO
VO control + sandboxing • VO runs the show • Prepackaged, domain specific • Little or no local control • Trust by reputation
Comparisons • I have tried my best to be impartial and objective • “Is this hard to do or not?” • Over-simplified conclusions • “difficult” vs “easy”
Comparisons • Lack of support for short-lived lifetimes & small-scale operations
Conclusions • No single model strikes out as #1 • Lack of support for short-lived, small-scale, light-weight operations
Topics for discussion • What model is most likely a best fit fora) academia, b) industry? • Are there alternatives? • What characteristics should we focus on in the near-term?