Details
Originalsprache | Englisch |
---|---|
Titel des Sammelwerks | Proceedings of the 5th International Conference on Networking and Services, ICNS 2009 |
Seiten | 481-486 |
Seitenumfang | 6 |
Publikationsstatus | Veröffentlicht - 2009 |
Veranstaltung | 5th International Conference on Networking and Services, ICNS 2009 - Valencia, Spanien Dauer: 20 Apr. 2009 → 25 Apr. 2009 |
Publikationsreihe
Name | Proceedings of the 5th International Conference on Networking and Services, ICNS 2009 |
---|
Abstract
Grid computing provides users with transparent access to substantial compute and storage resources. Up to now the main focus lay in the development of Grid infrastructures and the development of services providing access to Grid resources. This leads to a negligence of security aspects, which, for example, leads to the recommendation of open wide port ranges on firewalls protecting the Grid resources. In this paper we present an approach for a dynamic firewall operation facilitated by a strong inline authentication for every TCP connection. The presented approach, which is based on X.509 certificates and public-key encryption uses TCP segments exchanged during the TCP three-way handshake between the client and the server to transport user authentication information. Firewalls on the path use this authentication information to authorize the connection. To distinguish the authentication information in the TCP segments from application data a new TCP option tcpauthn is introduced.
ASJC Scopus Sachgebiete
- Informatik (insg.)
- Computernetzwerke und -kommunikation
- Ingenieurwesen (insg.)
- Elektrotechnik und Elektronik
Zitieren
- Standard
- Harvard
- Apa
- Vancouver
- BibTex
- RIS
Proceedings of the 5th International Conference on Networking and Services, ICNS 2009. 2009. S. 481-486 4976806 (Proceedings of the 5th International Conference on Networking and Services, ICNS 2009).
Publikation: Beitrag in Buch/Bericht/Sammelwerk/Konferenzband › Aufsatz in Konferenzband › Forschung › Peer-Review
}
TY - GEN
T1 - TCP-AuthN
T2 - 5th International Conference on Networking and Services, ICNS 2009
AU - Wiebelitz, Jan
AU - Kunz, Christopher
AU - Piger, Stefan
AU - Grimm, Christian
PY - 2009
Y1 - 2009
N2 - Grid computing provides users with transparent access to substantial compute and storage resources. Up to now the main focus lay in the development of Grid infrastructures and the development of services providing access to Grid resources. This leads to a negligence of security aspects, which, for example, leads to the recommendation of open wide port ranges on firewalls protecting the Grid resources. In this paper we present an approach for a dynamic firewall operation facilitated by a strong inline authentication for every TCP connection. The presented approach, which is based on X.509 certificates and public-key encryption uses TCP segments exchanged during the TCP three-way handshake between the client and the server to transport user authentication information. Firewalls on the path use this authentication information to authorize the connection. To distinguish the authentication information in the TCP segments from application data a new TCP option tcpauthn is introduced.
AB - Grid computing provides users with transparent access to substantial compute and storage resources. Up to now the main focus lay in the development of Grid infrastructures and the development of services providing access to Grid resources. This leads to a negligence of security aspects, which, for example, leads to the recommendation of open wide port ranges on firewalls protecting the Grid resources. In this paper we present an approach for a dynamic firewall operation facilitated by a strong inline authentication for every TCP connection. The presented approach, which is based on X.509 certificates and public-key encryption uses TCP segments exchanged during the TCP three-way handshake between the client and the server to transport user authentication information. Firewalls on the path use this authentication information to authorize the connection. To distinguish the authentication information in the TCP segments from application data a new TCP option tcpauthn is introduced.
UR - http://www.scopus.com/inward/record.url?scp=67650675834&partnerID=8YFLogxK
U2 - 10.1109/ICNS.2009.35
DO - 10.1109/ICNS.2009.35
M3 - Conference contribution
AN - SCOPUS:67650675834
SN - 9780769535869
T3 - Proceedings of the 5th International Conference on Networking and Services, ICNS 2009
SP - 481
EP - 486
BT - Proceedings of the 5th International Conference on Networking and Services, ICNS 2009
Y2 - 20 April 2009 through 25 April 2009
ER -