A concept for Grid credential lifecycle management and heuristic credential abuse detection

Research output: Chapter in book/report/conference proceedingConference contributionResearchpeer review

Authors

  • Christopher Kunz
  • Jan Wiebelitz
  • Stefan Piger
  • Christian Grimm
View graph of relations

Details

Original languageEnglish
Title of host publication8th International Symposium on Parallel and Distributed Computing, ISPDC 2009
Pages245-248
Number of pages4
Publication statusPublished - 2009
Event8th International Symposium on Parallel and Distributed Computing, ISPDC 2009 - Lisbon, Portugal
Duration: 30 Jun 20094 Jul 2009

Publication series

Name8th International Symposium on Parallel and Distributed Computing, ISPDC 2009

Abstract

In modern Grids, authentication is usually implemented via an X.509 PKI (Public Key Infrastructure). Proxy certificates are employed to facilitate interaction with the Grid, especially for purposes of delegation and single sign-on. We propose modifications to the Grid Security Infrastructure that allow reporting of proxy usage information to a database, giving the end user an opportunity to review by whom and for which purpose his credentials were used. By means of a standardized protocol for certificate revocation, they can then revoke affected proxies and stop abuse.

ASJC Scopus subject areas

Cite this

A concept for Grid credential lifecycle management and heuristic credential abuse detection. / Kunz, Christopher; Wiebelitz, Jan; Piger, Stefan et al.
8th International Symposium on Parallel and Distributed Computing, ISPDC 2009. 2009. p. 245-248 5284347 (8th International Symposium on Parallel and Distributed Computing, ISPDC 2009).

Research output: Chapter in book/report/conference proceedingConference contributionResearchpeer review

Kunz, C, Wiebelitz, J, Piger, S & Grimm, C 2009, A concept for Grid credential lifecycle management and heuristic credential abuse detection. in 8th International Symposium on Parallel and Distributed Computing, ISPDC 2009., 5284347, 8th International Symposium on Parallel and Distributed Computing, ISPDC 2009, pp. 245-248, 8th International Symposium on Parallel and Distributed Computing, ISPDC 2009, Lisbon, Portugal, 30 Jun 2009. https://doi.org/10.1109/ISPDC.2009.28
Kunz, C., Wiebelitz, J., Piger, S., & Grimm, C. (2009). A concept for Grid credential lifecycle management and heuristic credential abuse detection. In 8th International Symposium on Parallel and Distributed Computing, ISPDC 2009 (pp. 245-248). Article 5284347 (8th International Symposium on Parallel and Distributed Computing, ISPDC 2009). https://doi.org/10.1109/ISPDC.2009.28
Kunz C, Wiebelitz J, Piger S, Grimm C. A concept for Grid credential lifecycle management and heuristic credential abuse detection. In 8th International Symposium on Parallel and Distributed Computing, ISPDC 2009. 2009. p. 245-248. 5284347. (8th International Symposium on Parallel and Distributed Computing, ISPDC 2009). doi: 10.1109/ISPDC.2009.28
Kunz, Christopher ; Wiebelitz, Jan ; Piger, Stefan et al. / A concept for Grid credential lifecycle management and heuristic credential abuse detection. 8th International Symposium on Parallel and Distributed Computing, ISPDC 2009. 2009. pp. 245-248 (8th International Symposium on Parallel and Distributed Computing, ISPDC 2009).
Download
@inproceedings{ee1b0dc88db5476ba6ee04deec36e4ee,
title = "A concept for Grid credential lifecycle management and heuristic credential abuse detection",
abstract = "In modern Grids, authentication is usually implemented via an X.509 PKI (Public Key Infrastructure). Proxy certificates are employed to facilitate interaction with the Grid, especially for purposes of delegation and single sign-on. We propose modifications to the Grid Security Infrastructure that allow reporting of proxy usage information to a database, giving the end user an opportunity to review by whom and for which purpose his credentials were used. By means of a standardized protocol for certificate revocation, they can then revoke affected proxies and stop abuse.",
author = "Christopher Kunz and Jan Wiebelitz and Stefan Piger and Christian Grimm",
year = "2009",
doi = "10.1109/ISPDC.2009.28",
language = "English",
isbn = "9780769536804",
series = "8th International Symposium on Parallel and Distributed Computing, ISPDC 2009",
pages = "245--248",
booktitle = "8th International Symposium on Parallel and Distributed Computing, ISPDC 2009",
note = "8th International Symposium on Parallel and Distributed Computing, ISPDC 2009 ; Conference date: 30-06-2009 Through 04-07-2009",

}

Download

TY - GEN

T1 - A concept for Grid credential lifecycle management and heuristic credential abuse detection

AU - Kunz, Christopher

AU - Wiebelitz, Jan

AU - Piger, Stefan

AU - Grimm, Christian

PY - 2009

Y1 - 2009

N2 - In modern Grids, authentication is usually implemented via an X.509 PKI (Public Key Infrastructure). Proxy certificates are employed to facilitate interaction with the Grid, especially for purposes of delegation and single sign-on. We propose modifications to the Grid Security Infrastructure that allow reporting of proxy usage information to a database, giving the end user an opportunity to review by whom and for which purpose his credentials were used. By means of a standardized protocol for certificate revocation, they can then revoke affected proxies and stop abuse.

AB - In modern Grids, authentication is usually implemented via an X.509 PKI (Public Key Infrastructure). Proxy certificates are employed to facilitate interaction with the Grid, especially for purposes of delegation and single sign-on. We propose modifications to the Grid Security Infrastructure that allow reporting of proxy usage information to a database, giving the end user an opportunity to review by whom and for which purpose his credentials were used. By means of a standardized protocol for certificate revocation, they can then revoke affected proxies and stop abuse.

UR - http://www.scopus.com/inward/record.url?scp=74349108990&partnerID=8YFLogxK

U2 - 10.1109/ISPDC.2009.28

DO - 10.1109/ISPDC.2009.28

M3 - Conference contribution

AN - SCOPUS:74349108990

SN - 9780769536804

T3 - 8th International Symposium on Parallel and Distributed Computing, ISPDC 2009

SP - 245

EP - 248

BT - 8th International Symposium on Parallel and Distributed Computing, ISPDC 2009

T2 - 8th International Symposium on Parallel and Distributed Computing, ISPDC 2009

Y2 - 30 June 2009 through 4 July 2009

ER -