WLCG Authorisation from X.509 to Tokens

07/07/2020
by   Brian Bockelman, et al.
0

The WLCG Authorisation Working Group was formed in July 2017 with the objective to understand and meet the needs of a future-looking Authentication and Authorisation Infrastructure (AAI) for WLCG experiments. Much has changed since the early 2000s when X.509 certificates presented the most suitable choice for authorisation within the grid; progress in token based authorisation and identity federation has provided an interesting alternative with notable advantages in usability and compatibility with external (commercial) partners. The need for interoperability in this new model is paramount as infrastructures and research communities become increasingly interdependent. Over the past two years, the working group has made significant steps towards identifying a system to meet the technical needs highlighted by the community during staged requirements gathering activities. Enhancement work has been possible thanks to externally funded projects, allowing existing AAI solutions to be adapted to our needs. A cornerstone of the infrastructure is the reliance on a common token schema in line with evolving standards and best practices, allowing for maximum compatibility and easy cooperation with peer infrastructures and services. We present the work of the group and an analysis of the anticipated changes in authorisation model by moving from X.509 to token based authorisation. A concrete example of token integration in Rucio is presented.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
07/29/2018

Trust Based Identity Sharing For Token Grants

Authentication and authorization are two key elements of a software appl...
research
08/08/2019

Bootstrapping a stable computation token

We outline a token model for Truebit, a retrofitting, blockchain enhance...
research
10/10/2018

True2F: Backdoor-resistant authentication tokens

We present True2F, a system for second-factor authentication that provid...
research
08/16/2019

Attending to Future Tokens For Bidirectional Sequence Generation

Neural sequence generation is typically performed token-by-token and lef...
research
09/03/2019

The Bottom-up Evolution of Representations in the Transformer: A Study with Machine Translation and Language Modeling Objectives

We seek to understand how the representations of individual tokens and t...
research
11/25/2021

LET-Decoder: A WFST-based Lazy-evaluation Token-group Decoder with Exact Lattice Generation

We propose a novel lazy-evaluation token-group decoding algorithm with o...
research
08/02/2022

Evaluating Inter-Operator Cooperation Scenarios to Save Radio Access Network Energy

Reducing energy consumption is crucial to reduce the human debt's with r...

Please sign up or login with your details

Forgot password? Click here to reset