Dynamic Authorization Delegation in Grid Computing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current grid computing solutions face challenges in providing flexible, on-demand authorization and authentication for entities accessing grid nodes, especially in real-time collaborative environments, as existing methods are not dynamic and require contact with a superauthority for certification.
Innovation Solution
A method for dynamic on-demand delegation of control in a grid computing environment, where a moderator with special access grants authority, modifies the access control list, and issues unique authorization certificates to other entities, allowing control without needing to contact the superauthority for certification, enabling scalable and dynamic access management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a separate asynchronous process like grid-map files is used for authorization, then authorization can be handled at a different level, but the system becomes static and difficult to tie with authentication in on-demand environments
Solution Approach 1:
The patent merges authentication and authorization into a single integrated process. The authentication certificate contains both authentication information and authorization information, eliminating the need for separate asynchronous authorization processes. This integration allows the system to maintain adaptability while reducing the complexity of managing separate authorization mechanisms.
Solution Approach 2:
The patent implements dynamic authorization by allowing the authorization information in the certificate to be updated and revised. The system can dynamically adjust access rights and permissions based on current needs, transforming the static grid-map file approach into a dynamic, on-demand authorization mechanism that adapts to changing requirements.
2Reliability
If every end entity owns a X509 certificate and uses common PKI mechanisms, then authentication can be performed through trusted authority, but authorization becomes separate and requires additional processes
Solution Approach 1:
The patent combines authentication and authorization functions into a single certificate-based mechanism. The authentication certificate issued by the trusted authority contains both authentication credentials and authorization information, eliminating the need for separate authorization operations and simplifying the overall process while maintaining security.
Solution Approach 2:
The authentication certificate serves multiple functions: it provides authentication verification and simultaneously contains authorization information. This multi-functional certificate eliminates the need for separate authorization processes, making the system easier to operate while maintaining the security benefits of PKI mechanisms.
3Adaptability or versatility
If grid computing involves running applications in diverse environments, then resource sharing and virtualization opportunities increase, but security issues and interoperability challenges arise
Solution Approach 1:
The patent creates a universal security mechanism where a single integrated certificate-based system handles both authentication and authorization across diverse grid environments. This universal approach simplifies the security infrastructure by providing a common mechanism that works across different environments, reducing the complexity of managing multiple security systems while enabling broad resource sharing.
Data Source
AI summary
The method of the invention provides for dynamic on-demand delegation of control and access in a grid computing environment comprising granting authority of a grid node to a first moderator by a superauthority; admitting the first moderator to the grid node; modifying the access control list of the grid node by the first moderator; inviting other entities listed on the access control list to access the grid node; and issuing a unique authorization certificate to each of the other entities, wherein the first moderator controls the inviting of the other entities without contact with or accessing to the superauthority for certification.


