...
首页> 外文期刊>Operating systems review >Decentralized User Authentication in a Global File System
【24h】

Decentralized User Authentication in a Global File System

机译:全局文件系统中的分散用户身份验证

获取原文
获取原文并翻译 | 示例
           

摘要

The challenge for user authentication in a global file system is allowing people to grant access to specific users and groups in remote administrative domains, without assuming any kind of pre-existing administrative relationship. The traditional approach to user authentication across administrative domains is for users to prove their identities through a chain of certificates. Certificates allow for general forms of delegation, but they often require more infrastructure than is necessary to support a network file system. This paper introduces an approach without certificates. Local authentication servers pre-fetch and cache remote user and group definitions from remote authentication servers. During a file access, an authentication server can establish identities for users based just on local information. This approach is particularly well-suited to file systems, and it provides a simple and intuitive interface that is similar to those found in local access control mechanisms. An implementation of the authentication server and a file server supporting access control lists demonstrate the viability of this design in the context of the Self-certifying File System (SFS). Experiments demonstrate that the authentication server can scale to groups with tens of thousands of members.
机译:全局文件系统中的用户身份验证面临的挑战是,允许人们在不假定任何预先存在的管理关系的情况下,授予对远程管理域中特定用户和组的访问权限。跨管理域进行用户身份验证的传统方法是让用户通过证书链来证明其身份。证书允许采用一般形式的委派,但是证书通常需要比支持网络文件系统所需的基础结构更多的基础结构。本文介绍了一种无需证书的方法。本地身份验证服务器从远程身份验证服务器预取并缓存远程用户和组定义。在文件访问期间,身份验证服务器可以仅基于本地信息为用户建立身份。这种方法特别适合于文件系统,它提供了一个简单直观的界面,类似于在本地访问控制机制中发现的界面。认证服务器和支持访问控制列表的文件服务器的实现在自认证文件系统(SFS)的上下文中证明了该设计的可行性。实验表明,身份验证服务器可以扩展到具有成千上万个成员的组。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号