论文标题
WLCG授权从X.509到令牌
WLCG Authorisation from X.509 to Tokens
论文作者
论文摘要
WLCG授权工作组成立于2017年7月,目的是了解并满足WLCG实验的未来外观身份验证和授权基础设施(AAI)的需求。自2000年代初以来,X.509证书提出了最合适的网格授权选择;基于令牌的授权和身份联合会的进展为与外部(商业)合作伙伴的可用性和兼容性方面的优势提供了一个有趣的替代方案。在这种新模型中,对互操作性的需求至关重要,因为基础架构和研究社区变得越来越相互依存。在过去的两年中,工作组已采取了重大步骤,以确定一个系统,以满足社区在分阶段要求收集活动中突出的技术需求。由于外部资助的项目,增强工作是可能的,从而使现有的AAI解决方案适应了我们的需求。基础设施的基石是根据不断发展的标准和最佳实践对共同的令牌模式的依赖,从而可以最大程度地兼容并易于与同行基础架构和服务合作。我们通过从X.509到基于代币的授权来介绍该小组的工作以及对授权模型预期变化的分析。提出了Rucio中令牌整合的具体示例。
The WLCG Authorisation Working Group was formed in July 2017 with the objective to understand and meet the needs of a future-looking Authentication and Authorisation Infrastructure (AAI) for WLCG experiments. Much has changed since the early 2000s when X.509 certificates presented the most suitable choice for authorisation within the grid; progress in token based authorisation and identity federation has provided an interesting alternative with notable advantages in usability and compatibility with external (commercial) partners. The need for interoperability in this new model is paramount as infrastructures and research communities become increasingly interdependent. Over the past two years, the working group has made significant steps towards identifying a system to meet the technical needs highlighted by the community during staged requirements gathering activities. Enhancement work has been possible thanks to externally funded projects, allowing existing AAI solutions to be adapted to our needs. A cornerstone of the infrastructure is the reliance on a common token schema in line with evolving standards and best practices, allowing for maximum compatibility and easy cooperation with peer infrastructures and services. We present the work of the group and an analysis of the anticipated changes in authorisation model by moving from X.509 to token based authorisation. A concrete example of token integration in Rucio is presented.