EAI Endorsed Transactions on Security and Safety (Aug 2015)
Trust as the Foundation of Resource Exchange in GENI
Abstract
Researchers and educators in computer science and other domains are increasingly turning to distributed test beds that offer access to a variety of resources, including networking, computation, storage, sensing, and actuation. The provisioning of resources from their owners to interested experimenters requires establishing sufficient mutual trust between these parties. Building such trust directly between researchers and resource owners will not scale as the number of experimenters and resource owners grows. The NSF GENI (Global Environment for Network Innovation) project has focused on establishing scalable mechanisms for maintaining such trust based on common approaches for authentication, authorization and accountability. Such trust reflects the actual trust relationships and agreements among humans or real-world organizations. We describe here GENI’s approaches for federated trust based on mutually trusted authorities, and implemented via cryptographically signed credentials and shared policies.
Keywords