Back to Search Start Over

Integrating an AAA-based federation mechanism for OpenStack-The CLASSe view

Authors :
David W. Chadwick
Rafael Marín López
Gabriel López Millán
Alejandro Perez Mendez
Ioram S. Sette
Source :
Concurrency and Computation: Practice and Experience. 29:e4148
Publication Year :
2017
Publisher :
Wiley, 2017.

Abstract

Summary Identity federations enable users, service providers, and identity providers from different organizations to exchange authentication and authorization information in a secure way. In this paper, we present a novel identity federation architecture for cloud services based on the integration of a cloud identity management service with an authentication, authorization, and accounting infrastructure. Specifically, we analyse how this type of authentication, authorization, and accounting–based federation can be smoothly integrated into OpenStack, the leading open source cloud software solution, using the Internet Engineering Task Force (IETF) Application Bridging for Federated Access Beyond web specification for authentication and authorization. We provide details of the implementation undertaken in GEANT's CLASSe project and show its validation in a real testbed.

Details

ISSN :
15320626
Volume :
29
Database :
OpenAIRE
Journal :
Concurrency and Computation: Practice and Experience
Accession number :
edsair.doi.dedup.....d078b433478f36605ed78059c8686456
Full Text :
https://doi.org/10.1002/cpe.4148