Presentation is loading. Please wait.

Presentation is loading. Please wait.

Access Control for Dynamic Virtual Organisations Duncan Russell, Peter Dew & Karim Djemame University of Leeds.

Similar presentations


Presentation on theme: "Access Control for Dynamic Virtual Organisations Duncan Russell, Peter Dew & Karim Djemame University of Leeds."— Presentation transcript:

1 Access Control for Dynamic Virtual Organisations Duncan Russell, Peter Dew & Karim Djemame University of Leeds

2 Access Control for Dynamic Virtual Organisations DAME Context DAME Virtual Organisation Demonstration Portal & Workflow Management Virtual Organisation Issues

3 DAME (Distributed Aircraft Maintenance Environment) EPSRC Funded, 3 years. Ends Dec 2004 4 Universities: – University of Leeds - School of Computing and School of Mechanical Engineering – University of Oxford - Dept of Engineering Science – University of Sheffield - Dept of Automatic Control and Systems Engineering – University of York - Dept of Computer Science Industrial Partners: – Rolls-Royce – Data Systems and Solutions

4 DAME System Aircraft Engine Diagnostics – Expert system & decision support – Predictive maintenance scheduling Distributed Resources – Data sources e.g. aircraft engines – Signal & Case data processing services Distributed Users – Maintenance staff at airport (for Airline) – Engine experts at Rolls Royce and DS&S On-demand Requirements – Diagnostics response within turn-around time

5 DAME Example Business process for diagnosing engine data Three roles: – Maintenance Engineer – Maintenance Analyst – Domain Expert Forms problem solving team

6 DAME Virtual Organisation

7

8 DAME VO Properties Role based Task oriented – Linked by diagnosis problem to solve Evolves over time – Dynamic membership – Multiples of role instances High availability of services – Dynamic selection of compute resource Access to restricted services & data

9 DAME Architecture VO Templates VO Instances Controlled access to workflow instances Presentation Tier Business Tier Service Tier Browser Portal Role database Case database Workflow Manager Workflow Credential Feature Visualization Feature Detection CBR Workflow Advisor Engine Data Store Broker White Rose Grid Pattern Matching Resource Tier Engine Model Jump

10 DAME Portal

11 DAME Portal Tools

12 DAME VO Issues Multiple portals, i.e. one per company Multiple workflow engines Multiple organisations defining rights for their: – Users by role – Workflow (task) by role – Services by role privileges – Data by ownership – Resources by usage Service logging

13 DAME VO Requirements Definition of flexible VO template policy – Administration rights to policy Implement flexible policy control mechanisms – VO members permitted to modify VO policy – Services read/modify VO policy by proxy Distribute VO access control to services and resources Back to Architecture

14 DAME Access Control Issues Service interface implementation: – Control of service access (using VO policy) – Modifying VO policy (using VO policy) Implementation issues: – Define template policy and translate to dynamic policy – Single entity or separate policy components – Synchronising simultaneous policy changes Current implementation: – VO templates describe static teams – Access control in presentation and business tiers only Single grid certificate in DAME collaborative workflows

15 Questions? Access Control for Dynamic Virtual Organisations Duncan Russell, Peter Dew & Karim Djemame University of Leeds duncanr@comp.leeds.ac.uk This research is funded by the Engineering and Physical Science Research Council, e–Science Programme, Contract No. GR/R67668/01


Download ppt "Access Control for Dynamic Virtual Organisations Duncan Russell, Peter Dew & Karim Djemame University of Leeds."

Similar presentations


Ads by Google