VLDB 2026 Research / reviewers in the wild / expert
Yuri Demchenko
dblp:95/2010
· DBLP profile ↗
53ranked-venue papers
28as first author
6since 2021 · last 2024
0000-0001-7474-9506ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 4 first-authorApplied, interdisciplinary, general and emerging computing · 10 · 8 first-author · 5 since 2021Systems, architecture and hardware · 5 · 3 first-authorSoftware engineering, systems software and programming languages · 5 · 4 first-authorHuman-computer interaction and ubiquitous computing · 4 · 3 first-author · 4 since 2021Computer networks · 2 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | The Importance of System Engineering Competences and Knowledge for Big Data Science and Research Infrastructure ProjectsabstractBig Data Science projects are an essential part of the modern data driven science and require extensive use of digital technologies and are typically built using large scale Research Infrastructures (RI) that combine computational, storage and data management facilities to support data collection, processing and scientific workflow management. The success of realising Big Data Science projects and effective use of Big Data Infrastructures (BDI) will depend on adopting modern technologies and well-defined architectures that support the sustainability and long term evolution of technical solutions. Building and operating modern BDIs and data driven scientific instruments require a wide spectrum of competences and knowledge related to modern technologies, system and software engineering, including also Big Data infrastructure engineering. The paper provides background information on large European RI and e-Infrastructure projects and analyses different cases/scenarios where the availability of necessary system and software engineering competences and knowledge are critical for the success of RI. The paper summarises the Sustainable Architecture Design Principles (SADP) that can provide both guidance for the technical design of RI/BDI and a basis for targeted training for engineering and scientific personnel. The paper also refers to ongoing research and developments on ensuring the environmental sustainability of RIs where the proposed SADP plays an important role. The presented work is based on the author’s experiences of developing and teaching courses on Big Data Infrastructure Technologies for Data Analytics (BDIT4DA) and DevOps for Software Engineering (DevOps4SE) that include necessary competences and learning outcomes required for building modern data-driven infrastructures and applications. The paper shares the experience of how both courses have evolved and been adapted to the continuous technology development and specific needs of the developer teams. Yuri Demchenko |
IEEE Big Data | 1 |
| 2023 | Professional and 21st Century Skills for Data Driven Digital EconomyabstractEmerging data driven digital economy and Industry 4.0 transforms all sectors including industry, research and business. It requires new types of the general workforce and specialists that can effectively use digital and data technologies, variety of tools and global infrastructure services, and are capable for personal skills management and self-study. The paper provides an overview of the existing frameworks for competences, skills and qualifications that sets up a baseline for further research and definition of the skills for emerging data driven digital economy. The paper analyses the general profile of the modern agile data driven companies, their culture and required competences. The paper shares the experience of introducing professional and 21stCentury skills in the bachelor and master courses. The project based learning model is proven to be effective in this cases combining the student initiative and self-organisation given the well defined course objectives and reporting requirements. Yuri Demchenko, Viktoriya Degeler, Ana Opresu, Steve Brewer |
EDUCON | 1 |
| 2022 | SLICES, a scientific instrument for the networking communityabstractA science is defined by a set of encyclopedic knowledge related to facts or phenomena following rules or evidenced by experimentally-driven observations. Computer Science and in particular computer networks is a relatively new scientific domain maturing over years and adopting the best practices inherited from more fundamental disciplines. The design of past, present and future networking components and architectures have been assisted, among other methods, by experimentally-driven research and in particular by the deployment of test platforms, usually named as testbeds . However, often experimentally-driven networking research used scattered methodologies, based on ad-hoc, small-sized testbeds , producing hardly repeatable results. We believe that computer networks needs to adopt a more structured methodology, supported by appropriate instruments, to produce credible experimental results supporting radical and incremental innovations. This paper reports lessons learned from the design and operation of test platforms for the scientific community dealing with digital infrastructures. We introduce the SLICES initiative as the outcome of several years of evolution of the concept of a networking test platform transformed into a scientific instrument. We address the challenges, requirements and opportunities that our community is facing to manage the full research-life cycle necessary to support a scientific methodology. Serge Fdida, Nikos Makris, Thanasis Korakis, Raffaele Bruno 0001, Andrea Passarella, Panayiotis Andreou, Bartosz Belter, Cedric Crettaz, Walid Dabbous, Yuri Demchenko, Raymond Knopp |
Comput. Commun. | 10 |
| 2021 | EDISON Data Science Framework (EDSF): Addressing Demand for Data Science and Analytics Competences for the Data Driven Digital EconomyabstractEmerging data driven economy including industry, research and business, requires new types of specialists that are capable to support all stages of the data lifecycle from data production and input to data processing and actionable results delivery, visualisation and reporting, which can be jointly defined as the Data Science professions family. Data Science is becoming a new recognised field of science that leverages the Data Analytics methods with the power of the Big Data technologies and Cloud Computing that both provide a basis for effective use of the data driven research and economy models. Data Science research and education require a multi-disciplinary approach and data driven/centric paradigm shift. Besides core professional competences and knowledge in Data Science, increasing digitalisation of Science and Industry also requires new type of workplace and professional skills that rise the importance of critical thinking, problem solving and creativity required to work in highly automated and dynamic environment. The education and training of the data related professions must reflect all multi-disciplinary knowledge and competences that are required from the Data Science and handling practitioners in modern, data driven research and the digital economy. In modern conditions with the fast technology change and strong skills demand, the Data Science education and training should be customizable and delivered in multiple forms, also providing sufficient lab facilities for practical training. This paper discusses aspects of building customizable and interoperable Data Science curricula for different types of learners and target application domains. The proposed approach is based on using the EDISON Data Science Framework (EDSF) initially developed in the EU funded Project EDISON and currently being maintained by the EDISON Community Initiative. Yuri Demchenko, Juan Jose Cuadrado-Gallego, Steve Brewer, Tomasz Wiktorski |
EDUCON | 1 |
| 2021 | Research Data Management and Data Stewardship Competences in University CurriculumabstractSkills for data governance and management are critical for the wide adoption of Open Science practices and effective use of the data in research, industry, business and other economic sectors. The FAIR (Findable - Accessible - Interoperable - Reusable) data management principles and data stewardship provide a foundation for effective research data management. The 2018 “Turning FAIR into Reality” report and other documents recommend that data skills should be more widely included in university curricula and that a concerted effort should be made to coordinate and accelerate the pedagogy for professional data roles. Throughout Europe and beyond, many organisations, projects and initiatives work on providing training on FAIR data competences. However, wider adoption of the FAIR data culture can be achieved by including FAIR competences into university curricula. This paper presents the ongoing work of the FAIRsFAIR project to develop a Data Stewardship competence framework and to provide recommendations for implementing this framework in university curricula by means of defining the Data Stewardship Body of Knowledge Model Curricula. The proposed approach and identified competences and knowledge topics are supported by a job market analysis. The presented work is actively using the EDISON Data Science Framework as a basis for Data Stewardship competences definition and methodology for linking competences, skills, knowledge, and intended learning outcomes when designing curricula. Yuri Demchenko, Lennart Stoy |
EDUCON | 1 |
| 2021 | Classification and Analysis of Techniques and Tools for Data Visualization TeachingabstractData Visualization addresses the use of graphics with the purpose to obtain or transmit the knowledge in a easier and faster way, this is it main, and in many cases unique purpose. Since their invention Data graphics has evolved and many techniques has been developed, and in the last decades, with the definition and evolution of the Data Science, Data Visualization has become to be used profusely, in that manner that, by one side, the Data Science Body of Knowledge, DS-BoK, define five knowledge area groups that should be taught when learning Data Science, in all of them Data Visualization is taken a main role for different reasons applying each knowledge area; and by other side all the Data Science development environments, open source or proprietary, include tools for performing Data Visualizations. This paper presents the results of a research carried out with the main objective of improving the teaching of data visualization using two ways: propose a new system to classify the large amount of different graphical techniques for presenting data that can be found in the literature; and analyze using different attributes quite all the most important different tools, open source and private, that are available to develop data graphics mainly form a data visualization teaching point of view. Juan Jose Cuadrado-Gallego, Yuri Demchenko, Miguel A. Losada, Olga Ormandjieva |
EDUCON | 2 |
| 2019 | EDISON Data Science Framework (EDSF) Extension to Address Transversal Skills Required by Emerging Industry 4.0 TransformationabstractThe emerging data-driven economy (also defined as Industry 4.0 or simply 4IR), encompassing industry, research and business, requires new types of specialists that are able to support all stages of the data lifecycle from data production and input, to data processing and actionable results delivery, visualisation and reporting, which can be collectively defined as the Data Science family of professions. Data Science as a research and academic discipline provides a basis for Data Analytics and ML/AI applications. The education and training of the data related professions must reflect all multi-disciplinary knowledge and competences that are required from the Data Science and handling practitioners in modern, data-driven research and the digital economy. In the modern era, with ever faster technology changes, matched by strong skills demand, the Data Science education and training programme should be customizable and deliverable in multiple forms, tailored for different categories of professional roles and profiles. Referring to other publications by the authors on building customizable and interoperable Data Science curricula for different types of learners and target application domains, this paper is focused on defining a set of transversal competences and skills that are required from modern and future Data Science professions. These include workplace and professional skills that cover critical thinking, problem solving, and creativity required to work in highly automated and dynamic environment. The proposed approach is based on the EDISON Data Science Framework (EDSF) initially developed within the EU funded Project EDISON and currently being further developed in the EU funded MATES project and also the FAIRsFAIR projects. Yuri Demchenko, Tomasz Wiktorski, Juan Jose Cuadrado-Gallego, Steve Brewer |
eScience | 1 |
| 2019 | Teaching DevOps and Cloud Based Software Engineering in University CurriculaabstractThis paper presents recommendations on the design and pilot implementation of the DevOps and Cloud based Software Development curricula for Computer Science and Software Engineering masters. The central part of proposed approach is the Body of Knowledge in the DevOps technologies for Software Engineering (DevOpsSE BoK) that defines a set Knowledge Areas and Knowledge Units required for SE professionals to work efficiently as DevOps engineer or application developer. Defining DevOpsSE-BoK provides a basis for defining required professional competences and skills and allows consistent curricula structuring and profiling. The paper also reports on the experience of the first course run on 2018/2019 academic year at the University of Amsterdam. The paper presents the structure of the course and explains what instructional methodologies have been used for course development, such as project based learning that facilitates the students' team based skills both in mastering Agile development process and skills sharing. The paper provides a short summary of the generally used DevOps definitions, concepts, models and tools, specifically focusing on the cloud based DevOps tools for software development, deployment and operation that allows the main DevOps principle of continuous development and continuous improvement which are critical for modern agile data driven companies. Yuri Demchenko, Zhiming Zhao, Jayachander Surbiryala, Spiros Koulouzis, Zeshun Shi, Jelena Gordiyenko |
eScience | 1 |
| 2019 | Data Science Model Curriculum Implementation for Various Types of Big Data Infrastructure CoursesabstractThis paper presents experiences of development and teaching three different types of Big Data Infrastructure courses as a part of the general Data Science curricula. The authors built the discussed courses based on the EDISON Data Science Framework (EDSF), in particular, Data Science Body of Knowledge (DS-BoK) related to Data Science Engineering knowledge area group (KAG-DSENG). The paper provides overview of the sandboxes, Cloud-based platforms and tools for Big Data Analytics and stresses importance of including into curriculum the practical work with Clouds for future graduates or specialists workplace adaptability. The paper discusses a relationship between the DSENG BoK and Big Data technologies and platforms, in particular Hadoop-based applications and tools for data analytics that should be promoted through all course activities: lectures, practical activities and self-study. Tomasz Wiktorski, Yuri Demchenko, Oleg Chertov |
eScience | 2 |
| 2017 | Defining Intercloud Security Framework and Architecture Components for Multi-Cloud Data Intensive ApplicationsabstractThis paper presents results of the ongoing development of the Intercloud Security Framework (ICSF), that is a part of the Intercloud Architecture Framework (ICAF), and provides an architectural basis for building security infrastructure services for multi-cloud applications. The paper refers to general use case of the data intensive applications that indicate need for multi-cloud applications platforms that will require corresponding multi-cloud security services. The paper presents analysis of the general multi-cloud use case that helps eliciting the general requirement to ICSF and identifying the security infrastructure functional components that would allow using distributed cloud based resources and data sets. The paper defines the main ICSF services and functional components, and explains importance of consistent implementation of the Security Services Lifecycle Management in cloud based applications. The paper provides overview of the cloud compliance standards and their role in cloud security. The paper refers to the security infrastructure development in the CYCLONE project that implements federated identify management, secure logging service, and multi-domain Attribute Based Access Control, security services lifecycle management. The paper discusses implementation of the Trust Bootstrapping Protocol as an important mechanism to ensure consistent security in the virtualised inter-cloud environment. Yuri Demchenko, Fatih Turkmen, Cees T. A. M. de Laat, Mathias Slawik |
CCGrid | 1 |
| 2017 | Customisable Data Science Educational Environment: From Competences Management and Curriculum Design to Virtual Labs On-DemandabstractData Science is an emerging field of science, which requires a multi-disciplinary approach and is based on the Big Data and data intensive technologies that both provide a basis for effective use of the data driven research and economy models. Modern data driven research and industry require new types of specialists that are capable to support all stages of the data lifecycle from data production and input to data processing and actionable results delivery, visualisation and reporting, which can be jointly defined as the Data Science professions family. The education and training of Data Scientists currently lacks a commonly accepted, harmonized instructional model that reflects all multi-disciplinary knowledge and competences that are required from the Data Science practitioners in modern, data driven research and the digital economy. The educational model and approach should also solve different aspects of the future professionals that includes both theoretical knowledge and practical skills that must be supported by corresponding education infrastructure and educational labs environment. In modern conditions with the fast technology change and strong skills demand, the Data Science education and training should be customizable and delivered in multiple form, also providing sufficient data labs facilities for practical training. This paper discussed both aspects: building customizable Data Science curriculum for different types of learners and proposing a hybrid model for virtual labs that can combine local university facility and use cloud based Big Data and Data analytics facilities and services on demand. The proposed approach is based on using the EDISON Data Science Framework (EDSF) developed in the EU funded Project EDISON and CYCLONE cloud automation systems being developed in another EU funded project CYCLONE. Yuri Demchenko, Adam Belloum, Cees T. A. M. de Laat, Charles Loomis, Tomasz Wiktorski, Erwin Spekschoor |
CloudCom | 1 |
| 2017 | CYCLONE: The Multi-cloud Middleware Stack for Application Deployment and ManagementabstractDevOps teams have to consider many technology and platform aspects when developing, deploying and operating cloud based applications: application deployments need to work everywhere on different cloud platforms, identities need to come from anywhere, and networks need to connect to anyone. The CYCLONE middleware is a holistic middleware stack that allows deploying and managing cloud based applications on multiple clouds and multiple cloud platforms. It includes a deployment manager, a practical identity federation, as well as a network manager that connects VMs independent of any specific infrastructure. This article explains the CYCLONE middleware stack, and what it can offer for application developers and operators. The paper describes in details the main bioinformatics use cases that evolve from a single VM installation for simple microbial research to multicloud infrastructure for advanced genomic resource. The paper also describes the CYCLONE federated identity management and access control infrastructure that significantly simplifies access for institutional users. Mathias Slawik, Christophe Blanchet, Yuri Demchenko, Fatih Turkmen, Alexy Ilyushkin, Cees T. A. M. de Laat, Charles Loomis |
CloudCom | 3 |
| 2017 | Model Curricula for Data Science EDISON Data Science FrameworkabstractThis paper presents the Data Science Model Curriculum (MC-DS) that is based on the Data Science Competence Framework and Data Science Body of Knowledge defined in EDISON Data Science Framework (EDSF). MC-DS follows a competence-based curriculum design approach grounded in the Data Science competences (CD-DS) defined in EDSF and correspondingly defined Learning Outcomes (LO). The DSBoK provides a basis for structuring the proposed MC-DS by Knowledge Area Groups (KAG) defined in correspondence with the CF-DS competence groups. ECTS point allocation to specific areas is recommended for Master's and Bachelor's program covering professional profile groups. Tomasz Wiktorski, Yuri Demchenko, Adam Belloum |
CloudCom | 2 |
| 2016 | EDISON Data Science Framework: A Foundation for Building Data Science Profession for Research and IndustryabstractData Science is an emerging field of science, which requires a multi-disciplinary approach and should be built with a strong link to emerging Big Data and data driven technologies, and consequently needs re-thinking and re-design of both traditional educational models and existing courses. The education and training of Data Scientists currently lacks a commonly accepted, harmonized instructional model that reflects by design the whole lifecycle of data handling in modern, data driven research and the digital economy. This paper presents the EDISON Data Science Framework (EDSF) that is intended to create a foundation for the Data Science profession definition. The EDSF includes the following core components: Data Science Competence Framework (CF-DS), Data Science Body of Knowledge (DS-BoK), Data Science Model Curriculum (MC-DS), and Data Science Professional profiles (DSP profiles). The MC-DS is built based on CF-DS and DS-BoK, where Learning Outcomes are defined based on CF-DS competences and Learning Units are mapped to Knowledge Units in DS-BoK. In its own turn, Learning Units are defined based on the ACM Classification of Computer Science (CCS2012) and reflect typical courses naming used by universities in their current programmes. The paper provides example how the proposed EDSF can be used for designing effective Data Science curricula and reports the experience of implementing EDSF by the Champion Universities that cooperate with the EDISON project. Yuri Demchenko, Adam Belloum, Wouter Los, Tomasz Wiktorski, Andrea Manieri, Holger Brocks, Jana Becker, Dominic Heutelbeck, Matthias L. Hemmje, Steve Brewer |
CloudCom | 1 |
| 2016 | On the Use of SMT Solving for XACML Policy EvaluationabstracteXtensible Access Control Markup Language (XACML) allows for flexible management of authorisations and is particularly useful in settings where permissions change dynamically. However, it has been shown that policy evaluation in XACML may have scalability problems when policies become large and sophisticated in content. Among several proposals for designing efficient policy decision points for XACML policies, decision diagram (DD) based procedures still represent the state-of-the-art. In this paper, we present an alternative approach to policy evaluation that employs Satisfiability Modulo Theories (SMT) solving instead of DDs. The approach does not only represent a feasible policy evaluation procedure in terms of performance but also easily lends itself to different application areas such as verification at run-time during authorization query answering. We discuss various scenarios in which SMT-based policy evaluation would be more practical compared to DD-based procedures. A preliminary experimental evaluation of our policy evaluation procedure against real-world policies is also provided in the paper. Fatih Turkmen, Yuri Demchenko |
CloudCom | 2 |
| 2016 | Quantitative and Qualitative Analysis of Current Data Science Programs from Perspective of Data Science Competence Groups and FrameworkabstractData Science is becoming a field connecting multi-year development in areas such as Big Data and Data Analytics, and also applied domains like Bioengineering. Data Science education programs are rapidly being created on all levels. Usually it happens through reuse or renaming and can result in curricula that lack proper balance of competences, which balance is necessary for future data scientists. Our quantitative analysis of over 300 programs worldwide shows that at least one of the three core data science competence groups is under-represented in the majority of programs. Moreover, general business courses are often suggested to students to cover the domain competence group, which in most cases results in superficial treatment of this competence group. Our further qualitative analysis demonstrates that learning outcomes for most of the courses are usually not defined or defined improperly. Tomasz Wiktorski, Yuri Demchenko, Adam Belloum, Anoosheh Shirazi |
CloudCom | 2 |
| 2016 | Runtime Application Performance Management for Multi-Cloud Cyclone EnvironmentabstractThis paper presents results of the ongoing development of CYCLONE as a platform for scientific applications in heterogeneous multi-cloud/multi-provider environment. In particular, we focus on QoS management of the multi-cloud applications within CYCLONE. A challenging factor for application deployment and exploitation within the CYCLONE infrastructure is its highly dynamic nature, which raises the need for control methods that quickly adapt to, or even anticipate, changing circumstances. In this paper we present the solution that allows for performance optimization of the running applications within CYCLONE. This solution is envisioned as an eternal software solution which can be integrated with SlipStream, a multi-cloud application management platform. Based on the analysis of the measurement data, a number of actions may be taken. These actions may include re-scaling of the cloud resources, re-deployment of the application, or choosing of the alternative deployment of the same application. The core of our solution is the analytics engine, and, for a given scenario, we illustrate the some of the engine algorithms. Miroslav Zivkovic, Charles Loomis, Yuri Demchenko |
CloudCom | 3 |
| 2016 | iGenoPri: Privacy-preserving genomic data processing with integrity and correctness proofsabstractNowadays, governmental and non-governmental health organisations and insurance companies invest in integrating an individual's genetic information to their daily practices. In this paper, we focus on an emerging area of genome analysis, called Disease Susceptibility (DS), from which an individual's susceptibility to a disease is calculated by using her genetic information. Recent work by Danezis et al. [1] presents an approach for calculating DS in a privacy-preserving manner. However, the proposed solution has two drawbacks. First, it does not provide a mechanism to check the integrity of genomic data that is used to calculate the susceptibility and more importantly the computed result. Second, it lacks a mechanism to check the correctness of the performed DS test. In this paper, we present iGenoPri that aims at addressing both problems by employing the Message Authentication Code (MAC) and verifiable computing. Fatih Turkmen, Muhammad Rizwan Asghar, Yuri Demchenko |
PST | 3 |
| 2016 | Multi-tenant attribute-based access control for cloud infrastructure services
Canh Ngo, Yuri Demchenko, Cees T. A. M. de Laat |
J. Inf. Secur. Appl. | 2 |
| 2015 | Data Science Professional Uncovered: How the EDISON Project will Contribute to a Widely Accepted Profile for Data ScientistsabstractThe digital revolution made available vast amounts of data both in industry and in the research landscape. The ability to manipulate and extract knowledge and value from this data represents a new profession called the Data Scientist: expected to be the most visible job in future years. The EDISON project has been established in order to support universities, research centers, industry and research infrastructure organisations to cope with the potential shortfall of Data Scientists, to define the framework of competences as well as the body of knowledge for this profession. In this paper the EDISON team describes how it intends to nurture the profession of Data Scientist to cope with the expected increase in demand. The strategy proposed is based on both the analysis of the demand side (industries, research centers and research infrastructure organisations) and the supply side (Universities and training centers) bridging between the providers and employers by cooperating on the establishment of a Competence Framework and a Body of Knowledge for the Data Scientist Professional. The project will exploit piloting initiatives in cooperation with pioneer universities and also involve external experts as evangelists. Andrea Manieri, Steve Brewer, Ruben Riestra, Yuri Demchenko, Matthias L. Hemmje, Tomasz Wiktorski, Tiziana Ferrari, Jérémy Frey |
CloudCom | 4 |
| 2015 | Open Cloud eXchange (OCX): A Pivot for Intercloud Services Federation in Multi-provider Cloud Market EnvironmentabstractThis paper presents results of the ongoing development of the Open Cloud eXchange (OCX) that has been proposed in the framework of the GN3plus project. Its aim is to provide cloud aware network infrastructure to power and support modern data intensive research at European universities and research organisations. The paper describes the OCX concept, architecture, design and implementation options. OCX includes 3 major components: distributed L0-L2 (optionally L3) network infrastructure that includes OCX points of presence (OCXP) interconnected with GEANT backbone; the Trusted Third Party (TTP) for building dynamic trust federations; and the marketplace to enable publishing and discovery of cloud services. OCX intends to be neutral to actual cloud services provisioning and limits its services to Layer 0 through Layer 2 in order to remain transparent to current cloud services model. The recent developments include an architectural update, API definition, integration with higher-level applications and workflow control, signaling and intercloud topology modelling and visualization. The paper reports about results and experiences learnt from the recent OCX demonstrations at the SC14 Exhibition in November 2014 that demonstrated the benefits of an OCX enabled Intercloud infrastructure for running data intensive real-time cloud applications on top of the advanced GEANT multi-gigabit network. The implemented OCX functionality allowed applications to control the network path for data transfer and service delivery connectivity between multiple Cloud Service Providers (CSPs). It was used in combination with a multi-cloud workflow management and planning application (Vampire) that enables data processing performance monitoring and migration of VMs and processes to an alternative location based on performance predictions. Yuri Demchenko, Cosmin Dumitru, Ralph Koning, Cees T. A. M. de Laat, Taras Matselyukh, Sonja Filiposka, Migiel de Vos, Daniel Arbel, Damir Regvart, Tasos Karaliotas, Kurt Baumann |
IC2E | 1 |
| 2015 | Decision Diagrams for XACML Policy Evaluation and Management
Canh Ngo, Yuri Demchenko, Cees T. A. M. de Laat |
Comput. Secur. | 2 |
| 2014 | Experience of Profiling Curricula on Cloud Computing Technologies and Engineering for Different Target GroupsabstractThis paper presents results and experience by the authors based on the few delivered courses on Cloud Computing for different target groups of students, specialists and trainees. The developed courses implement the proposed by the authors instructional methodology integrating the two major concepts of effective learning: the Bloom's Taxonomy of cognitive learning processes and Andragogy as the adult learning methodology. The central part of the proposed approach is the Common Body of Knowledge in Cloud Computing (CBK-CC) that defines the professional level of knowledge in the selected domain and allows consistent curricula structuring and profiling. The paper presents the structure of the courses and explains the principles used for developing course materials, such as Bloom's Taxonomy applied for technical education, and andragogy instructional model for professional education and training. The developed courses are based on the well-defined Cloud Computing architecture, service and operational model, and stakeholder roles/responsibilities. The paper provides a short description of the developed education and training courses on Cloud Computing that illustrate how the proposed CBK-CC and instructional methodologies are used in different learning environments and for different learners' groups. Yuri Demchenko, Adam Belloum, David Bernstein, Cees T. A. M. de Laat |
CloudCom | 1 |
| 2014 | Instructional Model for Building Effective Big Data Curricula for Online and Campus EducationabstractThis paper presents current results and ongoing work to develop effective educational courses on the Big Data (BD) and Data Intensive Science and Technologies (DIST) that is been done at the University of Amsterdam in cooperation with KPMG and by the Laureate Online Education (online partner of the University of Liverpool). The paper introduces the main Big Data concepts: multicomponent Big Data definition and Big Data Architecture Framework that provide the basis for defining the course structure and Common Body of Knowledge for Data Science and Big Data technology domains. The paper presents details on approach, learning model, and course content for two courses at the Laureate Online Education/University of Liverpool and at the University of Amsterdam. The paper also provides background information about existing initiatives and activities related to information exchange and coordination on developing educational materials and programs on Big Data, Data Science, and Research Data Management. Yuri Demchenko, Emanuel Gruengard, Sander Klous |
CloudCom | 1 |
| 2014 | Federated Access Control in Heterogeneous Intercloud Environment: Basic Models and Architecture PatternsabstractThis paper presents on-going research to define the basic models and architecture patterns for federated access control in heterogeneous (multi-provider) multi-cloud and inter-cloud environment. The proposed research contributes to the further definition of Intercloud Federation Framework (ICFF) which is a part of the general Intercloud Architecture Framework (ICAF) proposed by authors in earlier works. ICFF attempts to address the interoperability and integration issues in provisioning on-demand multi-provider multi-domain heterogeneous cloud infrastructure services. The paper describes the major inter-cloud federation scenarios that in general involve two types of federations: customer-side federation that includes federation between cloud based services and customer campus or enterprise infrastructure, and provider-side federation that is created by a group of cloud providers to outsource or broker their resources when provisioning services to customers. The proposed federated access control model uses Federated Identity Management (FIDM) model that can be also supported by the trusted third party entities such as Cloud Service Broker (CSB) and/or trust broker to establish dynamic trust relations between entities without previously existing trust. The research analyses different federated identity management scenarios, defines the basic architecture patterns and the main components of the distributed federated multi-domain Authentication and Authorisation infrastructure. Yuri Demchenko, Canh Ngo, Cees T. A. M. de Laat, Craig A. Lee |
IC2E | 1 |
| 2014 | The GEYSERS optical testbed: A platform for the integration, validation and demonstration of cloud-based infrastructure services
Bartosz Belter, Juan Rodríguez Martinez, José I. Aznar, Jordi Ferrer Riera, Luis M. Contreras 0001, Monika Antoniak-Lewandowska, Matteo Biancani, Jens Buysse, Chris Develder, Yuri Demchenko, Pasquale Donadio, Dimitra Simeonidou, Reza Nejabati, Shuping Peng 0001, Lukasz Drzewiecki, Eduard Escalona, Joan Antoni García Espín, Steluta Gheorghiu, Mattijs Ghijsen, Jakub Gutkowski, Giada Landi, Gino Carrozzo, Damian Parniewicz, Sebastien Soudan |
Comput. Networks | 10 |
| 2013 | Dynamic Optimization of SLA-Based Services Scaling RulesabstractCurrent advanced cloud infrastructure management solutions allow scheduling actions for dynamically changing the number of running virtual machines (VMs). This approach, however, does not guarantee that the scheduled number of VMs will properly handle the actual user generated workload, especially if the user utilization patterns will change. We propose using a dynamically generated scaling model for the VMs containing the services of the distributed applications, which is able to react to the variations in the number of application users. We answer the following question: How to dynamically decide how many services of each type are needed in order to handle a larger workload within the same time constraints? We describe a mechanism for dynamically composing the SLAs for controlling the scaling of distributed services by combining data analysis mechanisms with application benchmarking using multiple VM configurations. Based on processing of multiple application benchmarks generated data sets we discover a set of service monitoring metrics able to predict critical Service Level Agreement (SLA) parameters. By combining this set of predictor metrics with a heuristic for selecting the appropriate scaling-out paths for the services of distributed applications, we show how SLA scaling rules can be inferred and then used for controlling the runtime scale-in and scale-out of distributed services. We validate our architecture and models by performing scaling experiments with a distributed application representative for the enterprise class of information systems. We show how dynamically generated SLAs can be successfully used for controlling the management of distributed services scaling. Alexandru-Florian Antonescu, Ana-Maria Oprescu, Yuri Demchenko, Cees T. A. M. de Laat, Torsten Braun |
CloudCom (1) | 3 |
| 2013 | The IEEE Intercloud Testbed - Creating the Global Cloud of CloudsabstractThis paper presents the current work of the IEEE Intercloud Testbed project. The notion of an Intercloud has been an active research topic. Within the IEEE several researchers formed a Standards Working Group (IEEE P2302) where a specific set of conventions, formats, and protocols were proposed. It was decided by those in the Standards Working Group that due to the scale, variability of component Compute Clouds, and lack of insight into extremely large Compute Cloud operational issues, such a system could not realistically be fully defined without live experimentation. Therefore it was decided to set up a specifically structured organization within the IEEE in parallel to the Standards Working Group, to provide a structure for a live, experimental testbed. This paper describes the innovative organizational structure and various policies were used to provide the desire context. Also covered are how we sorted the issues around governance of the namespace, and the technical details of reference "Root" and "Exchange" functions. Ongoing work includes the plan to bootstrap the new testbed. David Bernstein, Yuri Demchenko |
CloudCom (2) | 2 |
| 2013 | New Instructional Models for Building Effective Curricula on Cloud Computing Technologies and EngineeringabstractThis paper presents ongoing work to develop advanced education and training course on the Cloud Computing technologies foundation and engineering by a cooperating group of universities and the professional education partners. The central part of proposed approach is the Common Body of Knowledge in Cloud Computing (CBK-CC) that defines the professional level of knowledge in the selected domain and allows consistent curricula structuring and profiling. The paper presents the structure of the course and explains the principles used for developing course materials, such as Bloom's Taxonomy applied for technical education, and andragogy instructional model for professional education and training. The paper explains the importance of using the strong technical foundation to build the course materials that can address interests of different categories of stakeholders and roles/responsibilities in the Cloud Computing services provisioning and operation. The paper provides a short description of summary of the used Cloud Computing related architecture concepts and models that allow consistent mapping between CBK-CC, stakeholder roles/responsibilities and required skills, explaining also importance of the requirements engineering stage that provides a context for cloud based services design. The paper refers to the ongoing development of the educational course on Cloud Computing at the University of Amsterdam, University of Stavanger and provides suggestions for building advanced online training course for IT professionals. Yuri Demchenko, David Bernstein, Adam Belloum, Ana-Maria Oprescu, Tomasz Wiktor Wlodarczyk, Cees T. A. M. de Laat |
CloudCom (2) | 1 |
| 2013 | Open Cloud eXchange (OCX): Architecture and Functional ComponentsabstractThis paper presents the concept of Open Cloud eXchange (OCX) that has been proposed to bridge the gap between two major components of the cloud services provisioning infrastructure: Cloud Service Provider (CSP) infrastructure, and cloud services delivery infrastructure which in many cases requires dedicated local infrastructure and quality of services that cannot be delivered by the public Internet infrastructure. In both cases there is a need for interconnecting the CSP infrastructure and local access network infrastructure, in particular, to solve the "last mile" problem in delivering cloud services to customer locations and individual (end-)users. The OCX remains neutral to actual cloud services provisioning and limit its services to Layer 0 through Layer 2 to remain transparent to current cloud services model. The proposed document identifies the initial set of requirements to OCX, that can be run by NRENs, as a part of the G&201;ANT network, or jointly, and provides suggestions about OCX implementation. The proposed OCX concept will leverage the existing Internet eXchange (IX) and GLIF Open Light path Exchange (GOLE) solutions and practices, adding specific functionality that will simplify inter-CSP and customer infrastructure integration when supporting basic cloud services provisioning models, in particular Trusted Third Party (TTP) services to allow federated infrastructure and access control, commonly used by NRENs. The paper also describes trusted/secured topology exchange protocol and dynamic trust establishment protocol as a part of the OCX services. Yuri Demchenko, Jeroen van der Ham, Canh Ngo, Taras Matselyukh, Sonja Filiposka, Cees T. A. M. de Laat, Eduard Escalona |
CloudCom (2) | 1 |
| 2013 | ICOMF: Towards a Multi-cloud Ecosystem for Dynamic Resource Composition and ScalingabstractModern cloud-based applications and infrastructures may include resources and services (components) from multiple cloud providers, are heterogeneous by nature and require adjustment, composition and integration. The specific application requirements can be met with difficulty by the current static predefined cloud integration architectures and models. In this paper, we propose the Intercloud Operations and Management Framework (ICOMF) as part of the more general Intercloud Architecture Framework (ICAF) that provides a basis for building and operating a dynamically manageable multi-provider cloud ecosystem. The proposed ICOMF enables dynamic resource composition and decomposition, with a main focus on translating business models and objectives to cloud services ensembles. Our model is user-centric and focuses on the specific application execution requirements, by leveraging incubating virtualization techniques. From a cloud provider perspective, the ecosystem provides more insight into how to best customize the offerings of virtualized resources. Ana-Maria Oprescu, Alexandru-Florian Antonescu, Yuri Demchenko, Cees T. A. M. de Laat |
CloudCom (1) | 3 |
| 2013 | Multi-data-types interval decision diagrams for XACML evaluation engineabstractXACML policy evaluation efficiency is an important factor influencing the overall system performance, especially when the number of policies grows. Some existing approaches on high performance XACML policy evaluation can support simple policies with equality comparisons and handle requests with well defined conditions. Such mechanisms do not provide the semantic correctness of combining algorithms in cases with indeterminate and not-applicable states. They ignore the critical attribute setting, a mandatory property in XACML, leading to potential missing attribute attacks. In this paper, we present a solution using data interval partition aggregation together with new decision diagram combinations, that not only optimizes the performance but also provides correctness and completeness of XACML 3.0 features, including complex logical expressions, correctness in indeterminate states processing, critical attribute setting, obligations and advices as well as complex comparison functions for multiple data types. Canh Ngo, Marc X. Makkes, Yuri Demchenko, Cees T. A. M. de Laat |
PST | 3 |
| 2012 | Trusted Virtual Infrastructure Bootstrapping for On Demand ServicesabstractAs cloud computing continues to gain traction, a great deal of effort is being expended in researching the most effective ways to build and manage secure and trustworthy clouds. Providing consistent security services in on-demand provisioned Cloud infrastructure services is of primary importance due to the multi-tenant and potentially multi-provider nature of Cloud Infrastructure. Cloud security infrastructure should address two aspects of the IaaS operation and dynamic security services provisioning: (1) provide security infrastructure for secure Cloud IaaS operation; (2) provisioning dynamic security services. Although the first task is a traditional task in security engineering, dynamic provisioning of managed security services in virtualized environment remains a problem and requires additional research. Entire frameworks have been proposed and demonstrated but although successful, there is a tendency to see such solutions as integrated 'all in one' infrastructures. This paper describes a light-weight mechanism and protocol for building trust between two machines that takes advantage of the Trusted Platform Module (TPM) to handle a key exchange and remote trusted deployment of a bootstrapping tool (referred to as the Bootstrapping Initiator (BI)). Once deployed, the BI can execute any arbitrary software required which could be (but is not limited to) solutions for advanced architecture management such as the Dynamic Access Control Infrastructure (DACI). The proposed solution provides a light-weight layer of trust backed by a TPM that additional systems can build upon as required by the individual use case without the requirement for a specific management or security infrastructure to be deployed along with it. Peter Membrey, Keith C. C. Chan, Canh Ngo, Yuri Demchenko, Cees T. A. M. de Laat |
ARES | 4 |
| 2012 | Policy and Context Management in Dynamically Provisioned Access Control Service for Virtualized Cloud InfrastructuresabstractCloud computing is developing as a new wave of ICT technologies, offering a common approach to on-demand provisioning of computation, storage and network resources which are generally referred to as infrastructure services. Most of currently available commercial Cloud services are built and organized reflecting simple relations between a single provider and multiple customers with simple security and trust model. New architectural models should allow multi-provider heterogeneous service environment that can be delivered to organizational customers representing multiple user groups. These models should be supported by new security approaches for multi-provider, multi-tenant environment crossing multiple security domains to create consistent and dynamically configurable security services for virtualized infrastructures. This paper proposes an on-demand provisioned access control infrastructure with dynamic trust establishment for entities in a Cloud IaaS architecture model. It applies XACML-based RBAC model for the flexible authorization policy configuration and management. It uses authorization ticket as a security session management mechanism to solve the security context synchronization and exchange between multiple Cloud providers. The paper describes practical implementation of the proposed Dynamic Access Control Infrastructure as the part of a complex infrastructure services provisioning system. Canh Ngo, Peter Membrey, Yuri Demchenko, Cees T. A. M. de Laat |
ARES | 3 |
| 2012 | Intercloud Architecture for interoperability and integrationabstractThis paper presents on-going research to develop the Intercloud Architecture Framework (ICAF) that addresses problems in multi-provider multi-domain heterogeneous cloud based infrastructure services and applications integration and interoperability. The paper refers to existing standards in Cloud Computing, in particular, recently published NIST Cloud Computing Reference Architecture (CCRA). The proposed ICAF defines four complementary components addressing Intercloud integration and interoperability: multilayer Cloud Services Model that combines commonly adopted cloud service models, such as IaaS, PaaS, SaaS, in one multilayer model with corresponding inter-layer interfaces; Intercloud Control and Management Plane that supports cloud based applications interaction; Intercloud Federation Framework, and Intercloud Operation Framework. The paper briefly describes the architectural framework for cloud based infrastructure services provisioned on-demand being developed in the framework of the GEYSERS project that is used as a basis for building multilayer cloud services integration framework that allows optimized provisioning of both computing, storage and networking resources. The proposed architecture is intended to provide an architectural model for developing Intercloud middleware and in this way will facilitate clouds interoperability and integration. Yuri Demchenko, Marc X. Makkes, Rudolf J. Strijkers, Cees T. A. M. de Laat |
CloudCom | 1 |
| 2012 | Addressing Big Data challenges for Scientific Data InfrastructureabstractThis paper discusses the challenges that are imposed by Big Data Science on the modern and future Scientific Data Infrastructure (SDI). The paper refers to different scientific communities to define requirements on data management, access control and security. The paper introduces the Scientific Data Lifecycle Management (SDLM) model that includes all the major stages and reflects specifics in data management in modern e-Science. The paper proposes the SDI generic architecture model that provides a basis for building interoperable data or project centric SDI using modern technologies and best practices. The paper explains how the proposed models SDLM and SDI can be naturally implemented using modern cloud based infrastructure services provisioning model. Yuri Demchenko, Zhiming Zhao, Paola Grosso, Adianto Wibisono, Cees T. A. M. de Laat |
CloudCom | 1 |
| 2012 | Toward a Dynamic Trust Establishment approach for multi-provider Intercloud environmentabstractIn cloud computing, data are managed by different entities, not only by the actual data owner but also by many cloud providers. Sophisticated clouds collaboration scenarios may require that the data objects are distributed at cloud providers and accessed remotely, while still being under the control of the data owners. This brings security challenges for distributed authorization and trust management that existing proposed schemes have not fully solved. In this paper, we propose a Dynamic Trust Establishment approach which can be incorporated into cloud services provisioning life-cycles for the multi-provider Intercloud environment. It relies on attribute-based policies as the mechanism for trust evaluation and delegation. The paper proposes a practical implementation approach for attribute-based policies evaluation using Multi-type Interval Decision Diagrams extended from Integer Decision Diagrams which is more efficient in terms of evaluation complexity than other evaluation approaches. Canh Ngo, Yuri Demchenko, Cees T. A. M. de Laat |
CloudCom | 2 |
| 2011 | Defining Generic Architecture for Cloud IaaS Provisioning Model
Yuri Demchenko, Cees T. A. M. de Laat, Aleksej Mavrin |
CLOSER | 1 |
| 2011 | Security Infrastructure for On-demand Provisioned Cloud Infrastructure ServicesabstractProviding consistent security services in on-demand provisioned Cloud infrastructure services is of primary importance due to multi-tenant and potentially multi-provider nature of Clouds Infrastructure as a Service (IaaS) environment. Cloud security infrastructure should address two aspects of the IaaS operation and dynamic security services provisioning: (1) provide security infrastructure for secure Cloud IaaS operation, (2) provisioning dynamic security services, including creation and management of the dynamic security associations, as a part of the provisioned composite services or virtual infrastructures. The first task is a traditional task in security engineering, while dynamic provisioning of managed security services in virtualised environment remains a problem and requires additional research. In this paper we discuss both aspects of the Cloud Security and provide suggestions about required security mechanisms for secure data management in dynamically provisioned Cloud infrastructures. The paper refers to the architectural framework for on-demand infrastructure services provisioning, being developed by authors, that provides a basis for defining the proposed Cloud Security Infrastructure. The proposed SLA management solution is based on the WS-Agreement and allows dynamic SLA management during the whole provisioned services lifecycle. The paper discusses conceptual issues, basic requirements and practical suggestions for dynamically provisioned access control infrastructure (DACI). The paper proposes the security mechanisms that are required for consistent DACI operation, in particular security tokens used for access control, policy enforcement and authorisation session context exchange between provisioned infrastructure services and Cloud provider services. The suggested implementation is based on the GAAA Toolkit Java library developed by authors that is extended with the proposed Common Security Services Interface (CSSI) and additional mechanisms for binding sessions and security context between provisioned services and virtualised platform. Yuri Demchenko, Canh Ngo, Cees T. A. M. de Laat, Tomasz Wiktor Wlodarczyk, Chunming Rong, Wolfgang Ziegler |
CloudCom | 1 |
| 2011 | GEMBus as a Service Oriented Platform for Cloud-Based Composable ServicesabstractCloud computing has become a common technology for provisioning infrastructure services on-demand. Modern Cloud platforms can provide cloud-based applications, software, deployment platforms, or general infrastructure services that may include both computational and storage resources. However existing Cloud provisioning models are based on proprietary solutions and don't allow the combination of services from different providers and/or user legacy application that usually are present in user home organizations or campus networks. This paper introduces GEM Bus (GEANT Multi-domain Bus), a service-oriented middleware platform that allows flexible services composition, and their on-demand provisioning and deployment to create new specialized task-oriented services and applications. GEM Bus is built upon state-of-the-art Enterprise Service Bus (ESB) technologies and extend them with new functionalities that allow dynamic component services deployment, composition and management. The current paper discusses the general case for integration of Service-Oriented Architecture (SOA) principles and technologies with the provision and deployment mechanisms of Cloud-based platforms to support on-demand infrastructure services provisioning. It describes the Composable Services Architecture (CSA) that provides a general framework for GEM Bus services design and operation. The paper also presents the current GEM Bus implementation status and discusses how it can be applied as a general SOA platform for Cloud-based service provisioning. Finally, it discusses the practical use case of the federated network monitoring service that can be used as integration component in creating/building GEM Bus based Cloud infrastructure services. Mary Grammatikou, Constantinos Marinos, Yuri Demchenko, Diego R. López, Krzysztof Dombek, Jordi Jofre |
CloudCom | 3 |
| 2011 | An OpenFlow Based Network Virtualization Framework for the CloudabstractThe Cloud computing paradigm entails a challenging networking scenario. Due to the economy of scale, the Cloud is mainly supported by Data Center infrastructures. Therefore, virtualized environment manageability, seamless migration of virtual machines, inter-domain communication issues and scalability problems are some of the main concerns that should be addressed. A recently proposed abstract model is used as a reference for the Cloud computing architecture. This paper introduces a network virtualization framework for the Cloud based on this model. Accordingly, a proper abstraction of network elements (vhost, vnode and vlink) is defined in order to virtualize the physical infrastructure. Moreover, a novel Layer 2 network virtualization approach based on a new MAC addressing scheme is presented: we propose to build locally administered MAC addresses that hold context information, such as virtual operator, domain, node and host identifiers. In addition, implementation details are suggested, describing how the Open Flow technology can lead to an implementation of the proposed approach. Jon Matías, Eduardo Jacob, Yuri Demchenko |
CloudCom | 4 |
| 2011 | Security Framework for Virtualised Infrastructure Services Provisioned On-demandabstractCloud computing is developing as a new wave of ICT technologies, offering a common approach to on-demand provisioning computation, storage and network resources which are generally referred to as infrastructure services. Most of currently available commercial Cloud services are built and organized reflecting simple relations between single provider and single customer with simple security and trust model. New architectural models should allow multi-provider heterogeneous services environment that can be delivered to organizational customers representing multiple user groups. These models should be supported by new security approaches to create consistent security services in virtualised multi-provider Cloud environment and incorporate complex access control and trust relations among Cloud actors. The paper analyzes basis use cases in Cloud services provisioning and defines a security infrastructure reference model which is used to define other security infrastructure aspects such as dynamic trust management, distributed access control, policy and security context management. It also provides information about ongoing implementation of the proposed Dynamic Access Control Infrastructure based on Enterprise Service Bus as a part of complex infrastructure services provisioning system. Canh Ngo, Peter Membrey, Yuri Demchenko, Cees T. A. M. de Laat |
CloudCom | 3 |
| 2010 | Security Services Lifecycle Management in On-Demand Infrastructure Services ProvisioningabstractModern e-Science and high technology industry require high-performance and complicated network and computer infrastructure to support distributed collaborating groups of researchers and applications that should be provisioned on-demand. The effective use and management of the dynamically provisioned services can be achieved by using the Service Delivery Framework (SDF) proposed by TeleManagement Forum that provides a good basis for defining the whole services life cycle management and supporting infrastructure services. The paper discusses conceptual issues, basic requirements and practical suggestions for provisioning consistent security services as a part of the general e-Science infrastructure provisioning, in particular Grid and Cloud based. The proposed Security Services Lifecycle Management (SSLM) model extends the existing frameworks with additional stages such as “Reservation Session Binding” and “Registration and Synchronisation” that specifically target such security issues as the provisioned resources restoration, upgrade or migration and provide a mechanism for remote executing environment and data protection by binding them to the session context. The paper provides a short overview of the existing standards and technologies and refers to the on-going projects and experience in developing dynamic distributed security services. Yuri Demchenko, Cees T. A. M. de Laat, Diego R. López, Joan Antoni García Espín |
CloudCom | 1 |
| 2009 | Multi-domain lightpath authorization, using tokens
Leon Gommans, Yuri Demchenko, Alfred Wan, Mihai Cristea, Robert J. Meijer, Cees T. A. M. de Laat |
Future Gener. Comput. Syst. | 3 |
| 2009 | Definition and Implementation of a SAML-XACML Profile for Authorization Interoperability Across Grid Middleware in OSG and EGEE
Gabriele Garzoglio, Ian Alderman, Mine Altunay, Rachana Ananthakrishnan, Joe Bester, Keith Chadwick, Vincenzo Ciaschini, Yuri Demchenko, Andrea Ferraro, Alberto Forti, David L. Groep, Ted Hesselroth, John Hover, Oscar Koeroo, Chad La Joie, Tanya Levshina, Zach Miller, Jay Packard, Håkon Sagehaug, Valery Sergeev, Igor Sfiligoi, Neha Sharma 0001, Frank Siebenlist, Valerio Venturi, John Weigand |
J. Grid Comput. | 8 |
| 2008 | Re-thinking Grid Security ArchitectureabstractThe security models used in Grid systems today strongly bear the marks of their diverse origin. Historically retrofitted to the distributed systems they are designed to protect and control, the security model is usually limited in scope and applicability, and its implementation tailored towards a few specific deployment scenarios. A common approach towards even the "basic" elements such as authentication to resources is only now emerging, whereas for more complex issues such as community organization, integration of site access control with operating systems, cross-domain resource provisioning, or overlay community Grids ("late authentication" for pilot job frameworks or community-based virtual machines) there is no single coherent and consistent "security" view. Via this paper we aim to share some observations on current security models and solutions found in Grid architectures and deployments today and identify architectural limitations in solving complex access control and policy enforcement scenarios in distributed resource management. The paper provides a short overview of the OGSA security services and other security solutions used in Grid middleware and operations practice. However, it is becoming clear that further development in Grid requires a fresh look at the concepts, both operationally and security-wise. This paper analyses the security aspects of different types of Grids and a set of use cases that may require extended security functionality, such as dynamic security context management, and management of stateful services. Recent developments in open systems security, and revisiting basic security concepts in networking and computing including the OSI security architecture and the concepts used in the trusted computing base provide interesting examples on how some of the conceptual security problems in Grid can be addressed, and on how the shortcomings of current systems and the frequently proposed "ad-hoc" stop-gaps for what are in fact complex security manageability problems may be avoided. This paper is thus intended to initiate and stimulate the wider discussion on the concepts of Grid security, thereby setting the scene for and providing input to a Grid security taxonomy leading to a more consistent Grid security architecture. Yuri Demchenko, Cees T. A. M. de Laat, Oscar Koeroo, David L. Groep |
eScience | 1 |
| 2008 | Dynamic security context management in Grid-based applications
Yuri Demchenko, Olle Mulmo, Leon Gommans, Cees T. A. M. de Laat, Alfred Wan |
Future Gener. Comput. Syst. | 1 |
| 2007 | Using SAML and XACML for Complex Authorisation Scenarios in Dynamic Resource ProvisioningabstractThis paper presents ongoing research and current results on the development of flexible access control infrastructures for complex resource provisioning in grid-based collaborative applications and on-demand network services provisioning. The paper identifies basic resource provisioning models and specifies major requirements to authorisation (AuthZ) service infrastructure to support these models and focus on two main issues - AuthZ session support and policy expression for complex resource models. For the practical implementation, we investigate the use of two popular standards SAML and XACML for complex authorisation scenarios in dynamic resource provisioning across multiple administrative and security domains. The paper describes a proposed XML based AuthZ ticket format that is capable of supporting extended AuthZ session context. Additionally, the paper discusses what specific functionality should be added to existing grid-oriented authorization frameworks to handle dynamic domain-related security context including AuthZ session support. The paper is based on experiences gained from major grid based and grid oriented projects such as EGEE, NextGrid, Phosphorus and GigaPort research on network Yuri Demchenko, Leon Gommans, Cees T. A. M. de Laat |
ARES | 1 |
| 2007 | Security and dynamics in customer controlled virtual workspace organisationabstractThis paper proposes the security infrastructure for user-controlled Virtual Workspace Service (VWSS-UC) that comprises of three layers: trusted computing platform, secure virtualised workspace, and user aplication. The suggestions on the technology selection are provided for the first two layers: industry adopted Trusted Computing (TCG) platform, and Virtual Workspace Service (VWSS) developed in the framework of the Globus Toolkit. Solutions and implementation are proposed and discussed for the application authorisation session security context management. The paper is based on experiences gained from major Grid based projects such as EGEE, Globus Toolkit, and Phosphorus. Yuri Demchenko, Frank Siebenlist, Leon Gommans, Cees T. A. M. de Laat, David L. Groep, Oscar Koeroo |
HPDC | 1 |
| 2007 | Extending Role Based Access Control Model for Distributed Multidomain Applications
Yuri Demchenko, Leon Gommans, Cees T. A. M. de Laat |
SEC | 1 |
| 2006 | Domain Based Access Control Model for Distributed Collaborative ApplicationsabstractThis paper describes the design and development of a flexible domain-based access control infrastructure for distributed Collaborative Environments. The paper proposes extensions to classical RBAC models to address typical problems and tasks in the distributed hierarchical resource organisation that came from the practical experience in developing industry oriented virtual laboratories infrastructure, particular: hierarchical resources policy administration, user roles management, dynamic security context and authorisation session management. The paper provides implementation details on the use of XACML for finegrained access control policy definition for domain based resources and roles organisation. The paper analyses the required functionality and suggests extensions to the major service-oriented access generic framework such as Acegi, Globus Toolkit Authorisation framework, and GAAA Authorisation framework in order to support complex resource organisation and collaboration scenarios in dynamic virtualised environments. The paper is based on experiences gained from the industry funded project Collaboratory.nl and other major Grid-based and Grid-oriented projects in collaborative applications and complex resource provisioning. Yuri Demchenko, Cees T. A. M. de Laat, Leon Gommans, René van Buuren |
e-Science | 1 |
| 2006 | Using VO Concept for Managing Dynamic Security Associations
Yuri Demchenko, Leon Gommans, Cees T. A. M. de Laat |
SEC | 1 |
| 2004 | Virtual organisations in computer grids and identity management
Yuri Demchenko |
Inf. Secur. Tech. Rep. | 1 |