EUDAT: Towards a pan-European Collaborative Data Infrastructure
Federated Identity Management and Access Control
Mark van de Sanden SARA, The Netherlands Terena VAMP workshop Utrecht, 6-7 September 2012
EUDAT: Towards a pan-European Collaborative Data Infrastructure - - PowerPoint PPT Presentation
EUDAT: Towards a pan-European Collaborative Data Infrastructure Federated Identity Management and Access Control Mark van de Sanden SARA, The Netherlands Terena VAMP workshop Utrecht, 6-7 September 2012 Outline Project Core Services
Mark van de Sanden SARA, The Netherlands Terena VAMP workshop Utrecht, 6-7 September 2012
2
3
4
5
6
7
8
9
10
11
Dynamic replication to HPC workspace for processing
Service SR DR MD SSS PID AAI Community CLARIN X + X X + X ENES X X X + X EPOS X X X X
12 EPOS X X X X VPH X X X X LifeWatch X + X + + X
Objective: Enable communities to perform (HPC) computations on the replicated data Key benefits: Access to large computing facilities Description: This service will allow the EUDAT communities to dynamically replicate subsets of their data stored in EUDAT to HPC machine workspaces for processing.
EUDAT Storage HPC Facility
CINECA
Community Storage
EPOS
1 3 2
13
processing. Differences with the safe replication scenario:
replicated data are discarded when the analysis application ends; Persistent Identifier (PID) references are not applied to replicated data into HPC workspaces; Users initiate the process of replicating data while in the safe replication scenario data are replicated automatically on a policy basis.
Technologies: GridFTP, Griffin, gTransfer, Globus Online, iRODS
EUDAT Storage HPC Facility
SARA
HPC Facility
PRACE
PID
3 4 2
EUDAT is one of the first multi scientific domain project to tackle the data deluge Objective: Provide common data services with a working AAI system in a federated scenario Have to work with many different identity domains: community domains, federated NRENs, e-infrastucture (EGI, PRACE, eduGAIN), local Institutions, OpenID providers, … 14 Potential user base ranges from the current core communities (>10k) to all scientists in EU and beyond. Technologies: Oauth2, OpenID, RADIUS, SAML2, X.509, XACML, etc. Access via Web based, command line, portals and/or via workflows while maintaining access rights and uphold trust and privacy Partners and communities are from across EU countries, have to coop with differences in legislation
Make use of existing solutions, services and policy frameworks, avoid setting up your own AAI. Distinguish between IdP and AtP providers, whereas AtP are preferably managed by communities. Make use of Credential Conversion or Security
15
Make use of Credential Conversion or Security Token Service technologies, evaluating Contrail, EMI STS and GEMBUS STS Limit the technologies with which the data centers have to coop with, piloting with Shibbolizing services Integration with Community Portals and evaluating the use of Short Lived Certificates. What about homeless and citizen scientists?
16