Federated Identity Management for Research Collaborations. Bob Jones IT dept CERN 29 October 2013

Similar documents
Helix Nebula The Science Cloud

Helix Nebula Science Cloud Pre-Commercial Procurement pilot. 9 March 2016 Bob Jones, CERN

IT Challenges and Initiatives in Scientific Research

Helix Nebula Science Cloud Pre-Commercial Procurement pilot. 5 April 2016 Bob Jones, CERN

e-infrastructure for the 21st Century - one year later

EUDAT- Towards a Global Collaborative Data Infrastructure

European Cloud Initiative: implementation status. Augusto BURGUEÑO ARJONA European Commission DG CNECT Unit C1: e-infrastructure and Science Cloud

Pre-Commercial Procurement project - HNSciCloud. 20 January 2015 Bob Jones, CERN

Security Incident Response Trust Framework for Federated Identity (Sir-T-Fi) David Kelsey (STFC-RAL) REFEDS, Indianapolis 26 Oct 2014

EUDAT Towards a Collaborative Data Infrastructure

AARC. Christos Kanellopoulos AARC Architecture WP Leader GRNET. Authentication and Authorisation for Research and Collaboration

The Photon and Neutron Data Initiative PaN-data

WP3: Policy and Best Practice Harmonisation

European Open Science Cloud

Helix Nebula, the Science Cloud

The EUDAT Collaborative Data Infrastructure

Overview of the European Open Science Cloud. Jan Wiebelitz e-irg support programme

Giovanni Lamanna LAPP - Laboratoire d'annecy-le-vieux de Physique des Particules, Université de Savoie, CNRS/IN2P3, Annecy-le-Vieux, France

WP JRA1: Architectures for an integrated and interoperable AAI

EUDAT. Towards a pan-european Collaborative Data Infrastructure

AARC Overview. Licia Florio, David Groep. 21 Jan presented by David Groep, Nikhef.

Striving for efficiency

Cyberinfrastructure Framework for 21st Century Science & Engineering (CIF21)

e-infrastructures in Horizon 2020 e-infrastructures for data and computing

"drawing from the experience of Helix Nebula: collaboration between private sector and data providers in the scientific domain.

Helix Nebula, the Science Cloud

ESFRI Strategic Roadmap & RI Long-term sustainability an EC overview

Indiana University Research Technology and the Research Data Alliance

EUDAT. Towards a pan-european Collaborative Data Infrastructure

Developing a social science data platform. Ron Dekker Director CESSDA

Research Infrastructures in Horizon 2020

EUDAT - Open Data Services for Research

EGI federated e-infrastructure, a building block for the Open Science Commons

EUDAT. A European Collaborative Data Infrastructure. Daan Broeder The Language Archive MPI for Psycholinguistics CLARIN, DASISH, EUDAT

Open Science Commons: A Participatory Model for the Open Science Cloud

EUDAT and Cloud Services

Progress towards the EOSC

Conferenza GARR Moving Forward to deliver an «EOSC in Practice» by 2018

EUDAT. Towards a pan-european Collaborative Data Infrastructure

in Horizon 2020 Philippe Froissard European Commission DG Research & Innovation Research Infrastructures

Research Infrastructures for All You could be Next! e-infrastructures - WP

Overview of the CRISP proposal

FREYA Connected Open Identifiers for Discovery, Access and Use of Research Resources

The challenges of (non-)openness:

High Performance Computing from an EU perspective

Diamond Moonshot Pilot Participation

EUDAT & SeaDataCloud

EUDAT Data Services & Tools for Researchers and Communities. Dr. Per Öster Director, Research Infrastructures CSC IT Center for Science Ltd

Why CERIF? Keith G Jeffery Scientific Coordinator ERCIM Anne Assserson eurocris. Keith G Jeffery SDSVoc Workshop Amsterdam

Guide to e-infrastructure Requirements for European Research Infrastructures

Research Infrastructures for Robotics

EUDAT Common data infrastructure

Data Replication: Automated move and copy of data. PRACE Advanced Training Course on Data Staging and Data Movement Helsinki, September 10 th 2013

Supporting European e-infrastructure service providers to join the European Open Science Cloud

e-infrastructure: objectives and strategy in FP7

Using EUDAT services to replicate, store, share, and find cultural heritage data

European Open Science Cloud Implementation roadmap: translating the vision into practice. September 2018

ACCI Recommendations on Long Term Cyberinfrastructure Issues: Building Future Development

GATE: Big Data for Smart Society Dessislava Petrova-Antonova Sofia University St. Kliment Ohridski Faculty of Mathematics and Informatics

CZECH REPUBLIC IN THE EOSC ARENA

Coupled Computing and Data Analytics to support Science EGI Viewpoint Yannick Legré, EGI.eu Director

Data Discovery - Introduction

Preparing for High-Luminosity LHC. Bob Jones CERN Bob.Jones <at> cern.ch

ESFRI WORKSHOP ON RIs AND EOSC

EUDAT & AAI. Daan Broeder MPI for Psycholinguistics

Towards FAIRness: some reflections from an Earth Science perspective

EGI Strategy Enabling collaborative data- and compute-intensive science

EPOS a long term integration plan of research infrastructures for solid Earth Science in Europe

A European Vision and Plan for a Common Grid Infrastructure

1. Publishable Summary

Mobile Connect Driving Global Economic Growth Through Secure Mobile Identity

towards a federated infrastructure enabling integrated life science research

Review of OSI Report Developing the UK s e-infrastructure for Science and Innovation

e-infrastructures in FP7 INFO DAY - Paris

Global Data Sharing The Research Data Alliance

Federal-State Connections: Opportunities for Coordination and Collaboration

Digital Single Market Technologies and Public Service Modernisation Package -DSM. Grazyna Wojcieszko DG CONNECT

GSCB-Workshop on Ground Segment Evolution Strategy

Storage Virtualization. Eric Yen Academia Sinica Grid Computing Centre (ASGC) Taiwan

AAI in EGI Current status

Can R&E federations trust Research Infrastructures? - The Snctfi Trust Framework

The EOSC A personal vision (supported by some facts)

Federated Identities and Services: the CHAIN-REDS vision

On the EGI Operational Level Agreement Framework

Deliverable DJRA1.1. Use-Cases for Interoperable Cross- Infrastructure AAI

Cybersecurity ecosystem and TDL Antonio F. Skarmeta

From vision to action. European Open Science Cloud (EOSC)

e-infrastructures in FP7: Call 7 (WP 2010)

EPOS: European Plate Observing System

AARC Blueprint Architecture

2. HDF AAI Meeting -- Demo Slides

Scalable Negotiator for a Community Trust Framework in Federated Infrastructures (Snctfi)

21ST century enterprise. HCL Technologies Presents. Roadmap for Data Center Transformation

INFORMATION TECHNOLOGY ONE-YEAR PLAN

Paving the Rocky Road Toward Open and FAIR in the Field Sciences

eidas cross-sector interoperability

EU Research for Secure Societies

DARIAH-AAI. DASISH AAI Meeting. Nijmegen, March 9th,

EUDAT Training 2 nd EUDAT Conference, Rome October 28 th Introduction, Vision and Architecture. Giuseppe Fiameni CINECA Rob Baxter EPCC EUDAT members

Harmonisation of Digital Markets in the EaP. Vassilis Kopanas European Commission, DG CONNECT

Transcription:

Federated Identity Management for Research Collaborations Bob Jones IT dept CERN 29 October 2013

CERN ILL EFDA E. XFEL EIROforum EMBL ESRF ESA Bob Jones (CERN) October 2013 ESO CERN EFDA EMBL ESA ESO ESRF European XFEL ILL

FIM 4 R workshops STFC Nov 11 ASGC Feb 12 Asia MPI Jun 12 Social S & Humanities PSI Mar 13 Photon/ Neutron facilities CSC Oct 13 BioMedical Science CERN Jun 11 HEP Climate https://indico.cern.ch/event/129364 https://indico.cern.ch/event/157486 https://indico.cern.ch/event/177418 http://www.clarin.eu/events/3501 http://indico.psi.ch/event/2230 https://refeds.org/meetings/oct13/ Bob Jones (CERN) Oct 2013

Requirements from the research communities Important use cases Common vision across these communities Key stages of a roadmap Set of recommendations https://cdsweb.cern.ch/record/1442597/files/cern-open-2012-006.pdf Authors: Daan Broeder, Bob Jones, David Kelsey, Philip Kershaw, Stefan Lüders, Andrew Lyall, Tommi Nyrönen, Romain Wartel, Heinz J Weyer Bob Jones (CERN) March 2013

The FIM 4 R Vision A commonpolicy and trust frameworkfor Identity Management based on existingstructures and federations either presently in use by or available to the communities. This framework must provide researchers with unique electronic identities authenticated in multiple administrative domains and acrossnational boundaries that can be used together with community defined attributes to authorize access to digital resources. Bob Jones (CERN) October 2013

Prioritisationof FIM 4 R requirements User friendliness (high) Support for citizen scientists and researchers without formal association to research labs or univ Browser & non-browser federated access (high) Bridging communities (medium) Bridging is a central issue with an efficient mapping of the respective attributes Multiple technologies with translators including dynamic issue of credentials (medium) Implementations based on open stds and sustainable with compatible licenses (high) Different Levels of Assurance with provenance (high) Credentials need to include the provenance of the level under which it was issued Authorisation under community and/or facility control (high) Well defined semantically harmonised attributes (medium) Flexible and scalable IdP attribute release policy (medium) Bi-lateral negotiations between all SPs and all IdPs is not a scalable solution Attributes must be able to cross national borders (high) Data protection considerations must allow this to happen. Attribute aggregation for authorisation (medium) Attributes need to be aggregated from different sources of authority including federated IdPs and community-based attribute authorities. Privacy and data protection addressed with community-wide individual ids (medium)

Technologies being piloted by research communities Bob Jones (CERN) October 2013

Status of implementation 1st wave: ILL, ESRF, PSI online since August 2013 2 nd wave: DESY, ISIS, Diamond, HZB, Ellettra (Nov 2013 Jan 2014) Full deployment end of March 2014 FIM4R Helsinki, 2.10.2013 M van Daalen, PSI 8

Why to bridge? Creating a new account is often criticized FIM4R Helsinki, 2.10.2013 B. Abt, PSI 9

A Vision for a European e Infrastructure for the 21st Century Sustainable - RIs currently in construction (FAIR, XFEL, ELIXIR, EPOS, ESS, SKA, ITER, HiLHC and upgrades to ILL and ESRF etc.), need to be convinced that e-infrastructure will exist and continue to evolve throughout their construction and operation phases if they are to take the risk and invest in its creation & exploitation Inclusive - Need an e-infrastructure that supports the needs of the whole European research community, including the long tail of science, and interoperate with other regions Flexible - Cannot be a one-size-fits-all solution Integrated - Coherent set of services and tools must be available to meet the specific needs of each community Innovative - Essential that European industry engages with the scientific community to build and provide such services User driven - The user community should have a strong voice in the governance of the e- Infrastructure See https://cds.cern.ch/record/1550136/files/cern-open-2013-018.pdf CERN EFDA EMBL ESA ESO ESRF European XFEL ILL

What do we have already? Existing European e-infrastructure long-term projects GEANT, EGI, PRACE Many pathfinder initiatives have prototyped aspects of what will be needed in the future Includes much of the work in the existing e-infrastructure projects but also projects such as EUDAT, Helix Nebula, OpenAIRE+, etc Thematic projects such as BioMedBridges/ CRISP/ DASISH/ ENVRI, as well as Transplant, VERCE, Genesi- DEC and many others CERN EFDA EMBL ESA ESO ESRF European XFEL ILL

How can we create e-infrastructures that overcome fragmentation? Fragmentation of users (big science vs. long tail) Fragmentation of infrastructure (not integrated services) Common platform (e-infrastructure commons) with 3 integrated areas International network, authorization & authentication, persistent digital identifiers small number of facilities to provide cloud and data services of general and widespread usage Software services and tools to provide value-added abilities to the research communities, in a managed repository Need a data continuum - linking the different stages of the data lifecycle, from raw data to publication, and compute services to process this data CERN EFDA EMBL ESA ESO ESRF European XFEL ILL

ESFRI Cluster projects Bob Jones (CERN) October 2013

Cross-Disciplinary Challenges A matrix showing the interest in common topics for the four cluster initiatives Data identity Data identity continuum Software identity Concept identity User identity management Common data standards and formats Service discovery Service market places Integrated data access and discovery Data storage facilities Data curation Privacy and security Volatile data management User Community Body Semantic annotations and bridging Reference models Education & training CRISP Bob Jones (CERN) October 2013 ENVRI DASISH BioMed

A European cloud computing partnership: big science teams up with big business Strategic Plan Establish multi-tenant, multi-provider cloud infrastructure To support the computing capacity needs for the ATLAS experiment Setting up a new service to simplify analysis of large genomes, for a deeper insight into evolution and biodiversity To create an Earth Observation platform, focusing on earthquake and volcano research Identify and adopt policies for trust, security and privacy Create governance structure Define funding schemes Adopters http://www.helix-nebula.eu contact@helix-nebula.eu 15 @HelixNebulaSC HelixNebula.TheScienceCloud

Research Infrastructures need a common AAI service Technology is not the problem! Risk Analysis - implications of having a malicious SP in a federation Traceability - identifying the cause of any security incident Security Incident Response including all IdPs and SPs Transparency -essential to gain the trust of the users and service providers Reliability and Resilience - of the framework services Smooth Transition -of the existing production systems to a federated identity management model Easy integration with local SP environment -SPs will want to support multiple means of authentication Specific requirements - from some communities Bob Jones (CERN) October 2013

Next steps FIM4R is proposing to establish an interest group within RDA Ensure interaction with USA and Australia Hopefully to part of RDA event in Dublin in March 2014 7 th FIM4R workshop to be hosted by ESA in Frascati in April 2014 Bob Jones (CERN) October 2013

Summary The Research Communities have Highlighted identity mgmt as a common service Aligned their basic requirements Undertaken a series of prototypes/pilots with providers Confirmed that suitable technologies are available But the real issue is to establish policiesand networks of trust between users, SPs and IdPs We need a common federated identity management service for the whole of the e-infrastructure Bob Jones (CERN) October 2013