EUDAT & AAI. Daan Broeder MPI for Psycholinguistics

Similar documents
EUDAT. Towards a pan-european Collaborative Data Infrastructure - A Nordic Perspective? -

EUDAT. Towards a pan-european Collaborative Data Infrastructure

EUDAT. Towards a pan-european Collaborative Data Infrastructure

Data Replication: Automated move and copy of data. PRACE Advanced Training Course on Data Staging and Data Movement Helsinki, September 10 th 2013

EUDAT Training 2 nd EUDAT Conference, Rome October 28 th Introduction, Vision and Architecture. Giuseppe Fiameni CINECA Rob Baxter EPCC EUDAT members

EUDAT - Open Data Services for Research

EUDAT Data Services & Tools for Researchers and Communities. Dr. Per Öster Director, Research Infrastructures CSC IT Center for Science Ltd

EUDAT. Towards a Collaborative Data Infrastructure. Ari Lukkarinen CSC-IT Center for Science, Finland NORDUnet 2012 Oslo, 18 August 2012

EUDAT Towards a Collaborative Data Infrastructure

EUDAT. Towards a pan-european Collaborative Data Infrastructure

EUDAT. A European Collaborative Data Infrastructure. Daan Broeder The Language Archive MPI for Psycholinguistics CLARIN, DASISH, EUDAT

Data management and discovery

The EUDAT Collaborative Data Infrastructure

EUDAT Common data infrastructure

irods Security Aspects Willem Elbers CLARIN-ERIC, Netherlands

EUDAT- Towards a Global Collaborative Data Infrastructure

dcache: challenges and opportunities when growing into new communities Paul Millar on behalf of the dcache team

European Collaborative Data Infrastructure EUDAT - Training on EUDAT Principles -

Using EUDAT services to replicate, store, share, and find cultural heritage data

I data set della ricerca ed il progetto EUDAT

Data Discovery - Introduction

Management der Virtuellen Organisation DARIAH im Rahmen von Shibboleth- basierten Föderationen. 58. DFN- Betriebstagung, Berlin, 12.3.

Inge Van Nieuwerburgh OpenAIRE NOAD Belgium. Tools&Services. OpenAIRE EUDAT. can be reused under the CC BY license

EUDAT & SeaDataCloud

2. HDF AAI Meeting -- Demo Slides

DARIAH Update. 9th FIM4R Workshop. Vienna, Novemer 30, Peter Gietz, DAASI International GmbH.

ODC and future EIDA/ EPOS-S plans within EUDAT2020. Luca Trani and the EIDA Team Acknowledgements to SURFsara and the B2SAFE team

EUDAT. Towards a pan-european Collaborative Data Infrastructure. KNMI Workshop, Utrecht, Netherlands

Data Staging: Moving large amounts of data around, and moving it close to compute resources

The EGI AAI CheckIn Service

EUDAT. Towards a pan-european Collaborative Data Infrastructure. Damien Lecarpentier CSC-IT Center for Science, Finland EUDAT User Forum, Barcelona

USE CASES IN SEISMOLOGY. Alberto Michelini INGV

Data Staging and Data Movement with EUDAT. Course Introduction Helsinki 10 th -12 th September, Course Timetable TODAY

CLARIN s central infrastructure. Dieter Van Uytvanck CLARIN-PLUS Tools & Services Workshop 2 June 2016 Vienna

Data Staging: Moving large amounts of data around, and moving it close to compute resources

EOSC Services & Architecture: the EOSC-hub approach Tiziana Ferrari, Project Coordinator, EGI Founda?on

Fundamentals of Data Infrastructures

DARIAH-AAI. DASISH AAI Meeting. Nijmegen, March 9th,

Deliverable DJRA1.1. Use-Cases for Interoperable Cross- Infrastructure AAI

EUDAT and Cloud Services

EGI Check-in service. Secure and user-friendly federated authentication and authorisation

Federated Identity Management for Research Collaborations. Bob Jones IT dept CERN 29 October 2013

Options for Joining edugain. Lukas Hämmerle, SWITCH DARIAH Workshop, Köln 18 October 2013

globus online Globus Nexus Steve Tuecke Computation Institute University of Chicago and Argonne National Laboratory

irods workflows for the data management in the EUDAT pan-european infrastructure

Key Elements of Global Data Infrastructures

AAI in EGI Current status

B2FIND: EUDAT Metadata Service. Daan Broeder, et al. EUDAT Metadata Task Force

EGI federated e-infrastructure, a building block for the Open Science Commons

Shibboleth authentication for Sync & Share - Lessons learned

Coupled Computing and Data Analytics to support Science EGI Viewpoint Yannick Legré, EGI.eu Director

Authentication & Authorization systems developed for CTA

Scientific data management

EGI-InSPIRE. GridCertLib Shibboleth authentication for X.509 certificates and Grid proxies. Sergio Maffioletti

AARC Blueprint Architecture

30 Nov Dec Advanced School in High Performance and GRID Computing Concepts and Applications, ICTP, Trieste, Italy

Grid Computing. MCSN - N. Tonellotto - Distributed Enabling Platforms

INDIGO AAI An overview and status update!

European Cloud Initiative: implementation status. Augusto BURGUEÑO ARJONA European Commission DG CNECT Unit C1: e-infrastructure and Science Cloud

FeduShare Update. AuthNZ the SAML way for VOs

Introducing Shibboleth. Sebastian Rieger

The Materials Data Facility

The challenges of (non-)openness:

Introduction of Identity & Access Management Federation. Motonori Nakamura, NII Japan

Federated access to e-infrastructures worldwide

Guidelines on non-browser access

1. General requirements

EGI AAI Platform Architecture and Roadmap

NorStore. a national infrastructure for scientific data. Andreas O Jaunsen UNINETT Sigma as

B2DROP The EUDAT Personal Cloud Storage

Warm Up to Identity Protocol Soup

Goal. TeraGrid. Challenges. Federated Login to TeraGrid

INDIGO-Datacloud Identity and Access Management Service

Indiana University Research Technology and the Research Data Alliance

In Section 4 we discuss the proposed architecture and analyse how it can match the identified 2

Integrating Anonymous & Authenticated Access to VO Services. Patrick Dowler Canadian Astronomy Data Centre

B2SAFE metadata management

Federated Authentication with Web Services Clients

EUDAT Registry Overview for SAF (26/04/2012) John kennedy, Tatyana Khan

Best practices and recommendations for attribute translation from federated authentication to X.509 credentials

A national approach for storage scale-out scenarios based on irods

RCauth.eu / MasterPortal update

e-infrastructures in Horizon 2020 e-infrastructures for data and computing

Federated Services for Scientists Thursday, December 9, p.m. EST

Centrify for Dropbox Deployment Guide

Connect. Communicate. Collaborate. GN2 JRA5 update. Jürgen Rauschenbach (DFN), JRA5 team 04/02/08 Marseille. JRA5 Team

UNICORE 7 Middleware Services for Distributed and Federated Computing

SAML-Based SSO Solution

- C3Grid Stephan Kindermann, DKRZ. Martina Stockhause, MPI-M C3-Team

Authentication in the Cloud. Stefan Seelmann

Safe Replication and Data Staging

Copyright

Towards a joint service catalogue for e-infrastructure services

EUDAT-B2FIND A FAIR and Interdisciplinary Discovery Portal for Research Data

e-research Infrastructures for e-science Axel Berg SARA national HPC & e-science support center RAMIRI, June 15, 2011

Open Science Commons: A Participatory Model for the Open Science Cloud

Giovanni Lamanna LAPP - Laboratoire d'annecy-le-vieux de Physique des Particules, Université de Savoie, CNRS/IN2P3, Annecy-le-Vieux, France

Thebes, WS SAML, and Federation

Building on Existing Communities: the Virtual Astronomical Observatory (and NIST)

DSIT WP1 WP2. Federated AAI and Federated Storage Report for the Autumn 2014 All Hands Meeting

Transcription:

EUDAT & AAI Daan Broeder MPI for Psycholinguistics

Initially six research communities on Board EPOS: European Plate Observatory System CLARIN: Common Language Resources and Technology Infrastructure ENES: Service for Climate Modelling in Europe LifeWatch: Biodiversity Data and Observatories VPH: The Virtual Physiological Human INCF: International Neuroinformatics

Communities and Data Centers Identifying basic requirements Identify commonalities, common data services

EUDATs Mission Collaborative Data Infrastructure Data Generators Users User- focused func*onality, data capture & transfer, VREs Trust Data Cura*on Support Services Data discovery & naviga*on, workflow crea*on, annota*on, interpretability Common Data Services Persistent storage, iden*fica*on, authen*city, workflow execu*on, mining 4

EUDAT services Metadata Catalogue Aggregated EUDAT metadata domain. Data inventory Safe Replica6on Data curation and access optimization Data Staging Dynamic replication to HPC workspace for processing Simple Store Researcher data store (simple upload, share and access) AAI Network of trust among authentication and authorization actors PID Identity Integrity Authenticit y Loca*ons PID metadata data

EUDAT services Services under evalua6on EUDAT Box dropbox- like service easy sharing local synching Seman6c Anno checking & referencing Dynamic Data immediate handling EUDAT Box Sync file system with central storage Support collaborative work Only started thinking about AAI Dynamic Data Manage unfinished datasets: sensor data, surveys, Metadata for DD Cite / point using PIDs

What EUDAT Services need AAI? B2SHARE YouTube for scientists catering for long tail data uses its own user-store B2SAFE irods & icommands, HTTP API Data replicas stored at data-centers Many offer access through GridFTP or irods & icommands X.509 based access, certificate subject contains AUTZ attributes But this is not interesting for many communities that prefer HTTP HTTP API via OAUTH or CERTs tokens B2DROP [No Logo Yet] based on PowerFolder supporting local/ldap/ssl radius,shibboleth

Possible AAI Strategies & considerations 1. Solve everything for everyone 2. Solve many things for many people 3. Give precedence to non-it savvy community needs 4. Rely on supported software requiring minimal adaptations 5. Avoid necessary adaptations for the communities 6. Avoid need for new central DBs EUDAT initially went for 1, 5

* IdP B IdP A x.509 zoned creden*al conversion service unique user Ids, project- wise mapped to arribute based access control informa*on IdP D OpenID Ω consolidated creden*als AtP 1 AtP 2 AtP 3 Δ AuthZ Attribute Provider either community-managed or ( ) attributes provided by user s home IdP are reused *

Providing access to replica DO requires the availability of AUTZ information also! from a reliable central authority Communities want to control their own AUTZ Central AUTZ service synchronized with center/ community specific Authorization EUDAT AUTZ (XACML) center A AUTZ DO DO DO DATA center Y DATA center X

EUDAT Solutions 1 Communities use: Shib, X509, Need for a identity credential conversion to a single EUDAT identity In the FIM IDF/SAML world this requires to use of also a central user store since no unique user id is available e.g. eptid attribute Experimented with using Contrail Cloud Federation computing project ran from 2010 until Jan 2014 Homeless Web2nonWeb e.g. OAUTH, SLCS EUDAT credentials Unfortunately insufficient results Problematic necessary seeding of the contrail DB with user records AUTZ was never proved working for any EUDAT community Contrail software no longer supported

Contrail edugain or ESFRI SPFs AAI services provided by the EUDAT centers to the EUDAT communi*es EUDAT communi*es Haka federa*on DFN- AAI federa*on Contrail homeless (IdP for the homeless users) Web2nonWeb (bridge to non- web services) Database that stores everything service (CLARIN) service (ENES) service (EPOS) SIR.es federa*on management (for community memberships) REMS service (for dataset access rights)

EUDAT solution 2 Currently experimenting with using Unity Cloud Identity and Federation Management part of the UNICORE grid middleware stack Homeless Web2nonWeb e.g. SLCS (for now via contrail) EUDAT credentials Results seem better, promised: Automatic EUDAT credential creation at first login Easy promotion from homeless to external authentication Unity only solution in the making (SLCS) Supported (if necessary) as part of UNICORE stack

EUDAT solution 3 Nevertheless after the contrail experience need to be careful Perhaps simple limited but proven solutions can be considered More community centric Rely on SAML federations only Requiring eppn with homeless IdP as alternative Web2nonWeb as X509 should be delivered by those services that require it

Simpler distributed approach edugain + ESFRI SPFs Haka federa*on DFN- AAI federa*on AAI services provided by the EUDAT centers to the EUDAT communi*es Orphanage (IdP for the homeless users) Web2nonWeb (bridge to non- web services) EUDAT communi*es service (CLARIN) service (ENES) service (EPOS) SIR.es federa*on management (for community memberships) REMS service (for dataset access rights)

Thank you for your attention