European Life Sciences Infrastructure for Biological Information www.elixir-europe.org European Life Sciences Infrastructure for Biological Information.

Slides:



Advertisements
Similar presentations
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
Advertisements

Federated Identity Management for Researchers – A quick overview from GÉANT BoF TNC May 2014 Dublin.
Resource Entitlement Management System Manne Miettinen Mikael Linden Janne Lauros CSC – IT Center for Science.
WSO2 Identity Server Road Map
Agenda Project beginnings and funding. Purpose of the federation. Federation members. Federation protocols. Special features in our federation. Pilot.
WebFTS as a first WLCG/HEP FIM pilot
ESA EO Federated Identity Management Initiatives A. Baldi ESA: M. Leonardi RHEA:
European Life Sciences Infrastructure for Biological Information ELIXIR FI for BBMRI IT Morris FIMM and THL Tommi Nyrönen.
EGI-Engage EGI-Engage Engaging the EGI Community towards an Open Science Commons Project Overview 9/14/2015 EGI-Engage: a project.
Federated Identity and the International Research Community Dr Ken Klingenstein Director, Internet2 Middleware and Security.
Federated Identity Management for HEP David Kelsey WLCG GDB 9 May 2012.
Elements of Trust Framework for Cyber Identity & Access Services CYBER TRUST FRAMEWORK Service Agreement Trust Framework Provider Identity Providers Credential.
AAI-enabled VO Platform “VO without Tears” Christoph Witzig EGI TF, Amsterdam, Sept 15, 2010.
European Life Sciences Infrastructure for Biological Information Life science community update for the 7 th Federated Identity Management.
European Life Sciences Infrastructure for Biological Information META-pipe WP6 Kick-off Lars Ailo Bongo, ELIXIR-NO.
Resource Entitlement Management System Mikael Linden CSC – IT Center for Science.
WebFTS File Transfer Web Interface for FTS3 Andrea Manzi On behalf of the FTS team Workshop on Cloud Services for File Synchronisation and Sharing.
Authentication and Authorisation for Research and Collaboration Peter Solagna Milano, AARC General meeting Current status and plans.
Authentication and Authorisation for Research and Collaboration Peter Solagna Milano, AARC General meeting Report and plans Attribute.
Authentication and Authorisation for Research and Collaboration Peter Solagna Milano, AARC General meeting Current status and plans.
European Life Sciences Infrastructure for Biological Information ELIXIR and Identity Management 2 nd Workshop on Federated Identity.
JRA1.4 Models for implementing Attribute Providers and Token Translation Services Andrea Biancini.
Federated Identity Management for HEP David Kelsey HEPiX, IHEP Beijing 18 Oct 2012.
Example Use Case for Attribute Authorities and Token Translation Services Jens Jensen, EUDAT/AARC/STFC.
AAI Developments AAI for e-infrastructures UK T0 workshop, Milton Hill Park October 2015
EResearchers Requirements ELIXIR AAI Workshop Presenter: Mikael Linden (ELIXIR AAI-TF)
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
Networks ∙ Services ∙ People Marina Adomeit FIM4R meeting Virtual Organisation Platform as a Service VOPaaS Nov 30, 2015, Austria Task Leader,
Authentication and Authorisation for Research and Collaboration Taipei Taiwan Authentication and Authorisation for Research and.
European Grid Initiative AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
European Life Sciences Infrastructure for Biological Information EGI 2015, Lisbon, 18 May 2015 Rafael C Jimenez, ELIXIR CTO ELIXIR.
European Life Sciences Infrastructure for Biological Information ELIXIR Cloud Roadmap Chairs: Steven Newhouse, EMBL-EBI & Mirek Ruda,
Case Studies in Federated Identity Management for Research Communities Ann Harding, SWITCH/GN3plus Peter Gietz, DAASI International GmbH/DARIAH Tommi Nyro.
Connect communicate collaborate Case Studies in Federated Identity Management for Research Communities Ann Harding, SWITCH/GN3plus Peter Gietz, DAASI International.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI-InSPIRE PY5 new activities Peter Solagna – EGI.eu.
European Life Sciences Infrastructure for Biological Information ELIXIR’s needs from the EOSC Steven Newhouse, EMBL-EBI Part of the.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Enabling SSO capabilities in the EGI Cloud services Peter Solagna – EGI.eu.
Authentication and Authorisation for Research and Collaboration Peter Solagna, Davide Vaghetti, et al. Topics for PY2 activities.
CERN IT Department CH-1211 Geneva 23 Switzerland t OIS Operating Systems & Information Services CERN IT Department CH-1211 Geneva 23 Switzerland.
Authentication and Authorisation for Research and Collaboration Michał Jankowski, Maciej Brzeźniak AARC General Meeting, Utrecht.
European Life Sciences Infrastructure for Biological Information European Life Sciences Infrastructure for Biological Information.
Networks ∙ Services ∙ People Marina Adomeit TNC16 Conference, Prague Towards a platform for supporting collaboration GÉANT VOPaaS
Authentication and Authorisation for Research and Collaboration Peter Solagna, Nicolas EGI AAI integration experiences AARC Project.
Authentication and Authorisation for Research and Collaboration AARC/CORBEL Workshop for Life Sciences AAI AARC Draft Blueprint.
L’Oreal USA RSA Access Manager and Federated Identity Manager Kick-Off Meeting March 21 st, 2011.
ELIXIR AAI Michal Procházka, Mikael Linden, EGI VC 15 March 2016.
Security in the wider world David Kelsey (STFC-RAL) GridPP37 – Ambleside 2 Sep 2016.
WLCG Update Hannah Short, CERN Computer Security.
RCauth.eu CILogon-like service in EGI and the EOSC
Diego Scardaci EGI Technical Outreach Expert
EGI Updates Check-in Matthew Viljoen – EGI Foundation
AARC Update What’s been happening in AARC which matters for GÉANT
User Community Driven Development in Trust and Identity
MMG: from proof-of-concept to production services at scale (part II)
Identity Federations - Overview
AAI Alignment Nicolas Liampotis (based on the work of Mikael Linden)
Check-in Nicolas Liampotis
Mirjam van Daalen:: Paul Scherrer Institut
THE STEPS TO MANAGE THE GRID
ELIXIR Safeguarding the results of life science research in Europe
Pilots in AARC Arnout Terpstra (AARC2) / Paul van Dijk (AARC1)
AARC Blueprint Architecture and Pilots
Common Authentication and Authorisation Service for Life Science Research Mikael Linden, ELIXIR Finland.
AAI Architectures – current and future
Community AAI with Check-In
AAI in EGI Status and Evolution
Resource Entitlement Management System
Resource Entitlement Management System
Check-in Identity and Access Management solution that makes it easy to secure access to services and resources.
Common Authentication and Authorisation Service for Life Science Research Mikael Linden, ELIXIR Finland.
Presentation transcript:

European Life Sciences Infrastructure for Biological Information European Life Sciences Infrastructure for Biological Information ELIXIR AAI Miroslav Ruda, on behalf of 1

Terms and concepts Identity – there is a researcher called Authentication – has logged in using his password Authorisation Based on his membership in ELIXIR, can use ELIXIR Based on his membership in „ELIXIR HoN“ group, can access the Head of Nodes Wiki Based on his Data Access Application approved by the appropriate Data Access Committee, can access dataset EGAD

ELIXIR TF-AAI Use cases (Finished)Finished  Requirements (stabile draft)stabile draft  Design (first draft)first draft  Technical Use Cases document – Prioritization with ELIXIR -EXCELERATE user groups  Small pilots in spring 2015  Deployment in ELIXIR Excelerate project 3

ELIXIR AAI design (draft) 4 ELIXIR AAI External authentication (e-infrastructures) Relying services eduGAIN IdPsCommon IdPs ELIXIR Proxy IdP ELIXIR Directory Bona fide management Dataset authorisation management Group/role management Credential translation EGAwiki CloudIntranet … Data archive …… Attribute self-management

ELIXIR identity 5 ELIXIR AAI External authentication (e-infrastructures) Relying services eduGAIN IdPsCommon IdPs ELIXIR Proxy IdP ELIXIR Directory Bona fide management Dataset authorisation management Group/role management Credential translation EGAwiki CloudIntranet … Data archive …… Attribute self-management Each user has one ELIXIR identity e.g. ELIXIR Proxy maps external authentication providers to it e.g. (eduGAIN) e.g. (Google) e.g (ORCID) Also local username/password possible Each user has one ELIXIR identity e.g. ELIXIR Proxy maps external authentication providers to it e.g. (eduGAIN) e.g. (Google) e.g (ORCID) Also local username/password possible

Step-up authentication 6 ELIXIR AAI External authentication (e-infrastructures) Relying services eduGAIN IdPsCommon IdPs ELIXIR Proxy IdP Step-up authentication wiki Human data External authentication: Authentication with password Less sensitive services: password enough More sensitive service: Step-up authentication server asks for second factor (e.g. one-time password by SMS) More sensitive service: Step-up authentication server asks for second factor (e.g. one-time password by SMS)

Technical Use Cases Basic Technical Use Cases defined by AAI, Cloud and Data TFs Workshop in Amsterdam 12-13/3/15 – 45 participants: Elixir, e-Infrastructure & Other Service Providers – Discuss requirements of the Scientific Use Cases Initial Prioritisation and Grouping Analysis – 0: Federated ID, Other ID – 1: Elixir ID – 2: Credential Translation, Group/Attribute Management, Endorsed Personal Data Attributes

AAI milestones in ELIXIR-Excelerate EXCELERATE Milestone 4.1: (M12) Demonstrator I. Some ELIXIR Technical Services are operating and are usable to support aspects of the ELIXIR-Excelerate Use Cases. ELIXIR Identity established based on fedeated Identity Credential translation Bona fide researcher qualification management EXCELERATE Milestone 4.2 (M24) Demonstrator II. Most ELIXIR Technical Services operating and in more robust and sustained manner and capable of supporting most aspects of the ELIXIR-Excelerate Use Cases. group/attribute management, endorsed attribute Other external Identity 8

Pilot implementation Two pilots/use-cases Intranet usage – access to project documents, including group management Connect EGA archive to authorized Cloud services Reliable and fast enough data transfer from archive to Cloud storage Cloud authentication protocol uses ELIXIR AAI Provide a secure protocol for Cloud users to access EGA datasets based on DAC permissions Prototype Cloud VM data access rules that comply to EGA access regime. Tools, dependencies EduGAIN IdPs + Google/ORCID ProxyIdP - SURF ELIXIR directory, group management - Perun DAC - REMS Several tools discussed for credential translation (SAML2 to X.509 certificates, Kerberos...) 9