DARIAH EU AAI consideration K. Skala, D. Davidović, Z. Šojat Lisbon, 22 May 2015.

Slides:



Advertisements
Similar presentations
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
Advertisements

CLARIN AAI, Web Services Security Requirements
Federated access to e-Infrastructures worldwide
WebFTS as a first WLCG/HEP FIM pilot
SCI-BUS is supported by the FP7 Capacities Programme under contract nr RI WS-PGRADE/gUSE Supporting e-Science communities in Europe Zoltan Farkas.
EGI-Engage EGI-Engage Engaging the EGI Community towards an Open Science Commons Project Overview 9/14/2015 EGI-Engage: a project.
AARC Overview Licia Florio, David Groep 21 Jan 2015 presented by David Groep, Nikhef.
CLARIN and the Humanities Daan Broeder The Language Archive – MPI for Psycholinguistics CLARIN EU/NL Workshop on Federated Identity Management CERN, June.
Climate Sciences: Use Case and Vision Summary Philip Kershaw CEDA, RAL Space, STFC.
CLARIN Infrastructure Vision (and some real needs) Daan Broeder CLARIN EU/NL Max-Planck Institute for Psycholinguistics.
Authentication and Authorisation for Research and Collaboration Licia Florio (GÉANT) Christos Kanellopoulos (GRNET) Service orientation.
AAI WG EMI Christoph Witzig on behalf of EMI AAI WG.
WebFTS File Transfer Web Interface for FTS3 Andrea Manzi On behalf of the FTS team Workshop on Cloud Services for File Synchronisation and Sharing.
Authentication and Authorisation for Research and Collaboration Licia Florio REFEDS Meeting The AARC Project I2 Technology Exchange.
Authentication and Authorisation for Research and Collaboration Licia Florio AARC Workshop The AARC Project Brussels, 26 October.
Authentication and Authorisation for Research and Collaboration Peter Solagna Milano, AARC General meeting Current status and plans.
Authentication and Authorisation for Research and Collaboration Peter Solagna Milano, AARC General meeting Report and plans Attribute.
Authentication and Authorisation for Research and Collaboration Michał Jankowski, Maciej Brzeźniak AARC General Meeting, Milan.
Authentication and Authorisation for Research and Collaboration Peter Solagna Milano, AARC General meeting Current status and plans.
SAML to LDAP bridging developments Marcus Hardt Marcus kit.eduSteinbuch Centre for Computing (SCC) Motivation Allow linux logins,
Identity Management in DEISA/PRACE Vincent RIBAILLIER, Federated Identity Workshop, CERN, June 9 th, 2011.
Connect. Communicate. Collaborate Deploying Authorization Mechanisms for Federated Services in the eduroam architecture (DAMe)* Antonio F. Gómez-Skarmeta.
AAI Developments AAI for e-infrastructures UK T0 workshop, Milton Hill Park October 2015
HEXAA e-Science gateways with external attribute authority István Tétényi, MTA SZTAKI 21-May-2014 Co-Authors: Mr. Héder, Mihály (MTA SZTAKI); Mr. BAJNOK,
Authentication and Authorisation for Research and Collaboration Christos Kanellopoulos Open Day Event: Towards the European Open.
EUDAT receives funding from the European Union's Horizon 2020 programme - DG CONNECT e-Infrastructures. Contract No B2ACCESS LSDMA.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
A uthentication & A uthorization for R esearch & C ollaboration Pilots in SA1 Paul van Dijk, SURFnet AARC.
Networks ∙ Services ∙ People Thomas Bärecke Journée Fédération, Paris Collaboration européenne GÉANT SA5 03/07/2015 SA5 T5 team
b2access.eudat.eu B2ACCESS The simple and secure authorisation and authentication platform of EUDAT This work is licensed under the Creative.
Storing digital assets on Grid/EGI FedCloud with gLibrary Giuseppe La Rocca, INFN DARIAH ERIC.
Tutorial on Science Gateways, Roma, Riccardo Rotondo Introduction on Science Gateway Understanding access and functionalities.
European Grid Initiative AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
Networks ∙ Services ∙ People Mandeep Saini TNC15, Porto, Portugal Virtual organisation Authorisation Management Practices in Research and.
INDIGO – DataCloud WP5 introduction INFN-Bari CYFRONET RIA
AAI needs of the Distributed Computing Infrastructures - CLARIN Dieter Van Uytvanck Max Planck Institute for Psycholinguistics
INDIGO – DataCloud Security and Authorization in WP5 INFN RIA
Authentication and Authorisation for Research and Collaboration Bari, Italy Training and Outreach Authentication and Authorisation.
Storing digital assets on Grid/EGI FedCloud with gLibrary Giuseppe La Rocca, INFN DARIAH ERIC.
EGI-Engage is co-funded by the Horizon 2020 Framework Programme of the European Union under grant number DARIAH Competence Centre e-Infrastructure.
Ljubljana, 22 nd April 2015EGI DARIAH CC Kick-off meeting1 EGI DARIAH Competence Centre Project logistics and activity plan Karolj Skala, Davor Davidović.
Project Moonshot Daniel Kouřil EGI Technical Forum
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Enabling SSO capabilities in the EGI Cloud services Peter Solagna – EGI.eu.
Authentication and Authorisation for Research and Collaboration Peter Solagna, Davide Vaghetti, et al. Topics for PY2 activities.
REST API to develop application for mobile devices Mario Torrisi Dipartimento di Fisica e Astronomia – Università degli Studi.
Authentication and Authorisation for Research and Collaboration Peter Solagna, Nicolas EGI AAI integration experiences AARC Project.
Authentication and Authorisation for Research and Collaboration AARC/CORBEL Workshop for Life Sciences AAI AARC Draft Blueprint.
Web and mobile access to digital repositories Mario Torrisi National Institute of Nuclear Physics – Division of
Security in the wider world David Kelsey (STFC-RAL) GridPP37 – Ambleside 2 Sep 2016.
EGI Updates Check-in Matthew Viljoen – EGI Foundation
AAI for a Collaborative Data Infrastructure
eduTEAMS platform for collaboration Niels Van Dijk
CheckIn: the AAI platform for EGI
AAI Alignment Nicolas Liampotis (based on the work of Mikael Linden)
EGI-Engage Engaging the EGI Community towards an Open Science Commons
The AARC Project Licia Florio (GÉANT) Christos Kanellopoulos (GRNET)
The AARC Project Licia Florio AARC Coordinator GÉANT
ESA Single Sign On (SSO) and Federated Identity Management
DARIAH requirements and roadmap in EGI
EGI FedCloud in Digital Humanities
Ruđer Bošković Institute, Croatia
DARIAH Competence Centre: architecture and activity summary
Conference: Data and Life Sci +DC
AARC Blueprint Architecture and Pilots
Ruđer Bošković Institute, Croatia
The SADE mini-project of the EGI DARIAH Competence Centre
AAI Architectures – current and future
Community AAI with Check-In
AAI in EGI Status and Evolution
Check-in Identity and Access Management solution that makes it easy to secure access to services and resources.
Presentation transcript:

DARIAH EU AAI consideration K. Skala, D. Davidović, Z. Šojat Lisbon, 22 May 2015

Multi-Source Distributed Real- Time Search and Information Retrieval’ application (GWDG) Bavarian dialects dataset (AAS) Clouds and GridsFederated DARIAH resources CDSTAR JRA2.1 Federated Data New DARIAH applications and datasets (RBI, DANS) JRA2.2 Federated Cloud DARIAH Virtual Organisation ? Outreach, training, user support (all) Technologies e-Infrastructure Apps. and datasets Community ? DARIAH Competente Centre: Architecture & Activity Summary EGI Conference 2015, Lisbon, Portugal2

Services offered by DARIAH CC WS-PGRADE/gUSE: Liferay-based, generic-purpose, workflow-oriented, customizable gateway technology EGI Conference 2015, Lisbon, Portugal3 DCI Bridge: compute resource access abstraction layer, using standardized OGSA-BES (access to EGI services, EC2-based clouds, clusters) Data Avenue: data resource access abstraction layer (access to S3, SRM, iRODS, Cassandra, GSIFTP, etc.)

Use Case Bavarian dialects database dialects within the Austrian-Hungarian monarchy from the beginnings of German language to nowadays File types: text, multimedia (images, audio files etc.), primary collection data, interpreted data, secondary background data and geo-data Headwords (about 50,000 A-Z) Records (about 40,000 plants; about 70,000 in general) Aim: provide distributed repository on EGI using gLibrary Final decision later Possible extension/upgrade with other use cases

Other possible use cases (to be decided) The Quadriga System: Computational Analysis of deep semantically annotated text develop prototypical workflow for the computational analysis of historical documents Multi-Source Distributed Real-Time Search and Information Retrieval distributed real-time search engines built on-top of a big-data search and analytics platform

Current AAI status of DARIAH community/research Infrastructure To be defined after the survey process in DARIAH CC AAI related questions: Has your community/research infrastructure already used AAI solutions for their use case? Can you describe the solutions you have adopted highlighting as applicable: Technology adopted (e.g. X509, SAML Shibboleth,...) Identity Providers (IdP) federations integrated (e.g. eduGAIN) or approximate number of individual IdPs integrated Solution for homeless users (users without an insitutional IdP) Solutions to handle user attributes How do users access your online resources? (Which kind of access control did you implement to grant access to your service and resources) What do users of your resources need authentication for?

Needs and expectations from an AAI integration in the EGI infrastructure Type of IdP to be integrated (e.g. institutional IdP part of national federations and eduGAIN or non federated, social media credentials, dedicated research community catch-all IdP,...) Preferred authentication technology, and requirements for support of multiple technology and credential translation services (e.g. SAML -> X509 translation) Community level authorization/attribute based authorization to support different authorization levels for the users Web access and/or non-web access Need for delegation (e.g. execute complex workflows on behalf of the user) Support for different level of assurance credentials, and need to use the information about users with lower level of assurance credentials to limit their capability Requirements for high level of assurance credentials (e.g. to access confidential/sensitive data)

Planned AAI solutions Web-based platform Authentication and authorization available via: SAML2 (eduGAIN, HEXAA - authZ) Social media credentials (Facebook) Username/password X.509 ceredntials LDAP Access to compute/data services via: SAML assertions X.509 Username/password Public key Delegation also planned beside robot credentials