EGEE-II INFSO-RI-031688 Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Service to Encrypt Biological Data on Grid.

Slides:



Advertisements
Similar presentations
Wei Lu 1, Kate Keahey 2, Tim Freeman 2, Frank Siebenlist 2 1 Indiana University, 2 Argonne National Lab
Advertisements

Enabling Grids for E-sciencE INFSO-RI GPSA grid portal for Bioinformatics, EGEE3 Athens, 20/04/ GPSA - Grid Protein Sequence Analysis on the.
E-science grid facility for Europe and Latin America A Data Access Policy based on VOMS attributes in the Secure Storage Service Diego Scardaci.
INFSO-RI Enabling Grids for E-sciencE EGEE Security Status – Biomed meeting – Valencia, January 27th, 2006 EGEE Security status.
11 DICOM Image Communication in Globus-Based Medical Grids Michal Vossberg, Thomas Tolxdorff, Associate Member, IEEE, and Dagmar Krefting Ting-Wei, Chen.
Web-based Portal for Discovery, Retrieval and Visualization of Earth Science Datasets in Grid Environment Zhenping (Jane) Liu.
INFSO-RI Enabling Grids for E-sciencE FloodGrid application Ladislav Hluchy, Viet D. Tran Institute of Informatics, SAS Slovakia.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Configuring and Maintaining EGEE Production.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks The EGEE Infrastructure and Remote Instruments.
EGEE-III INFSO-RI Enabling Grids for E-sciencE The Medical Data Manager : the components Johan Montagnat, Romain Texier, Tristan.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks The network monitoring in grid context Operations.
EGEE-Forum – May 11, 2007 Enabling Grids for E-sciencE EGEE and gLite are registered trademarks A gateway platform for Grid Nicolas.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE middleware: gLite Data Management EGEE Tutorial 23rd APAN Meeting, Manila Jan.
E-science grid facility for Europe and Latin America Using Secure Storage Service inside the EELA-2 Infrastructure Diego Scardaci INFN (Italy)
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Security Token Service Valéry Tschopp - SWITCH.
Enabling Grids for E-sciencE Introduction Data Management Jan Just Keijser Nikhef Grid Tutorial, November 2008.
Tanenbaum & Van Steen, Distributed Systems: Principles and Paradigms, 2e, (c) 2007 Prentice-Hall, Inc. All rights reserved DISTRIBUTED.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Next steps with EGEE EGEE training community.
INFSO-RI Enabling Grids for E-sciencE Biomedical applications V. Breton, CNRS-IN2P3.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks IPv6 test methodology Mathieu Goutelle (CNRS.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Status report on Application porting at SZTAKI.
INFSO-RI Enabling Grids for E-sciencE gLite Data Management and Interoperability Peter Kunszt (JRA1 DM Cluster) 2 nd EGEE Conference,
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Services for advanced workflow programming.
INFSO-RI Enabling Grids for E-sciencE EGEE Security Joni Hahkala, UH-HIP On behalf of JRA3 JRA1 AH March 22-24, 2006.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks The GILDA t-Infrastructure Roberto Barbera.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE Site Architecture Resource Center Deployment Considerations MIMOS EGEE Tutorial.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Web interface for Protein Sequence.
WP 10 ATF meeting April 8, 2002 Data Management and security requirements of biomedical applications Johan Montagnat - WP10.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks BiG: A Grid Service to Distribute Large BLAST.
INFSO-RI Enabling Grids for E-sciencE Introduction Data Management Ron Trompert SARA Grid Tutorial, September 2007.
Enabling Grids for E-sciencE EGEE-II INFSO-RI Medical Data Manager 1 Dicom retrieval : overview of the DPM One command line to retrieve a file:
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Ignacio Blanquer Vicente Hernández Damià.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Data management in LCG and EGEE David Smith.
1 Grid School Module 4: Grid Security. 2 Typical Grid Scenario Users Resources.
EGEE-II INFSO-RI Enabling Grids for E-sciencE Command Line Grid Programming Spiros Spirou Greek Application Support Team NCSR “Demokritos”
INFSO-RI Enabling Grids for E-sciencE EGEE-2 NA4 Biomed Bioinformatics in CNRS Christophe Blanchet Institute of Biology and Chemistry.
EGEE-II INFSO-RI Enabling Grids for E-sciencE Storage Accounting for Grid Environments Fabio Scibilia INFN - Catania.
EGEE-II INFSO-RI Enabling Grids for E-sciencE P-GRADE overview and introduction: workflows & parameter sweeps (Advanced features)
EGEE is a project funded by the European Union under contract IST Enabling bioinformatics applications to.
EGEE-II INFSO-RI Enabling Grids for E-sciencE Data Management cluster summary David Smith JRA1 All Hands meeting, Catania, 7 March.
INFSO-RI Enabling Grids for E-sciencE NPM Security Alistair K Phipps (NeSC) JRA4 Face To Face, CERN, Geneva.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Bioinformatics activity Christophe BLANCHET.
INFSO-RI Enabling Grids for E-sciencE University of Coimbra gLite 1.4 Data Management System Salvatore Scifo, Riccardo Bruno Test.
EGEE-II INFSO-RI Enabling Grids for E-sciencE Architecture of LHC File Catalog Valeria Ardizzone INFN Catania – EGEE-II NA3/NA4.
The EPIKH Project (Exchange Programme to advance e-Infrastructure Know-How) gLite Grid Introduction Salma Saber Electronic.
Scuola Grid INFN, Trieste, 1-12 Dic Managing Confidential Data in the gLite Middleware – The Secure Storage.
2 nd EGEE/OSG Workshop Data Management in Production Grids 2 nd of series of EGEE/OSG workshops – 1 st on security at HPDC 2006 (Paris) Goal: open discussion.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Argus: command line usage and banning Christoph.
SSL: Secure Socket Layer By: Mike Weissert. Overview Definition History & Background SSL Assurances SSL Session Problems Attacks & Defenses.
INFSO-RI Enabling Grids for E-sciencE Ákos Frohner, Ricardo Brito Da Rocha (CERN) EGEE Delegation 1.1.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Nagios Grid Monitor E. Imamagic, SRCE OAT.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Direct User Support and updates on EGEE.
INFSO-RI Enabling Grids for E-sciencE Security needs in the Medical Data Manager EGEE MWSG, March 7-8 th, 2006 Ákos Frohner on behalf.
Enabling Grids for E-sciencE University of Perugia Computational Chemistry status report EGAAP Meeting – 21 rst April 2005 Athens, Greece.
INFSO-RI Enabling Grids for E-sciencE ESR Database Access K. Ronneberger,DKRZ, Germany H. Schwichtenberg, SCAI, Germany S. Kindermann,
EGEE Data Management Services
Grid based telemedicine application
gLite Basic APIs Christos Filippidis
SFS-HTTP: Securing the Web with Self-Certifying URLs
Grid Security.
NA4 Medical Imaging Geneva, September 26, 2006 Johan Montagnat.
Cross-health enterprises Medical Data Management on the EGEE grid
Scuola Grid INFN, Martina Franca, Nov
GGF OGSA-WG, Data Use Cases Peter Kunszt Middleware Activity, Data Management Cluster EGEE is a project funded by the European.
StoRM Architecture and Daemons
Study course: “Computing clusters, grids and clouds” Andrey Y. Shevel
Encrypted Data Store, Hydra & Delegation Interface
Sindhusha Doddapaneni
GSAF Grid Storage Access Framework
Electronic Payment Security Technologies
Presentation transcript:

EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Service to Encrypt Biological Data on Grid Mollon R., Blanchet C. and Deleage G. Pôle Bioinformatique de Lyon – PBIL Institut de Biologie et de Chimie des Protéines IBCP CNRS UMR 5086 Lyon – Gerland, France

Enabling Grids for E-sciencE EGEE-II INFSO-RI Service to Encrypt Biological Data on Grid, 2 French CNRS Institute, associated to Univ. Lyon 1 –Life Science –About 160 people – –Located in Lyon, France Study of proteins in their biological context –Approaches used include : integrative cellular (cell culture, various types of microscopies) and molecular techniques, both experimental (including biocrystallography, and nuclear magnetic resonance) and theoretical (structural bioinformatics) Three main departments, bringing together 13 groups –Topics such as cancer, extracellular matrix, tissue engineering, membranes, cell transport and signalling, bioinformatics and structural biology Institute of Biology and Chemistry of Proteins

Enabling Grids for E-sciencE EGEE-II INFSO-RI Service to Encrypt Biological Data on Grid, 3 Outlines Security Bioinformatics Requirements –Data confidentiality : patient, industrial Encrypted File Management System –Key sharing between several servers –Encryption / Decryption client –Transparent access to remote file : Perroquet

Enabling Grids for E-sciencE EGEE-II INFSO-RI Service to Encrypt Biological Data on Grid, 4 Bioinformatics requirements Certificate management –For all entities (like users, services, Web portals,...) –Renew and revoke mechanisms Fine grain access to data –Access Control Lists (ACL) support –The owner can do modifications Data encryption –Long-term storage of encrypted data –Transparent (unencrypted) access for authorized users According to EGEE requirement database, DONE In Progress

Enabling Grids for E-sciencE EGEE-II INFSO-RI Service to Encrypt Biological Data on Grid, EGEE 06, Sept. 26, 2006, Geneva 5 Presentation of EncFile Encrypted File Management System on a Grid –Files are encrypted with AES algorithm and 256-bit keys  Fast encryption/decryption (~30 Mbits/s) and good security properties –Encrypted files are stored with the Grid Data Management  Authorizations are ensured by the grid mechanism (LFC) Possible thanks to proxy delegation to key servers –Mutual authentication between clients and servers –Communications are secured thanks to OpenSSL –Secure and survivable cryptographic key storage  Several keys servers which can be on different sites  M-of-N technique : Shamir's Secret Sharing Algorithm Keys are split into N shares Key reconstruction needs M of these N shares With less than M shares, no information can be deduced

Enabling Grids for E-sciencE EGEE-II INFSO-RI Service to Encrypt Biological Data on Grid, 6 EncFile: Encryption Scenario DMS eg.: biological data eg.: EGEE SE 256 bits M-of-N technique

Enabling Grids for E-sciencE EGEE-II INFSO-RI Service to Encrypt Biological Data on Grid, 7 Perroquet : File Access Forwarder Based on Parrot Software –Collaboration with D. L. Thain, Univ. Notre Dame, USA –Permits to applications to transparently access to remote files –Supports several protocols : chirp, http, ftp, gsiftp, dcap, rfio, glite, nest Added functionalities –LFN namespace  Checks authorizations with LFC server  Resolve LFN into a Gsi-FTP url  Read, write, create are supported  No GFAL support, because of local-site-only limitations of RFIO –On-the-fly encryption and decryption  Integration of the EncFile client in Perroquet

Enabling Grids for E-sciencE EGEE-II INFSO-RI Service to Encrypt Biological Data on Grid, 8 EncFile: Decryption Scenario

Enabling Grids for E-sciencE EGEE-II INFSO-RI Service to Encrypt Biological Data on Grid, 9 EncFile: Architecture AuthZ

Enabling Grids for E-sciencE EGEE-II INFSO-RI Service to Encrypt Biological Data on Grid, 10 EncFile: Performances Used file –500,000 protein sequences –~200 MB – replicated to several SEs Experiment –Copying this file locally on the used worker node C. Blanchet, R. Mollon and G. Deleage: Building an Encrypted File System on the EGEE grid: Application to Protein Sequence Analysis. IEEE Proceedings of ARES 2006, Vienna, April

Enabling Grids for E-sciencE EGEE-II INFSO-RI Service to Encrypt Biological Data on Grid, 11 Perroquet Usage Put a file on the Grid with encrypting it –perroquet -e cp /local/path/to/my/file lfn:/grid/path/to/my/file Get a encrypted file from the Grid with decrypting it –perroquet cp lfn:/grid/path/to/my/file /local/path/to/my/file Run a blast on swissprot –perroquet blastall -i my_sequence.fas -d lfn:/grid/biomed/db/swissprot/last/sprot.fas -o blast.out -p blastp

Enabling Grids for E-sciencE EGEE-II INFSO-RI Service to Encrypt Biological Data on Grid, 12 Conclusion

Enabling Grids for E-sciencE EGEE-II INFSO-RI Service to Encrypt Biological Data on Grid, 13 Perspectives Key redistribution –Counter a key server compromising –Redistribution protocol  Key reconstruction isn't needed  Decentralized protocol Verifiable secret sharing protocol –Verify the correctness of (re)distribution –Deal with fault server during (re)distribution Interface to CHIRP storage component –Integrate EncFile in Parrot system –In Collaboration with D.L. Thain (Univ. Notre Dame)

Enabling Grids for E-sciencE EGEE-II INFSO-RI Service to Encrypt Biological Data on Grid, 14 Acknowledgement  Science collaborators ● D.G. Thain (Univ. ND, US) ● Y. Denneulin (IMAG, Fr) ● Members of the EU-FP6 EGEE project  Team collaborators ● C. Blanchet ● R. Mollon (EGEE fellow) ● V. Daric (EMBRACE fellow) ● C. Combet ● G. Deléage (Team Leader) Work supported in part by projects: French ACI GriPPS (FR-GRID-PPL02-05), EU-FP6 EGEE-II (INFSO-RI ) EU-FP6 EMBRACE (LHSG-CT )