Umbrella AAI Photon / Neutron community

Slides:



Advertisements
Similar presentations
4th workshop, federated identity systems, Nymegen June 21/22, 2012Heinz J Weyer, PSI 1 1 Federated Identity and the Photon / Neutron Community.
Advertisements

Lousy Introduction into SWITCHaai
Federated Identity Management for Researchers – A quick overview from GÉANT BoF TNC May 2014 Dublin.
ECM27, Bergen DDD Workshop August 6, 2012Heinz J Weyer, PSI 1 1 ECM27 Workshop on Data Diffraction Deposition.
2006 © SWITCH Authentication and Authorization Infrastructures in e-Science (and the role of NRENs) Christoph Witzig SWITCH e-IRG, Helsinki, Oct 4, 2006.
FIM-ig Federated Identity Management Interest Group.
Umbrella Federated Identity Management Workshop, Taipei, February 27, 2012Heinz J Weyer, PSI 1 1 Umbrella for Photon / Neutron Community.
Umbrella PaN-data ODI Kickoff meeting, STFC November 3/4, 2011Heinz J Weyer, PSI 1 1 PaN-data ODI WP3 User AAA Service (Umbrella System)
ESUO Meeting ALBA Umbrella AAI for Photon / Neutron Community M van Daalen 1 Mirjam van Daalen, Heinz Weyer, Björn Abt.
FIM-related activities and issues being discussed in Japan 1.GEO Grid Yoshio Tanaka (AIST) 2.HPCI, GakuNin Eisaku Sakane, Kento Aida (NII)
NMI3 Meeting Umbrella AAI for Photon / Neutron Community M van Daalen 1 Mirjam van Daalen, Heinz Weyer, Björn Abt.
AAI WG EMI Christoph Witzig on behalf of EMI AAI WG.
CALIPSO kick off ; Elettra Umbrella AAI for Photon / Neutron Community M van Daalen 1 Mirjam van Daalen, Heinz Weyer, Björn Abt.
Jamie Hall (ILL). SciencePAD Persistent Identifiers Workshop PANData Software Catalogue January 30th 2013 Jamie Hall Developer IT Services, Institut Laue-Langevin.
ESFRI & e-Infrastructure Collaborations, EGEE’09 Krzysztof Wrona September 21 st, 2009 European XFEL.
Connect. Communicate. Collaborate AAI scenario: How AutoBAHN system will use the eduGAIN federation for Authentication and Authorization Simon Muyal,
Connect. Communicate. Collaborate Deploying Authorization Mechanisms for Federated Services in the eduroam architecture (DAMe)* Antonio F. Gómez-Skarmeta.
CRISP 2 nd annual meeting PSI; WP 16 CRISP M van Daalen, PSI 1 Mirjam van Daalen, Heinz Weyer, Björn Abt.
PaN-Data Meeting, October 4/5, 2010, Berlin Gen H.J. Weyer Overview Umbrella Project  Pan-EU Authentication  Proposal handling (prototype)  Coaching.
EGI Technical Forum 2010, September 14, 2010, Amsterdam H.J. Weyer TOC Photon Facilities and Authentication  The environment  General boundary conditions.
Networks ∙ Services ∙ People Thomas Bärecke Journée Fédération, Paris Collaboration européenne GÉANT SA5 03/07/2015 SA5 T5 team
CRISP Topic Meeting ESRF, WP 16 CRISP M van Daalen, PSI 1 Mirjam van Daalen.
Connect communicate collaborate Trust & Identity EC meets GÉANT 19 June 2014 Brussels Valter Nordh, NORDUnet Federation as a Service Task Leader Trust.
b2access.eudat.eu B2ACCESS The simple and secure authorisation and authentication platform of EUDAT This work is licensed under the Creative.
Networks ∙ Services ∙ People Marina Adomeit FIM4R meeting Virtual Organisation Platform as a Service VOPaaS Nov 30, 2015, Austria Task Leader,
Thomas Gutberlet HZB User Coordination NMI3-II Neutron scattering and Muon spectroscopy Integrated Initiative WP5 Integrated User Access.
AAI needs of the Distributed Computing Infrastructures - CLARIN Dieter Van Uytvanck Max Planck Institute for Psycholinguistics
Case Studies in Federated Identity Management for Research Communities Ann Harding, SWITCH/GN3plus Peter Gietz, DAASI International GmbH/DARIAH Tommi Nyro.
Connect communicate collaborate Case Studies in Federated Identity Management for Research Communities Ann Harding, SWITCH/GN3plus Peter Gietz, DAASI International.
7 th Umbrella Harmonisation Meeting Zürich Airport M van Daalen, PSI 1 Retrospection Umbrella.
CRISP WP18, High-speed data recording Krzysztof Wrona, European XFEL PSI, 18 March 2013.
Networks ∙ Services ∙ People Licia Florio TNC, Lisbon Consuming identities across e- Infrastructures 16 June 2015 PDO GÈANT.
E-infrastructure requirements from the ESFRI Physics, Astronomy and Analytical Facilities cluster Provisional material based on outcome of workshop held.
Networks ∙ Services ∙ People Marina Adomeit TNC16 Conference, Prague Towards a platform for supporting collaboration GÉANT VOPaaS
The Umbrella Project Authentication The minimum user information possible is stored centrally to avoid Data Protection issues. The Authentication is done.
Authentication and Authorisation for Research and Collaboration Taipei - Taiwan Mechanisms of Interfederation 13th March 2016 Alessandra.
CERN IT Department CH-1211 Genève 23 Switzerland Federated identity system for scientific collaborations Summary of user requirements session.
Web SSO with Cloud Resources using AD Federation Services
Introduction to AAI Services
Status Umbrella ID Mirjam van Daalen.
Status Umbrella ID Mirjam van Daalen.
Umbrella ID Status Mirjam van Daalen.
Icat January st Jan 2013 Jamie Hall / Jean-François Perrin ILL IT services - 4th Harmonisation Meeting at XFEL/DESY.
AAI for a Collaborative Data Infrastructure
Budget JRA2 Beneficiaries Description TOT Costs incl travel
User Community Driven Development in Trust and Identity
Introduction the IT and DM Topic
7th Umbrella Harmonisation Meeting
Status Umbrella AAI Photon / Neutron community
Case Studies in Federated Identity Management for Research Communities
Umbrella Bridging Björn Abt.
European photon/neutron facilities The User Umbrella System, Status and Future 1.
Future Ideas: Federation and Integration
CRISP WP16 F2F Meeting, RAL Sep 27
Federated Identity Management for Researchers (FIM4R)
Umbrella Roadmap & CALIPSOplus
Mirjam van Daalen:: Paul Scherrer Institut
Umbrella AAI Photon / Neutron community
Pandata Service Verification
PaNdata ODI WP3 User Catalogue and AAI Service
Umbrella Implementation at the ESRF and affiliation database project
WP18, High-speed data recording
Mirjam van Daalen, (Stephan Egli, Derek Feichtinger) :: Paul Scherrer Institut Status Report PSI PaNDaaS2 meeting Grenoble 6 – 7 July 2016.
ESA Single Sign On (SSO) and Federated Identity Management
AAI Architectures – current and future
Mirjam van Daalen, (Stephan Egli, Derek Feichtinger) :: Paul Scherrer Institut Status Report PSI PaNDaaS2 meeting Grenoble 12 – 13 December 2016.
Status JRA2 WP24 Demonstrator of a Photon Science Analysis Service (DaaS) Mirjam van Daalen 6/28/2019 Mirjam van Daalen PSI.
WP6 – EOSC integration J-F. Perrin (ILL) 15th Jan 2019
Check-in Identity and Access Management solution that makes it easy to secure access to services and resources.
Umbrella ID Federated Identity for PaN facilities
Presentation transcript:

Umbrella AAI Photon / Neutron community Mirjam van Daalen

Contents todays presentation Part 1: Intro Umbrella Part 1: Umbrella Status Part 2: Bridging of Umbrella to other federations

Umbrella is the Authentication and Authorisation Infrastructure (AAI) concept for the Photon and Neutron community It is the first time that such a kind of IT environment is offered: European wide Community overlapping Shared between different EU projects

Future user operation at large scale facilities What are the present and upcoming user needs? 40% of the users do experiments at different facilities, transfacility access for users. Acces to and management of experimental data (also within the collaboration). Online entry mode: remote experiment access Access to efficient data analysis tools. Minimal administration load for users. Remote file access. Unified acces. Same method to acces tools and identify At the end all this needs a unique persistent user identification to have unified access to these tools.

Umbrella is part of several FP7 projects: EuroFEL- ESFRI project Free Electron Lasers of Europe PaNData-Europe, PaNData ODI- FP7 projects CRISP – Cluster project of different ESFRI projects CALIPSO – I3 synchrotron community NMI3 - I3 neutron community BioStruct-X – renewal of I3 ELISA FP7 (only struct. biol) Instruct – ESFRI project

How does it work? User User Office 1 XXX User Office 2 ILL User ESRF User Office 4 PSI

Umbrella Characteristics Overview

Umbrella Characteristics Umbrella is the basis for various user services under development Info & service portal European proposal support (NMI3 & CALIPSO) Remote experiment access Remote file access Metadata catalogue (iCAT) Without a unique identifier it will not be possible to have unified access and work with these tools. Unified acces. Same method to acces tools and identify

Umbrella Characteristics Concept Unique persistent Identifier on EU scale independent of home institution life time account account owned by the user single sign-on no possibility for cross-facility information pull waterproof but slim data protection system

Umbrella Characteristics Incorporate confidentiality aspects high competition, especially structural biology time-window-structured access to experiments and data. Authorisation is delegated to the systems participating in Umbrella for highest grade of independence in heterogeneous environments no complicated trust relationships

Umbrella Characteristics Rely on existing local user office structure Great experience Do It Yourself operation by the user Users: manage their personal entries User offices: supervising; manage authorizations Principal investigators: have responsibility for their teams and can handle authorization within their group Base system on professional authentication standard Shibboleth, federated Single-Sign-On System (SAML), widely used Special photon / neutron user federation Supervising by the local User Offices

Roadmap for Umbrella deployment Project end PaNdata 31.03.2014 Project end CRISP 30.09.2014 MoU between partners

Status of implementation 1st wave: ILL, ESRF, PSI online since August 2013 2nd wave: DESY, ISIS, Diamond, HZB, Ellettra (Nov 2013 – Jan 2014) Full deployment end of March 2014

Status of Service Provider deployment 1st wave Facility Status SP installed WUO adapted Production OK

x Deployment planning Umbrella Umbrella Deployment CRISP PaNData NMI3 CALYPSO Others ESRF implemented x ILL DESY Fall 2013 Diamond ISIS Elettra Planned until end of PaNdata MaxLab HZB Not clear yet Soleil ? Alba EUXFEL Planned at start of user operation ESS GSI PSI Summer 2013 Biostruct-X FMI Basel

Umbrella Status In operation In progress Basic Umbrella https://umbrellaid.org/euu/ Geo DNS (server Umbrella distributed between different facilities) In progress Access to Umbrella via EduGain (Geant 3+, Switch) Login with account home institution (Universities etc.) Link of Umbrella to Moonshot (Geant 3+ , non web based access) Remote experiment access Access to iCAT metadata catalogue via Umbrella

Bridging of Umbrella to other federations Part 1: Why to bridge? Part 2: What to bridge? Part 3: How to bridge?

Part 1: Why to bridge? From the previous FIM 4R meetings it became very clear: The various research communities have such different needs that one FIM solution for all is impossible. We want to offer the users a homogeneous efficient easy to use platform Therefore bridging between the different research federations (social media, cloud).

Why to bridge? Creating a new account is often criticized

Why to bridge? User already know their home institution credentials

Why to bridge? Bring people together from different federations (cultures) Not yet another account People already know their home institution account

What to bridge? National research and education networks (NRENs)

What to bridge? eduGain Grid solutions Commercial federations

What to bridge?

For bridging also slim concept Minimal administration User driven (minimalisation of legal requirements) Via mapping table bridging for each individual user Use cases prototype Bridging to GRID EduGain (Switch)

Umbrella collaborators ALBA Daniel Salvat DESY Frank Schluenzen, Rolf Treusch, Thorsten Kracht, Jan-Peter Kurz, Ulrike Lindemann Fermi/Elettra Cecilia Blasetti, Ornela Degiacomo, Giorgio Paolucci ESRF Rudolf Dimper, Dominique Porte, Julien Savoyet, Stefan Schulze European XFEL Krzysztof Wrona GSI Peter Malzacher, Almudena Montiel Gonzalez, Kilian Schwarz HZB Thomas Gutberlet, Dietmar Herrendoerfer I LL Jean-Francois Perrin IPJ (Poland) Robert Nietubic MaxLAB Krister Johansson PSI Bjoern Abt, Stephan Egli, Stefan Janssen, Markus Knecht, Mirjam van Daalen, Heinz J Weyer Soleil Frederique Fraissard STFC Anthony Gleeson, Tom Griffin, Alistair Mills, Bill Pulford

Thank you for your attention!

  Umbrella ORCID Persistent ID y User driven Password Identifier is public n Project confidentiality full no Information Access control Facilities only Coarse: manually given to organization by ORCID user Separation bw login information and additional attributes Passwords stored hashed Entry provided by User User or institution user belongs to Personal info vs. roles Strictly separated Same db Central db Minimal, only for identification Assertion Self, handshake foreseen Self, working group for multi-assertion topology Facilities, PIs Policy MoU between facilities Given by ORCID System hybrid central