Common Authentication and Authorisation Service for Life Science Research Mikael Linden, ELIXIR Finland.

Slides:



Advertisements
Similar presentations
Resource Entitlement Management System Manne Miettinen Mikael Linden Janne Lauros CSC – IT Center for Science.
Advertisements

European Life Sciences Infrastructure for Biological Information ELIXIR FI for BBMRI IT Morris FIMM and THL Tommi Nyrönen.
EGI-Engage EGI-Engage Engaging the EGI Community towards an Open Science Commons Project Overview 9/14/2015 EGI-Engage: a project.
EMI AAI Strategy & Plans John White / Helsinki Institute of Physics Federated Identity Systems for Scientific Collaborations Workshop , CERN,
Authentication and Authorisation for Research and Collaboration Licia Florio (GÉANT) Christos Kanellopoulos (GRNET) Service orientation.
European Life Sciences Infrastructure for Biological Information Life science community update for the 7 th Federated Identity Management.
This document produced by Members of the Helix Nebula Partners and Consortium is licensed under a Creative Commons Attribution 3.0 Unported License. Permissions.
Authentication and Authorisation for Research and Collaboration Licia Florio REFEDS Meeting The AARC Project I2 Technology Exchange.
Authentication and Authorisation for Research and Collaboration Christos Kanellopoulos GRNET Proposed Pilots for Libraries and eGov.
Authentication and Authorisation for Research and Collaboration Michał Jankowski, Maciej Brzeźniak AARC General Meeting, Milan.
European Life Sciences Infrastructure for Biological Information ELIXIR and Identity Management 2 nd Workshop on Federated Identity.
Authentication and Authorisation for Research and Collaboration Milan, Italy Training and Outreach Authentication and Authorisation.
Federated Identity Management for HEP David Kelsey HEPiX, IHEP Beijing 18 Oct 2012.
EResearchers Requirements ELIXIR AAI Workshop Presenter: Mikael Linden (ELIXIR AAI-TF)
EUDAT receives funding from the European Union's Horizon 2020 programme - DG CONNECT e-Infrastructures. Contract No B2ACCESS LSDMA.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
Networks ∙ Services ∙ People Thomas Bärecke Journée Fédération, Paris Collaboration européenne GÉANT SA5 03/07/2015 SA5 T5 team
Networks ∙ Services ∙ People Marina Adomeit FIM4R meeting Virtual Organisation Platform as a Service VOPaaS Nov 30, 2015, Austria Task Leader,
Authentication and Authorisation for Research and Collaboration Licia Florio REFEDS Meeting AARC and AARC2 Vienna, 1 st December.
European Life Sciences Infrastructure for Biological Information EGI 2015, Lisbon, 18 May 2015 Rafael C Jimenez, ELIXIR CTO ELIXIR.
European Life Sciences Infrastructure for Biological Information ELIXIR’s needs from the EOSC Steven Newhouse, EMBL-EBI Part of the.
Authentication and Authorisation for Research and Collaboration Heiko Hütter, Martin Haase, Peter Gietz, David Groep AARC 3 rd.
Authentication and Authorisation for Research and Collaboration Peter Solagna, Davide Vaghetti, et al. Topics for PY2 activities.
Authentication and Authorisation for Research and Collaboration Licia Florio AARC CORBEL Workshop The AARC Project Paris, 31 May.
European Life Sciences Infrastructure for Biological Information European Life Sciences Infrastructure for Biological Information.
Authentication and Authorisation for Research and Collaboration Peter Solagna, Nicolas EGI AAI integration experiences AARC Project.
Authentication and Authorisation for Research and Collaboration AARC/CORBEL Workshop for Life Sciences AAI AARC Draft Blueprint.
European Life Sciences Infrastructure for Biological Information European Life Sciences Infrastructure for Biological Information.
EGI-InSPIRE EGI-InSPIRE RI EGI strategy towards the Open Science Commons Tiziana Ferrari EGI-InSPIRE Director at EGI.eu.
Rafael Jimenez ELIXIR CTO BioMedBridges Life science requirements from e-infrastructure: initial results from a joint BioMedBridges workshop Stephanie.
Authentication and Authorisation for Research and Collaboration Taipei - Taiwan Mechanisms of Interfederation 13th March 2016 Alessandra.
Networks ∙ Services ∙ People Mandeep Saini AARC/CORBEL Workshop Collaborative Organisation Platform as a Service June 1, 2016, Paris Product.
Authentication and Authorisation for Research and Collaboration Licia Florio IGTF Meeting The AARC Project Amsterdam, 8 September.
ELIXIR AAI Michal Procházka, Mikael Linden, EGI VC 15 March 2016.
Security in the wider world David Kelsey (STFC-RAL) GridPP37 – Ambleside 2 Sep 2016.
Innovation through participation Data Protection Code of Conduct (DP CoC) TNC2013 conference, 4 June 2013 Mikael Linden, CSC – IT Center for Science
Introduction to AAI Services
Project Facts Partners: DANTE (UK), GARR (IT), RedCLARA (UY), RedIRIS (ES), RENATA (CO), RNP (BR), TERENA (NL) Coordinator: RedCLARA Project Duration:
RCauth.eu CILogon-like service in EGI and the EOSC
Panel discussion on Principles of Engagement
EGI Updates Check-in Matthew Viljoen – EGI Foundation
User Community Driven Development in Trust and Identity
Defining EOSC Rules of Engagement Damien Lecarpentier (CSC)
eduTEAMS platform for collaboration Niels Van Dijk
Christos Kanellopoulos
AAI Alignment Nicolas Liampotis (based on the work of Mikael Linden)
GÉANT International Networking and Collaboration
EGI-Engage Engaging the EGI Community towards an Open Science Commons
ELIXIR Safeguarding the results of life science research in Europe
EGI – Organisation overview and outreach
Thursday pilot session: 7-minutes
EduTEAMS at a Glance Mandeep Saini Linz, Austria 30 May 2017.
WP2 Governance Per Öster
EGI Webinar - Introduction -
Pilots in AARC Arnout Terpstra (AARC2) / Paul van Dijk (AARC1)
AARC Blueprint Architecture and Pilots
ELIXIR Competence Center
AAI Architectures – current and future
RCauth.eu CILogon-like service in EGI and the EOSC
Single Sign-On (SSO) Authentication
Community AAI with Check-In
ESFRI ROADMAP Madrid, 12th March 2019 Gonzalo Arévalo Nieto
UmbrellaID in the EOSC era ?
WP6 – EOSC integration J-F. Perrin (ILL) 15th Jan 2019
Stakeholders R. Dimper 15 January 2019
Authentication and Authorisation for Research and Collaboration
Check-in Identity and Access Management solution that makes it easy to secure access to services and resources.
LifeWatch AARC Pilot Fernando Aguilar 13th FIM4R Workshop
Umbrella ID Federated Identity for PaN facilities
Common Authentication and Authorisation Service for Life Science Research Mikael Linden, ELIXIR Finland.
Presentation transcript:

Common Authentication and Authorisation Service for Life Science Research Mikael Linden, ELIXIR Finland

background Since 2015, thirteen ESFRI Research Infrastructures from the field of BioMedical Science (BMS RI) joined their scientific capabilities and services to transform the understanding of biological mechanisms and accelerate its translation into medical care. biobanking & biomolecular resources curated databases highly pathogenic microorganisms functional genomics microorganisms translational research marine model organisms screening & medicinal chemistry structural biology -> hyperlinks placed on each logo, active only in presentation mode clinical trials plant phenotyping biological/medical imaging systems biology

background 4 year project: 2015-2019 37 partners in 13 BMS RIs budget: €14.8 million builds on BioMedBridges (2012-2015) co-coordinated by ELIXIR and BBMRI-ERIC -> hyperlinks placed on each logo, active only in presentation mode

How many research infrastructure AAIs needed? Any cooperation possible? Life Science Authentication and Authorisation Infrastructure (AAI) Figure: Academy of Finland

research infrastructures and AAI Why not? AAI is not core business for research infrastructures => Partner with e-infrastructures Why RIs active in research AAI? Research infrastructures are permanent Have sustainable funding model Research infrastructures are there to provide research support services Research infrastructures have contact to research communities and services Understand their research domain’s needs

Use scenarios of a Life Science AAI Producing research data (instruments, e.g. microscopes, genome sequencers) Storing research data (data archives) Transferring research data (to a computing environment, e.g. gridFTP) Computing environments (e.g. clouds, computing clusters) Various collaborative tools (wikis, intranets, mailing lists)

History of the Life Science AAI June 2016: CORBEL WP5 workshop on AAI Autumn 2016: use case documentation Spring 2017: developing requirements specification Autumn 2017: call for a pilot with e-infrastructures Spring 2018: pilot with e-infrastructures Applied funding for a deployment project starting in 2019

Requirements of the Life Science AAI See our full paper for the requirements on the LS AAI There is really nothing specific to Life Sciences! The requirements could apply to any other research infrastructures Potential for Wider cross-research infrastructure collaboration E-infrastructures to provide focused services

Identity and authentication User identifiers Life Science identifier, e.g. 28c5353b8bb34984a8bd4169b a94c606@lifescienceid.org Life Science username, e.g. mike@lifescienceid.org One identity for one person assumed User authentication By external authentication providers (e.g. eduGAIN, ORCID, Google, …) By Hostel Identity Provider Users can link several authentication providers to their Life Science ID

Attributes and authorisation User’s Home Organisation Registered access data eduPersonAffiliation received from eduGAIN, if available Researcher prove and attest that they qualify as a bona fide researcher Otherwise, manually assign Home organisation attribute to users Service owner decides what a bona fide researcher can access Groups Active role selection Group managers can add, invite and remove members User can access X when working with project A User can access Y when working with project B Group hierarchy User must not access Y when working in project A Controlled access data User selects their current project in the beginning of the session Researcher applies for data access Dataset owner approves applications

Integration to relying services SAML 2.0 X.509 The legacy protocol Mostly, for grid interoperability (gridFTP) Wide deployment base and support RCAuth.eu OpenID Connect Provisioning/deprovisioning 3-tier scenarios For batch-based syncronisation Non-web scenarios (CLI, app) E.g. management for mailing lists based on group memberships Refreshing attributes Simpler and more modern E.g. shutting down user’s VMs in a cloud when they depart

Pilot with e-infrastructures In the context of AARC2 project E-infrastructures operating the pilot environment (EGI, EUDAT, GEANT) Phase 1 January 2018 Phase 2 May 2018 Phase 3 autumn 2018

Non-technical considerations Policies Service operations For end users (AUP) Partnering with e-infrastructures to operate the service For relying services (qualification, obligations) Data protection model Service management and sustainability Data controller/processor Purpose, legal grounds Funding model after the deployment phase Organisational and technical measures Bodies and procedures for decision making etc

Questions? The projects receive funding from the European Union’s Horizon 2020 research and innovation programme under grant agreements No 654248 (CORBEL) and 730941 (AARC2).