DAME Collaborative Workflow & Access Control Duncan Russell University of Leeds.

Slides:



Advertisements
Similar presentations
LEAD Portal: a TeraGrid Gateway and Application Service Architecture Marcus Christie and Suresh Marru Indiana University LEAD Project (
Advertisements

The Next Generation Grid Kostas Tserpes, NTUA Beijing, 22 of June 2005.
Working Group 3 – Grid C/W & VOs Glenn Gapper, Josep Vallés Sanchez, Boas Betzler, John Brooke & many others! Questions Posed: –What are VOs? –Services.
Business Plan and Outstanding Issues for Illinois Justice Network Portal IIJIS Technical Committee Meeting January 16, 2004.
5-Dec-02D.P.Kelsey, GridPP Security1 GridPP Security UK Security Workshop 5-6 Dec 2002, NeSC David Kelsey CLRC/RAL, UK
GT 4 Security Goals & Plans Sam Meder
Research Councils ICT Conference Welcome Malcolm Atkinson Director 17 th May 2004.
VO Support and directions in OMII-UK Steven Newhouse, Director.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
Policy Based Dynamic Negotiation for Grid Services Authorization Infolunch, L3S Research Center Hannover, 29 th Jun Ionut Constandache Daniel Olmedilla.
Decision Support Tools CBR & Modeling Jeff Allan University of Sheffield.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI - Identity Management Steven Newhouse Director, EGI.eu Federated Identity.
The Community Authorisation Service – CAS Dr Steven Newhouse Technical Director London e-Science Centre Department of Computing, Imperial College London.
TF-EMC2 February 2006, Zagreb Deploying Authorization Mechanisms for Federated Services in the EDUROAM Architecture (DAME) -Technical Project Proposal-
Security NeSC Training Team International Summer School for Grid Computing, Vico Equense,
Towards the Design and Implementation of the DAME prototype: OGSA Compliant Grid Services on the White Rose Grid Sarfraz A Nadeem University of Leeds.
CoLaB 22nd December 2005 Secure Access to Service-based Collaborative Workflow for DAME Duncan Russell Informatics Institute University of Leeds, UK.
Supporting further and higher education Authentication & Authorisation for JISC and UK e-Science Alan Robiette, JISC Development Group.
Cardea Requirements, Authorization Model, Standards and Approach Globus World Security Workshop January 23, 2004 Rebekah Lepro Metz
A PERMIS-based Authorization Solution between Portlets and Back-end Web Services Hao Yin 1, Sofia Brenes-Barahona 2, Donald F. McMullen * 2, Marlon Pierce.
What is OMII-Europe? Qin Li Beihang University. EU project: RIO31844-OMII-EUROPE 1 What is OMII-Europe? Open Middleware Infrastructure Institute for Europe.
Climate Sciences: Use Case and Vision Summary Philip Kershaw CEDA, RAL Space, STFC.
Grid Security Issues Shelestov Andrii Space Research Institute NASU-NSAU, Ukraine.
DAME: The route to commercialisation Tom Jackson University of York.
1 Grid Security. 2 Grid Security Concerns Control access to shared services –Address autonomous management, e.g., different policy in different work groups.
SIMDAT Authentification and Autorisation Matteo Dell’Acqua ET-CTS meeting, Toulouse, May 2008.
Security Area in GridPP2 4 Mar 2004 Security Area in GridPP2 “Proforma-2 posts” overview Deliverables – Local Access – Local Usage.
Distributed Aircraft Maintenance Environment - DAME DAME Workflow Advisor Max Ong University of Sheffield.
OGSA-DAI in OMII-Europe Neil Chue Hong EPCC, University of Edinburgh.
The DAME project Professor Jim Austin University of York.
Supporting further and higher education The Akenti Authorisation System Alan Robiette, JISC Development Group.
SOA-39: Securing Your SOA Francois Martel Principal Solution Engineer Mitigating Security Risks of a De-coupled Infrastructure.
DAME: A Distributed Diagnostics Environment for Maintenance Duncan Russell University of Leeds.
Supporting education and research Security and Authentication for the Grid Alan Robiette, JISC Development Group.
SEEK Welcome Malcolm Atkinson Director 12 th May 2004.
Oxford University e-Science Centre 1 Managing Access 4 Dec Managing Access to Resources on the Grid 4 December 2002.
DAME: A Distributed Diagnostics Environment for Maintenance Dr Tom Jackson University of York.
GridShib and PERMIS Integration: Adding Policy driven Role-Based Access Control to Attribute-Based Authorisation in Grids Globus Toolkit is an open source.
Shibboleth Akylbek Zhumabayev September Agenda Introduction Description WS Standards WS-Federation Picture Grid Security GridShib References 2.
Grid Authorization Landscape and Futures Von Welch NCSA
Authorisation, Authentication and Security Guy Warner NeSC Training Team Induction to Grid Computing and the EGEE Project, Vilnius,
Authentication and Authorisation for Research and Collaboration Peter Solagna Milano, AARC General meeting Current status and plans.
Approaching Fine-grain Access Control for Distributed Biomedical Databases within Virtual Environments Onur Kalyoncu, Yi Pan, Matthias Assel High Performance.
DTI Mission – 29 June LCG Security Ian Neilson LCG Security Officer Grid Deployment Group CERN.
Standards driven AAA for Job Management within the OMII-UK distribution Steven Newhouse Director, OMII-UK
© Drexel University Software Engineering Research Group (SERG) 1 The OASIS SOA Reference Model Brian Mitchell.
Access Control for Dynamic Virtual Organisations Duncan Russell, Peter Dew & Karim Djemame University of Leeds.
GRID ANATOMY Advanced Computing Concepts – Dr. Emmanuel Pilli.
1 AHM, 2–4 Sept 2003 e-Science Centre GRID Authorization Framework for CCLRC Data Portal Ananta Manandhar.
Policy Management for OGSA Applications as Grid Services Lavanya Ramakrishnan.
E-Science Security Roadmap Grid Security Task Force From original presentation by Howard Chivers, University of York Brief content:  Seek feedback on.
Toward a common data and command representation for quantum chemistry Malcolm Atkinson Director 5 th April 2004.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
Selected Semantic Web UMBC CoBrA – Context Broker Architecture  Using OWL to define ontologies for context modeling and reasoning  Taking.
Virtual Organisations for Trials and Epidemiological Studies (VOTES) Overview VOTES is a pioneering project investigating the application of Grid technology.
GALT 031 Distributed Programmable Authorisation David Chadwick.
1 Globus Toolkit Security Java Components Rachana Ananthakrishnan Frank Siebenlist.
Virtual Organisation Management in the Level 2 Grid Steven Newhouse Technical Director London e-Science Centre Department of Computing, Imperial College.
Frascati, 2-3 July 2008 Slide 1 User Management compliance testing for G-POD HMA-T Phase 2 KO Meeting 2-3 July 2008, Frascati Andrew Woolf, STFC Rutherford.
Virtual Organisations and the NGS Mike Jones Research Computing Services e-Science & “The Grid” for Bio/Health Informaticians, IT January 2008.
Grid Computing Security Mechanisms: the state-of-the-art
EGI Updates Check-in Matthew Viljoen – EGI Foundation
Creating an SOA roadmap and Project Plan
Security Requirements for ChinaGrid Applications - What the current grid security solutions cannot do Hai Jin Huazhong University of Science and Technology.
A user-friendly approach to grid security
Liang Fang, Dennis Gannon Indiana University Frank Siebenlist
Community AAI with Check-In
High Performance Computing Center – HLRS
Check-in Identity and Access Management solution that makes it easy to secure access to services and resources.
OU BATTLECARD: Oracle Systems Learning Subscription
Presentation transcript:

DAME Collaborative Workflow & Access Control Duncan Russell University of Leeds

Distributed Aircraft Maintenance Environment - DAME Collaborative Workflow Business process –Involving different people/resources –Across different organisations Task based problem solving –Collaboration of Skills Expertise

Distributed Aircraft Maintenance Environment - DAME DAME Example Business process for diagnosing vibration data across three roles: –Maintenance Engineer –Maintenance Analyst –Domain Expert

Distributed Aircraft Maintenance Environment - DAME DAME Virtual Organisation

Distributed Aircraft Maintenance Environment - DAME DAME Access Control Restrict access to sensitive services and data Provide accountability for actions and visibility of permissions Must scale to multiples of: –Users/VOs –Portals –Workflows and Services Decouple decision and enforcement Existing solutions too static (CAS, VOMS, PERMIS, Akenti)

Distributed Aircraft Maintenance Environment - DAME Cardea Access Control Lepro, R, 2003, Cardea: Dynamic Access Control in Distributed Systems, NAS Technical Report NAS , NASA Advanced Supercomputing (NAS) Division

Distributed Aircraft Maintenance Environment - DAME DAME Access Control

Distributed Aircraft Maintenance Environment - DAME DAME Access Control Integrate access control into application interface Define who can control VO membership Self modifying service to update VO membership policies Workflow engine pass VO to service factories All VO service instances use VO policy

Distributed Aircraft Maintenance Environment - DAME Access Control Building Blocks SAML –Authorisation assertions XACML –Policy descriptions WS-Secure Conversation –From GSI Secure Conversation –Includes WS-Security – message token XML-Signature – message integrity XML-Encryption – message privacy

Distributed Aircraft Maintenance Environment - DAME Integration Into DAME Workflow manager –Control of VO membership Application interface Security/access control handlers in grid container Link to audit trail and Provenance System

Any Questions? DAME Collaborative Workflow & Access Control Duncan Russell University of Leeds