Climate Sciences: Use Case and Vision Summary Philip Kershaw CEDA, RAL Space, STFC.

Slides:



Advertisements
Similar presentations
Identity Network Ideals – Heterogeneity & Co-existence
Advertisements

EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
The role of the ISIC facility for Climate and Environmental Monitoring from Space (CEMS) in the development of Quality Assured Datasets and Downstream.
Contrail and Federated Identity Management
The Internet2 NET+ Services Program Jerry Grochow Interim Vice President CSG January, 2012.
The EGI – a sustainable European grid infrastructure Michael Wilson STFC RAL.
SCD in Horizon 2020 Ian Collier RAL Tier 1 GridPP 33, Ambleside, August 22 nd 2014.
Cloud Computing Special Interest Group Cloud Computing for the UK Research Community Workshop December 2013 Philip Kershaw, STFC Rutherford Appleton.
VO Sandpit, November 2009 NERC Big Data And what’s in it for NCEO? June 2014 Victoria Bennett CEDA (Centre for Environmental Data Archival)
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI - Identity Management Steven Newhouse Director, EGI.eu Federated Identity.
Federated Identity Management for Research Communities (FIM4R) David Kelsey (STFC-RAL) EGI TF, AAI workshop 19 Sep 2012.
1 Issues in federated identity management Sandy Shaw EDINA IASSIST May 2005, Edinburgh.
Agenda Project beginnings and funding. Purpose of the federation. Federation members. Federation protocols. Special features in our federation. Pilot.
Towards Cloud Federations: what we have; what we want OGF 31, Taipei Cloud security session Jens Jensen Science and Technology Facilities Council Rutherford.
Modelling and Data Centre Requirements: CEDA ESGF UV-CDAT Conference December 2014 Philip Kershaw, Centre for Environmental Data Archival, RAL Space,
Constellation Technologies Providing a support service to commercial users of gLite Nick Trigg.
FIM-ig Federated Identity Management Interest Group.
DESIGN OF A PLATFORM OF VIRTUAL SERVICE CONTAINERS FOR SERVICE ORIENTED CLOUD COMPUTING Carlos de Alfonso Andrés García Vicente Hernández.
Cloud Computing Cloud Security– an overview Keke Chen.
The Cloud Identity Security Leader. © 2012 Ping Identity Corporation Nair the twain shall meet Enterprise Social Mobile.
Software to Data model Lenos Vacanas, Stelios Sotiriadis, Euripides Petrakis Technical University of Crete (TUC), Greece Workshop.
Open Source Grid Computing in the Finance Industry Alex Efimov STFC Kite Club Knowledge Exchange Advisor UK CERN Technology Transfer Officer
1 Dr. Markus Hillenbrand, ICSY Lab, University of Kaiserslautern, Germany A Generic Database Web Service for the Venice Service Grid Michael Koch, Markus.
EGI-Engage EGI-Engage Engaging the EGI Community towards an Open Science Commons Project Overview 9/14/2015 EGI-Engage: a project.
Authentication and Authorization in a federated environment Jules Wolfrat (SARA)
CEMS: The Facility for Climate and Environmental Monitoring from Space Victoria Bennett, ISIC/CEDA/NCEO RAL Space.
The National Grid Service User Accounting System Katie Weeks Science and Technology Facilities Council.
Advanced Computing Services for Research Organisations Bob Jones Head of openlab IT dept CERN This document produced by Members of the Helix Nebula consortium.
Federated Identity Management for HEP David Kelsey WLCG GDB 9 May 2012.
VO Sandpit, November 2009 e-Infrastructure to enable EO and Climate Science Dr Victoria Bennett Centre for Environmental Data Archival (CEDA)
Grid Security Issues Shelestov Andrii Space Research Institute NASU-NSAU, Ukraine.
JASMIN and CEMS: The Need for Secure Data Access in a Virtual Environment Cloud Workshop 23 July 2013 Philip Kershaw Centre for Environmental Data Archival.
NETWORKED EUROPEAN SOFTWARE & SERVICES INITIATIVE Future research challenges in dependability - an industrial perspective from NESSI Aljosa Pasic Atos.
Federated Identity in the Earth Science Domain: the Earth System Grid Federation, EGI-Inspire and GENESI-DEC Federated Identity System for Scientific Collaborations.
7 th FIM 4 R meeting April 2014 ESRIN Frascati.
NA-MIC National Alliance for Medical Image Computing UCSD: Engineering Core 2 Portal and Grid Infrastructure.
Virtualisation & Cloud Computing at RAL Ian Collier- RAL Tier 1 HEPiX Prague 25 April 2012.
EResearchers Requirements the IGTF model of interoperable global trust and with a view towards FIM4R AAI Workshop Presenter: David Groep, Nikhef.
GRID Overview Internet2 Member Meeting Spring 2003 Sandra Redman Information Technology and Systems Center and Information Technology Research Center National.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks SA1: Grid Operations Maite Barroso (CERN)
Security Policy Update David Kelsey UK HEP Sysman, RAL 1 Jul 2011.
Internet2 AdvCollab Apps 1 Access Grid Vision To create virtual spaces where distributed people can work together. Challenges:
Diego R. Lopez, RedIRIS JRES2005, Marseille On eduGAIN and the Coming GÉANT Middleware Infrastructure.
GRID ANATOMY Advanced Computing Concepts – Dr. Emmanuel Pilli.
LHC Computing, CERN, & Federated Identities
Federated Identity Management for Scientific Collaborations The Common Vision David Kelsey (STFC) 3 Nov 2011.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
Networks ∙ Services ∙ People Thomas Bärecke Journée Fédération, Paris Collaboration européenne GÉANT SA5 03/07/2015 SA5 T5 team
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI strategy and Grand Vision Ludek Matyska EGI Council Chair EGI InSPIRE.
b2access.eudat.eu B2ACCESS The simple and secure authorisation and authentication platform of EUDAT This work is licensed under the Creative.
The National Grid Service User Accounting System Katie Weeks Science and Technology Facilities Council.
Shibboleth Use at the National e-Science Centre Hub Glasgow at collaborating institutions in the Shibboleth federation depending.
Using a Simple Knowledge Organization System to facilitate Catalogue and Search for the ESA CCI Open Data Portal EGU, 21 April 2016 Antony Wilson, Victoria.
All Hands Meeting 2005 BIRN-CC: Building, Maintaining and Maturing a National Information Infrastructure to Enable and Advance Biomedical Research.
The Helmholtz Association Project „Large Scale Data Management and Analysis“ (LSDMA) Kilian Schwarz, GSI; Christopher Jung, KIT.
Co-ordination & Harmonisation of Advanced e-Infrastructures Research Infrastructures – Grant Agreement n CHAIN sustainability guidelines Dr. Ognjen.
EGI-InSPIRE EGI-InSPIRE RI The European Grid Infrastructure Steven Newhouse Director, EGI.eu Project Director, EGI-InSPIRE 29/06/2016CoreGrid.
Security in the wider world David Kelsey (STFC-RAL) GridPP37 – Ambleside 2 Sep 2016.
Bob Jones EGEE Technical Director
Services for EOSC management
Cloud Security– an overview Keke Chen
Ian Bird GDB Meeting CERN 9 September 2003
Federated Identity Management for Researchers (FIM4R)
Federated Identity Management for Scientific Collaborations
ESA Single Sign On (SSO) and Federated Identity Management
EGI Webinar - Introduction -
David Kelsey (STFC-RAL)
Single Sign-On (SSO) Authentication
EOSC-hub Contribution to the EOSC WGs
Check-in Identity and Access Management solution that makes it easy to secure access to services and resources.
Presentation transcript:

Climate Sciences: Use Case and Vision Summary Philip Kershaw CEDA, RAL Space, STFC

Overview Update on developments since last workshop Federated Identity for the Cloud – Use case from two contrasting scenarios Vision Summary – What is the vision for this community – What are the issues we face and challenges we wish to address Philip Kershaw

Update from Last Workshop Earth System Grid Federation (ESGF): – a software infrastructure deployed in the first instance to support CMIP5 CMIP5, a globally co-ordinated set of climate model experiments organised under the WCRP ESGF – Globally federated archive ~2.5Pb – 25k users worldwide (not just CMIP5) Security Architecture – Dual SSO methods supported: OpenID and MyProxyCA – SAML interfaces for attribute and authorisation queries ESGF now being deployed for other Earth science data – Earth observation and regional model data EGI – INSPIRE: – Project to enable access to ESGF resources via EGI – An inter-federation trust challenge Philip Kershaw

Federated Identity for Cloud: two contrasting scenarios CEMS (Climate and Environmental Monitoring from Space) – A UK facility for climate change and environmental science using satellite data and services. – Builds on ISIC (International Space Innovation Centre) public private partnership – A focal point for science, government and commercial user communities. – Data quality and integrity services and expertise – Data hosting and processing facilities FP7 funded project over three years Develop Federated cloud infrastructure: – An abstraction layer to manage resources over multiple cloud providers Platform as a Service solutions Virtual Infrastructure Networks Federated file system SLA negotiation Federated security Build on Open Source cloud solutions Philip Kershaw

CEMS Architecture Public and Commercial Cloud Infrastructure Hardware – data storage [NCEO and Commercial Data] and processing App 2 App 3 App N App 1 … Business and research user communities Data Access Quality Services Core Services Applications Cloud Management Services Data Processing

CEMS: Federated Identity Challenges Access control is needed to enforce: – Licence agreements – Project restrictions – pay-for services? Federate identity needed to bridge: – academic and commercial organisations Bridging independent domains: – How to manage trust? – Communication of levels of assurance – Middleware to bridge independent access control infrastructures Integration with off-the-shelf cloud infrastructure Philip Kershaw

CONTRAIL: Federated Identity Challenges Layered architecture: federation abstracts individual providers and their resources Single sign-on on two axes: external to federation and federation to provider Credential management challenge: Resources may be long lived (e.g. a VM) but dynamically provisioned – Virtual infrastructure networks may require dynamic creation of CAs Philip Kershaw

Climate Sciences: Vision Statement Project-oriented vs. ‘national’ federated identity management infrastructure – Projects require attributes scoped within the project’s domain covering multiple IdPs and possibly federations – Can IdPs be expected to support attributes needed for multiple projects? – Project-wide attribute authorities needed to manage project attributes – Challenging to leverage national infrastructure for international projects! Inter-federation and bridging technologies – Management of levels of assurance between independent domains – Provenance of credentials Policies and trust – The lack of clear policy statements can inhibit the ability to interoperate with other established systems. – Newer communities need to see the value of policies Cloud and virtualisation are creating new challenges – Dynamic provision of credentials for long lived resources Philip Kershaw