Trust Relationships in Grid CHEP 07 Mine Altunay.

Slides:



Advertisements
Similar presentations
The Digital Millennium Copyright Act and Liability for Hosting and Linking Mark D. Robins Nixon Peabody LLP.
Advertisements

GLOBAL SCI CONSUMER NETWORK: Resources for online communication Frans Penninx (Dutch SCI Association) Sara Rubinelli (University of Lucerne and Swiss Paraplegic.
9/25/08DLP1 OSG Operational Security D. Petravick For the OSG Security Team: Don Petravick, Bob Cowles, Leigh Grundhoefer, Irwin Gaines, Doug Olson, Alain.
This work was performed under the following financial assistance award 70NANB13H189 from the U.S. Department of Commerce, National Institute of Standards.
Community Outreach Strategies 101
Defining France Grilles resource allocation strategy Gilles Mathieu, IN2P3 Computing Centre France Grilles International Advisory Committee – March 2011.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI - Identity Management Steven Newhouse Director, EGI.eu Federated Identity.
Grid Security Users, VOs, Sites OSG Collaboration Meeting University of Washington Bob Cowles August 23, 2006 Work supported.
INFSO-RI Enabling Grids for E-sciencE Update on LCG/EGEE Security Policy and Procedures David Kelsey, CCLRC/RAL, UK
Trustworthy Repository Criteria, Virtual Organizations, and Infrastructure MacKenzie Smith, MIT Libraries NDIIPP Meeting, July 2010.
Developing a Records & Information Retention & Disposition Program:
WLCG Cloud Traceability Working Group progress Ian Collier Pre-GDB Amsterdam 10th March 2015.
Foundation of Rock vs. House of Cards: What Leads to Successful Collaborations? Presenters: Nancy Rogers & Dawn Underwood.
Chapter 9 e-Commerce Systems.
A Guide for Navigators 1National Disability Institute.
Organizing for Heritage Tourism 4 th Webinar in the Heritage Tourism Initiative North Central Regional Center for Rural Development.
Chapter © 2012 Pearson Education, Inc. Publishing as Prentice Hall.
Community Criteria People Criteria Process Criteria Culture Criteria
SRA Enabling Programme SRA Board Meeting – Public Session Carey Street, London 26 th February 2009.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI Security Policy Group EGI Technical Forum Sep 2010 David Kelsey.
Copyright © 2009 Pearson Education, Inc. Slide 6-1 Chapter 6 E-commerce Marketing Concepts.
Operational Security Working Group Topics Incident Handling Process –OSG Document Review & Comments:
CILogon OSG CA Mine Altunay Jim Basney TAGPMA Meeting Pittsburgh May 27, 2015.
Certification and Accreditation CS Phase-1: Definition Atif Sultanuddin Raja Chawat Raja Chawat.
VO Sandpit, November 2009 Environmental Data Archival: Practices and Benefits crib sheet Graham Parton With many thanks to Dr.
Trust Models Presentation Trust Models. Trust Models Presentation Vishwas Patil, TIFR.2/100 Trust Models: Introduction  What is Trust ?  assured reliance.
Survey on Land Administration Systems Note by the Working Party on Land Administration James O Boyle, WPLA Bureau member, Property Registration Authority.
Promoting Good Practices in Domain Name Registration Supported by.
Connective Leadership
Data Warehousing Data Mining Privacy. Reading Bhavani Thuraisingham, Murat Kantarcioglu, and Srinivasan Iyer Extended RBAC-design and implementation.
Evolution of the Open Science Grid Authentication Model Kevin Hill Fermilab OSG Security Team.
Introducing HingX now with Capacity Development Network.
WLCG Cloud Traceability Working Group face to face report Ian Collier 11 February 2015.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
OSG PKI Contingency and Recovery Plans Mine Altunay, Von Welch October 16, 2012.
Communicating in Small Groups
Mine Altunay July 30, 2007 Security and Privacy in OSG.
How To: A Process for Successful Partnerships. Partnership Definition A partnership IS: A written agreement between the parties. Mutual interest in, mutual.
Data Governance 101. Agenda  Purpose  Presentation (Elijah J. Bell) Data Governance Data Policy Security Privacy Contracts  FERPA—The Law  Q & A.
Internal communication It includes all communication within an organization. Communication may be oral or written, face to face or virtual, one-on- one.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks SA1: Grid Operations Maite Barroso (CERN)
1 Privacy Plan of Action © HIPAA Pros 2002 All rights reserved.
Security Policy Update David Kelsey UK HEP Sysman, RAL 1 Jul 2011.
TPAS Annual Conference 2014 Registered Tenant Organisations What are they & what they’re not?! Ann Marie Stanley Tenant Priorities Team.
The Power of Teacher Teams Presenter – Diane Still Kentucky Dept. of Education.
Technical Support to SOA Governance E-Government Conference May 1-2, 2008 John Salasin, Ph.D. DARPA
AB 86: Adult Education Consortia Planning Using Your Planning $$$ Wisely Webinar Series
Open Science Grid Security Activities Mine Altunay, FNAL OSG Security Officer For the OSG Security Team: Doug Olson, Deputy Security Officer, LBNL, Jim.
HIT Policy Committee NHIN Workgroup HIE Trust Framework: HIE Trust Framework: Essential Components for Trust April 21, 2010 David Lansky, Chair Farzad.
“Power Networking for Community Impact – An Overview” 2015 PANO Collaborative Conference Monday, September 22, 2015.
DTI Mission – 29 June LCG Security Ian Neilson LCG Security Officer Grid Deployment Group CERN.
Interest-Based Bargaining.  Interest-based bargaining involves parties in a collaborative effort to jointly meet each other’s needs and satisfy mutual.
Computer Science and Engineering 1 Mobile Computing and Security.
GRID ANATOMY Advanced Computing Concepts – Dr. Emmanuel Pilli.
Security Policy: From EGEE to EGI David Kelsey (STFC-RAL) 21 Sep 2009 EGEE’09, Barcelona david.kelsey at stfc.ac.uk.
© BLR ® —Business & Legal Resources 1408 Teambuilding for All Employees.
June 6, 2006OSG - Draft VO AUP1 Open Science Grid Trust as a Foundation June 6, 2006 Keith Chadwick.
Chapter © 2012 Pearson Education, Inc. Publishing as Prentice Hall.
SEPARATE ACCOUNTS FOR PROSPECTS? WHAT A HEADACHE! Ann West Assistant Director, InCommon Assurance and Community Internet2 at Michigan Tech.
Opensciencegrid.org Operations Interfaces and Interactions Rob Quick, Indiana University July 21, 2005.
Halton Hills Community Website & Box Office
4 core technologies integrated into one handheld device Data points: date/time, BrAC, photo ID/facial recognition, GPS Inside SL2?
OSG Security: Updates on OSG CA & Federated Identities Mine Altunay, PhD OSG Security Team OSG AHM March 24, 2015.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Security aspects (based on Romain Wartel’s.
KNOWLEDGE MANAGEMENT (KM) Session # 33. Corporate Intranet A Conceptual Model INTRANET Production Team— New Product Budget Director— New Product Knowledge.
OSG VO Security Policies and Requirements Mine Altunay OSG Security Team July 2007.
Open Science Grid Consortium Meeting
A Model for Grid User Management
CONTRACT MANAGEMENT CORPORATE.
Chapter 14 Generating and Utilizing Trust
Presentation transcript:

Trust Relationships in Grid CHEP 07 Mine Altunay

Organizational Structures Traditional organizations brick and mortar well-defined hierarchy up-down info flow face-face time everyone knows their place and responsibility Grid communities virtual flat organization side-side info flow willing collaboration limited face-face time

Trust: Essential ingredient in Grids Collaboration based on trust Trust is relationship between two parties such that one party believes the other one does what s/he promises to do Three key factors of a trust relationship: when time the parties should perform, clear start-end dates how under the conditions parties perform what actions they perform

How Grid participants cultivate trust Ad-hoc, immature process Use established contacts Meet face-face Phone your friends up Manual processing Current Automated processes to build, grow and monitor trust relationships Trust relationship lifecycle Cultivate transitive trust relationships Our Goal

Formalizing trust relationship Trust A (B, Action, Period, Cond) = Level of Assurance A’s trust in B to perform action under the condition cond during the time period is equal to the level of assurance LoA, where LoA Є (low, high, medium) Unidirectional, non-reflexive – A trust B ≠ B trusts A Transitive function – A trusts B, B trusts C  A trusts C

Benefits of Formalization Categorize trust relationships based on levels of assurance Monitor relationships Reach agreements between two parties – Well-defined expectations Promote collaborations

Trust Relationship Lifecycle Definition Categorization Agreement Publication Monitoring Termination Restoration Definition name the parties define actions define the conditions Categorization determine level of assurance Agreement reach an agreement over the trust relationship establish non-repudiation and traceability Publication publish the agreement to all involved parties use for monitoring Monitoring enforce the agreement sample behavior detect non-compliant behavior store info for future trust relationships Termination end the trust relationship Restoration restore the terminated trust relationship

Transitive Trust

VO #1 Site#1 VO#2 Site#3 Site#2 VO #1 Member Transitive relationships Transitive relationship

Transitive trust relationships Builds a web of trust Reduces one-one relationships Broadens available resources Eases collaboration

OSG VO Site register Ad-hoc VO Site Complete trust life-cycle -- Automated trust establishment -- Service-level agreements -- Agreed upon access rights -- Agreed usage policy -- Monitoring of trust -- enforcements (breach of agreements)

Trusting in Grid Trust: Essential Ingredient in Grids when  the time parties should perform how  under the conditions they perform what  actions they perform The Current meet face-face Phone your friends up Formalizing Trust relationship Trust A (B, Action, Period, Cond) = Level of Assurance A’s trust in B to perform action under the condition cond during the time period is equal To the level of assurance LoA, where LoA Є (low, high, medium) reach an agreement establish non-repudiation and traceability Definition Categorization Agreement Publication Monitoring Termination Restoration name the parties define actions define conditions determine level of assurance publish the agreement to all involved parties use for monitoring sample behavior detect non-compliance store info for future end the trust relationship restore the terminated relationship Trust Life-Cycle One-One Trust Relationships Benefits of Trust Formalization Categorize trust relationships based on levels of assurance Reach agreements between two parties Well-defined expectations Monitor relationships Enforcement of the agreements -- Unidirectional, non-reflexive A trust B ≠ B trusts A -- Transitive function A trusts B, B trusts C  A trusts C One-one trust VO #1 Site#1 VO#2 Site#3 Site#2 VO #1 member Transitive trust relationships Transitive trust relationship One-one trust One-one trust One-one trust One-one trust VO Site Complete trust life-cycle Automated trust establishment Service-level agreements Agreed upon access rights Agreed usage policy Monitoring of trust Enforcements (breach of agreements) register OSG VO Site register Ad-hoc missing link Our Goal Build web of trust Reduces one-one relationships Broadens available resources Eases collaboration Why essential ? What is it? Trust is a relationship between two parties such that one party believes the other one does what s/he promises to do hierarchical brick and mortar up-down info flow face-face time flat organization virtual side-side info flow willing collaboration Grid depends on collaborations Collaborations depends on trust Thus, grid depends on trust Grid community: vs. Traditional Organization How to formalize it ? How to accomplish it ? Our Goal The OSG process for establishing trust: registration agreements, agreed usage policies (AUP) OSG