CALIPSO kick off 30.-31.10.2012; Elettra Umbrella AAI for Photon / Neutron Community M van Daalen 1 Mirjam van Daalen, Heinz Weyer, Björn Abt.

Slides:



Advertisements
Similar presentations
4th workshop, federated identity systems, Nymegen June 21/22, 2012Heinz J Weyer, PSI 1 1 Federated Identity and the Photon / Neutron Community.
Advertisements

Federated Identity Management for Researchers – A quick overview from GÉANT BoF TNC May 2014 Dublin.
Slide: 1 Welcome to the workshop ESRFUP-WP7 User Single Entry Point.
Introduction on WP7/WP9 Dominique PORTE 29/05/2008 Menu What is WP7? What is WP9? Goal of the brainstorming Introduction on WP7/WP9.
ECM27, Bergen DDD Workshop August 6, 2012Heinz J Weyer, PSI 1 1 ECM27 Workshop on Data Diffraction Deposition.
Federated Identity Management for Research Communities (FIM4R) David Kelsey (STFC-RAL) EGI TF, AAI workshop 19 Sep 2012.
PaNdata Photon and Neutron Data Infrastructure I2S2Meeting 1 April 2011 Juan Bicarregui.
EMI INFSO-RI Session Summary AAI Needs for DCIs John White, HIP Christoph Witzig, SWITCH
2 nd Data without Boundaries Training Course Bucharest, February 2013.
FIM-ig Federated Identity Management Interest Group.
PaN-data WP4 - Users Gordon Brown STFC-e-Science Alun Ashton DLS Bill Pulford DLS.
1 Large-scale Data Processing Challenges David Wallom.
Umbrella Federated Identity Management Workshop, Taipei, February 27, 2012Heinz J Weyer, PSI 1 1 Umbrella for Photon / Neutron Community.
Umbrella PaN-data ODI Kickoff meeting, STFC November 3/4, 2011Heinz J Weyer, PSI 1 1 PaN-data ODI WP3 User AAA Service (Umbrella System)
ESUO Meeting ALBA Umbrella AAI for Photon / Neutron Community M van Daalen 1 Mirjam van Daalen, Heinz Weyer, Björn Abt.
Federated Identity Management for HEP David Kelsey WLCG GDB 9 May 2012.
NMI3 Meeting Umbrella AAI for Photon / Neutron Community M van Daalen 1 Mirjam van Daalen, Heinz Weyer, Björn Abt.
CRISP WP17 2/2 Data Continuum Achievements & Perspectives 18th March 2013Jean-François Perrin - Institut Laue Langevin - CRISP 2nd Annual Meeting1.
Dr. Cecilia Blasetti - Elettra ST Elettra I3 IA-SFS Managing team Role of scientific background Dr. Cecilia Blasetti Elettra - Sincrotrone Trieste iii.
Jamie Hall (ILL). SciencePAD Persistent Identifiers Workshop PANData Software Catalogue January 30th 2013 Jamie Hall Developer IT Services, Institut Laue-Langevin.
WP18: High-Speed Data Recording Krzysztof Wrona, European XFEL 07 October 2011 CRISP.
ESFRI & e-Infrastructure Collaborations, EGEE’09 Krzysztof Wrona September 21 st, 2009 European XFEL.
7 th Pan-Data & CRISP Harmonisation Meeting Zürich Airport EduGain-Bridge and Moonshot for Umbrella Production B.Abt PSI 1 Björn Abt.
Simplified Experiment Submit Proposal Results Excited Users Do Expt Data Analysis Feedback.
PaNdata ODI Open Data Infrastructure INFRA : Data infrastructures for e-Science PaNdata-ODI will develop, deploy and operate an Open Data Infrastructure.
CRISP 2 nd annual meeting PSI; WP 16 CRISP M van Daalen, PSI 1 Mirjam van Daalen, Heinz Weyer, Björn Abt.
PanDATA Meeting DESY, June 18/ , WP2/Access O. Schwarzkopf, H.J. Weyer USER ACCESS IRUVX /WP2 + ESRFUP /WP9 PanDATA Meeting/ DESY June 18/
PaN-Data Meeting, October 4/5, 2010, Berlin Gen H.J. Weyer Overview Umbrella Project  Pan-EU Authentication  Proposal handling (prototype)  Coaching.
A European Open Science Cloud
EGI Technical Forum 2010, September 14, 2010, Amsterdam H.J. Weyer TOC Photon Facilities and Authentication  The environment  General boundary conditions.
Networks ∙ Services ∙ People Thomas Bärecke Journée Fédération, Paris Collaboration européenne GÉANT SA5 03/07/2015 SA5 T5 team
CRISP Topic Meeting ESRF, WP 16 CRISP M van Daalen, PSI 1 Mirjam van Daalen.
Networks ∙ Services ∙ People Marina Adomeit FIM4R meeting Virtual Organisation Platform as a Service VOPaaS Nov 30, 2015, Austria Task Leader,
TIARA – WP6 Involving Industry in TIARA Lucio Rossi (WPD) CERN.
Thomas Gutberlet HZB User Coordination NMI3-II Neutron scattering and Muon spectroscopy Integrated Initiative WP5 Integrated User Access.
AAI needs of the Distributed Computing Infrastructures - CLARIN Dieter Van Uytvanck Max Planck Institute for Psycholinguistics
Case Studies in Federated Identity Management for Research Communities Ann Harding, SWITCH/GN3plus Peter Gietz, DAASI International GmbH/DARIAH Tommi Nyro.
Connect communicate collaborate Case Studies in Federated Identity Management for Research Communities Ann Harding, SWITCH/GN3plus Peter Gietz, DAASI International.
7 th Umbrella Harmonisation Meeting Zürich Airport M van Daalen, PSI 1 Retrospection Umbrella.
CRISP WP18, High-speed data recording Krzysztof Wrona, European XFEL PSI, 18 March 2013.
E-infrastructure requirements from the ESFRI Physics, Astronomy and Analytical Facilities cluster Provisional material based on outcome of workshop held.
Networks ∙ Services ∙ People Marina Adomeit TNC16 Conference, Prague Towards a platform for supporting collaboration GÉANT VOPaaS
The Umbrella Project Authentication The minimum user information possible is stored centrally to avoid Data Protection issues. The Authentication is done.
CERN IT Department CH-1211 Genève 23 Switzerland Federated identity system for scientific collaborations Summary of user requirements session.
The ESUO-wayforlight collaboration in 2015 and 2016 Cecilia Blasetti International Project Officer Umbrella 2016 Meeting - ALBA 23/09/16.
Status Umbrella ID Mirjam van Daalen.
Status Umbrella ID Mirjam van Daalen.
Umbrella ID Status Mirjam van Daalen.
WP18, High-speed data recording Krzysztof Wrona, European XFEL
Budget JRA2 Beneficiaries Description TOT Costs incl travel
Introduction the IT and DM Topic
7th Umbrella Harmonisation Meeting
Status Umbrella AAI Photon / Neutron community
Case Studies in Federated Identity Management for Research Communities
Umbrella AAI Photon / Neutron community
European photon/neutron facilities The User Umbrella System, Status and Future 1.
Future Ideas: Federation and Integration
CRISP WP16 F2F Meeting, RAL Sep 27
Mirjam van Daalen:: Paul Scherrer Institut
Umbrella AAI Photon / Neutron community
Pandata Service Verification
PaNdata ODI WP3 User Catalogue and AAI Service
PaNdata Photon and Neutron Data Infrastructure Juan Bicarregui
ELIXIR Safeguarding the results of life science research in Europe
WP18, High-speed data recording
Mirjam van Daalen, (Stephan Egli, Derek Feichtinger) :: Paul Scherrer Institut Status Report PSI PaNDaaS2 meeting Grenoble 6 – 7 July 2016.
EGI Webinar - Introduction -
Mirjam van Daalen, (Stephan Egli, Derek Feichtinger) :: Paul Scherrer Institut Status Report PSI PaNDaaS2 meeting Grenoble 12 – 13 December 2016.
Status JRA2 WP24 Demonstrator of a Photon Science Analysis Service (DaaS) Mirjam van Daalen 6/28/2019 Mirjam van Daalen PSI.
Umbrella ID Federated Identity for PaN facilities
Presentation transcript:

CALIPSO kick off ; Elettra Umbrella AAI for Photon / Neutron Community M van Daalen 1 Mirjam van Daalen, Heinz Weyer, Björn Abt

CALIPSO kick off ; Elettra M van Daalen, PSI 2 Umbrella is the revolutionary AAI concept for the Photon and Neutron community It is the first time that such a kind of IT environment is offered European wide Community overlapping Shared between different EU projects

CALIPSO kick off ; Elettra M van Daalen, PSI 3 Umbrella is part of several FP7 projects: EuroFEL- ESFRI project Free Electron Lasers of Europe PaNData-Europe, PaNData ODI- FP7 projects CRISP – Cluster project of different ESFRI projects CALIPSO – renewal of I3 ELISA FP7 NMI3 - I3 neutron community BioStruct-X – renewal of I3 ELISA FP7 (only struct. biol) Instruct – ESFRI project

CALIPSO kick off ; Elettra M van Daalen, PSI 4 How does it work?

CALIPSO kick off ; Elettra M van Daalen, PSI 5 Peter Fischer has 4 different accounts at photon and neutron research facilities. He has to remember 4 different username and password combinations. Probably 4 different tools for data access. Current Situation

CALIPSO kick off ; Elettra M van Daalen, PSI 6 1.Peter Fischer creates an Umbrella account. 2.Connection of the Umbrella account with the 4 existing accounts at other research facilities by login in to the application. 3.From now on only Umbrella username and password necessary to get access to all his existing accounts. 4.The existing accounts are now permanently linked with each other. 5.The link can be removed if e.g. an account ceases to exist. 6.This link acts as a common basis for tools which can exploit synergies between facilities, e.g. standardized tools for data access to facilities. The Umbrella Concept

CALIPSO kick off ; Elettra M van Daalen, PSI 7 Peter Fischer creates an Umbrella account Option 1: P. Fischer has a user account at a facility (e.g. PSI): 1.Enters PSI user office DUO (local WUO). 2.He extends his DUO account to an Umbrella account (once only). 3.He links his Umbrella account to his accounts at other facilities (once only). 4.Based on Umbrella he can link to a new facility and create a new account by transferring his credentials from Umbrella to the new WUO. Option 2 P. Fischer has no user account: 0. P. Fischer has to open an account at a user facility. 1.Local WUO account is needed Umbrella Concept

CALIPSO kick off ; Elettra M van Daalen, PSI 8 o The Umbrella tool was developed first in WP2 of the EuroFEL ESFRI project „User needs and policies“ (lead H. Weyer, O. Schwarzkopf). o WP2 defined a general access policy, and developed the Umbrella authentication and authorisation prototype tool. Coaching of new users as well as proposal handling were part of this developments. o Umbrella should guarantee efficient and transparent use of all distributed FEL facilities and beamlines involved. Based on these procedures, a web-based access point was foreseen. o EuroFEL ended on the and the MoU was signed on the The Umbrella project though did not stop and was carried on with first under the PaNData Europe project and now und the PaNData ODI and CRISP projects. Initiation of Umbrella

CALIPSO kick off ; Elettra M van Daalen, PSI 9 PaNdata Partners Alba, Spanish National Sychrotron Facility Diamond UK Synchrotron facility European Synchrotron Radiation Facility (ESRF) Elettra Sinchrotrone Trieste Deutsches Elektronen Synchrotron (DESY) Institut Laue–Langevin (ILL) Max IV Laboratory Lund ISIS STFC Neutron source HZB, Helmholtz Zentrum Berlin Paul Scherrer Institut (PSI), hosting SINQ and SLS Soleil, French National Synchrotron Facility

CALIPSO kick off ; Elettra PaNData Europe / ODI P SI, PaNdata Europe ( ), PaNData ODI ( ). PANdata brings together European synchrotron, FEL and neutron research infrastructures to create an information infrastructure supporting the scientific process. It aims to provide user communities with data repositories and data management tools to access, analyse and archive large data sets. PaNdata is working together with CRISP to achieve some of these aims. PSI has the lead of WP3 object: Umbrella as solution of the FIM demands.

CALIPSO kick off ; Elettra M van Daalen, PSI 11 CRISP IT Partners European Synchrotron Radiation Facility (ESRF) Deutsches Elektronen Synchrotron (DESY) European Organisation for Nuclear Research (CERN) European Spallation Source (ESS) GSI Helmholtz Centre for Heavy Ion Research (GSI) Institut Laue–Langevin (ILL) European X-ray Free Electron Laser (XFEL) Paul Scherrer Institut (PSI)

CALIPSO kick off ; Elettra CRISP P SI, CRISP: Cluster of Research Infrastructures and Synergies in Physics Objective: Build up collaborations and create long-term synergies. Facilitate the implementation and enhance the efficiency and attractiveness of the (future) RIs. Who: Initial group of eleven ESFRI-PPs projects (EuroFEL, ELI, EU XFEL, FAIR, ILL2020, ESRF up, ESS, Spiral2, ILC) The project is divided in to four main topics: 1) Accelerators, 2) Instruments & Experiments, 3) Detectors & Data Acquisition, and 4) Information Technology & Data Management. PSI lead of WP 16, objective: to develop and deploy a pan-european system for unique identification (Authentication and Authorisation infrastructure) AAI for all users of the participating RI‘s Umbrella for Pan European services: account management, proposal management, remote data access, remote experiment resource access

CALIPSO kick off ; Elettra M van Daalen, PSI 13 CALIPSO Partners ALBA, Spanish National Sychrotron Facility AU University Aarhus CNRS Centre National de la Rescherche Scientifique DESY Deutsches Elektronen Synchrotron Diamond UK Synchrotron facility EMBL European Molecular Biology Laboratory ESRF European Synchrotron Radiation Facility HZB, Helmholtz Zentrum Berlin HZDR Helmholtz Zentrum Dresden Rossendorf INFN Istituto Nazionale di Fisica Nucleare KIT Karlsruhe Institute of Technology Max IV Laboratory Lund Paul Scherrer Institut (PSI) Soleil, French National Synchrotron Facility Solaris TARLA XFEL European XFEL

CALIPSO kick off ; Elettra CALIPSO P SI, CALIPSO: Coordinated Access to Lightsources to Promote Standards and Optimization Objective: funding of transnational user acces. Who: 8FEL’s, 14 synchrotrons PSI lead of subtask 2.1.2, objective: Umbrella as a pan-European user support system.

CALIPSO kick off ; Elettra Umbrella as basis Umbrella is the basic IT environment to get access to common software tools used in the community such as: Moonshot (non web based acces) iCAT (metadata catalogue) and many others to come in the future Umbrella iCAT Moonshot Others Umbrella iCAT Moon- shot Others

CALIPSO kick off ; Elettra M. Van Daalen, PSI 16 Umbrella was tested by friendly users February 1 – March Central Applications that were tested Prototype of central Umbrella web site EAA: registration, mutation Examples for bridging: Alfresco, Indico, Issue tracker, Wiki Participants Facilities: DESY, Diamond (iCAT service, Moonshot), ESRF, PSI ‘Friendly’ users ~30, all over EU External expert users (ETH, BioStruct, and others) Local facility experts (DESY) Feedback In spite of the very early development stage (only initial functionalities) Highly welcomed by the users Status Umbrella

CALIPSO kick off ; Elettra M van Daalen, PSI 17 With Umbrella we try to use synergies on EU level: Using synergies between these different EU projects. Not invent the wheel twice. Harmonisation meetings every 6 months (partners of all the projects) We take part in Federated Identity Meetings (different communities) every 6 months Implementation of Umbrella planned for spring 2013 Other communities are interested in Umbrella Umbrella cited in TERENA AAI paper Status Umbrella

CALIPSO kick off ; Elettra M van Daalen, PSI 18 Concept Unique + persistent user identification on EU scale Single sign on Hybrid information storage No possibility for cross-facility information pull Multi-level identification, different for different actions (maximum autonomy to facilities) Waterproof but slim data protection system Incorporate confidentiality aspects High competition, especially structural biology Time-window-structured access to experiments and data Umbrella Characteristics

CALIPSO kick off ; Elettra M van Daalen, PSI 19 Rely on existing local user office structure Great experience DIY (Do It Yourself) operation  Users: manage their personal entries  User offices: supervising; manage authorizations  Principal investigators: have responsability for their teams and can handle authorisation within their group Base system on professional authentication standard Shibboleth, federated Single-Sign-On System (SAML), widely used Special photon / neutron user federation Supervising by local User Offices Umbrella Characteristics

CALIPSO kick off ; Elettra M van Daalen,, PSI 20 Next steps before implementation 2 implementation teams (representatives of participating institutions) harmonisation meeting twice a year Legal issues (MoU for continuation after the end of CRISP & PaNdata projects) Affiliation data base (ESRF) Sync with other programs o iCAT meetings (ILL, RAL) o Moonshot (non web based access) (JANET; SWITCH) o Harmonized proposal handling (format) (CALYPSO, NMI3) Overlapping IT communities, bridging Edugain (large research institutes, universities) Other federations (e.g. GRID; google; industry) Umbrella Website Umbrella next steps

CALIPSO kick off ; Elettra M van Daalen, PSI 21 Facilities Keep existing administration structures as much as possible During implementation parallel operation o smooth transition o No time-zero Users DIY (Do It Yourself) operation o Users: manage their personal entries o User offices: supervising; manage authorizations Collaborations Self organization of data access via collaborations Principal investigator / main proposer controls who is allowed to access data Applications Multi-level trust applications define level Lowest level: Google-type handshake Higher level: explicit authentication at facility user offices Operational concept

CALIPSO kick off ; Elettra M van Daalen, PSI 22 What are the IT requests? Huge datasets Novel 2D detectors, quantum leap in data quality, but also data volumes Multi-image techniques (tomography, lens-less imaging) Molecular movies at FELs ‘Petabyte’ ‘normal’ unity; time over for ‘hard-disk in the trouser pocket’ Trans-facility experiments Single Sign On (SSO) Standardize proposal procedures on EU scale Remote data access Analyze data remotely at facility Combine datasets taken at different facilities Clouds (commercial, community-based) Respect confidentiality restrictions Remote experiment access Basic: passive online access to measured data Advanced: active control

M. van Daalen, PSI 23 ALBA  Joachim Metge, Sergio Vicente DESY  Frank Schluenzen, Rolf Treusch, Jan-Peter Kurz, Ulrike Lindemann Fermi/Elettra  Cecilia Blasetti, Ornela Degiacomo, Giorgio Paolucci ESRF  Rudolf Dimper, Dominique Porte, Stefan Schulze European XFEL  Krzysztof Wrona GSI  Peter Malzacher, Almudena Montiel HZB  Thomas Gutberlet, Dietmar Herrendoerfer, Olaf Schwarzkopf I LL  Jean-Francois Perrin IPJ (Poland)  Robert Nietubic MaxLAB  Ulf Johansson PSI  Bjoern Abt, Stephan Egli, Stefan Janssen, Markus Knecht, Mirjam van Daalen, Heinz J Weyer Soleil  Frederique Fraissard STFC  Anthony Gleeson, Bill Pulford Umbrella collaborators 23

CALIPSO kick off ; Elettra Thank you for your attention! M van Daalen, H. Weyer PSI 24

CALIPSO kick off ; Elettra Operation Concept Heinz J Weyer, PSI 25  Facilities Keep existing administration structures as much as possible o Proposal workflow o Guest house / restaurant, access badges, stock room, … During implementation parallel operation o smooth transition o No time-zero  Users DIY (Do It Yourself) operation o Users: manage their personal entries o User offices: supervising; manage authorizations  Collaborations Self organization of data access via collaborations Principal investigator / main proposer controls who is allowed to access data  Applications Multi-level trust applications define level Lowest level: Google-type handshake Higher level: authentication at facility user offices, no external ?? Bottom-up: Delegation and direct feedback

CALIPSO kick off ; Elettra M. van Daalen, PSI 26 Pjxx User3 User4 User1 User2 User5 PpA1 Data1 PpA1 User1 User3 User5 PpB1 User1 User3 User5 PpB2 User1 User2 PpC1 User3 User4 User5 Pjyy User2 Pjzz User4 User5 PpA1 DataN …. PpB1 Data1 PpB1 DataN …. PpB2 Data1 PpB2 DataN …. PpC1 Data1 PpC1 DataN …. Facility A Facility B Facility C Users User Level Projects Project Level ProposalsExperiments / Data Facility Level User3 User1 User3 User5

CALIPSO kick off ; Elettra Heinz J Weyer, PSI 27 Umbrella and BioStruct 27 WUO3WUO2 WUO1 Central BioStruct User Office User c) BioStruct with Umbrella Central Umbrella WUOS1 Facility Web-based User Offices Other BioStruct services WUOS2 WUO3WUO2WUO1 b) BioStruct as present present Facility Web-based User Offices Central BioStruct User Office User Other BioStruct services WUO3WUO2WUO1 User a) Standard Facility Web-based User Offices