PaN-Data Meeting, October 4/5, 2010, Berlin Gen H.J. Weyer Overview Umbrella Project  Pan-EU Authentication  Proposal handling (prototype)  Coaching.

Slides:



Advertisements
Similar presentations
4th workshop, federated identity systems, Nymegen June 21/22, 2012Heinz J Weyer, PSI 1 1 Federated Identity and the Photon / Neutron Community.
Advertisements

EzScoreboard.com A Fully Integrated Administration Service.
Lousy Introduction into SWITCHaai
Trust Management of Services in Cloud Environments:
Author - Title- Date - n° 1 GDMP The European DataGrid Project Team
Chapter 19: Network Management Business Data Communications, 5e.
James Martin CpE 691, Spring 2010 February 11, 2010.
Dorian Grid Identity Management and Federation Dialogue Workshop II Edinburgh, Scotland February 9-10, 2006 Stephen Langella Department.
Chapter 19: Network Management Business Data Communications, 4e.
GRID DATA MANAGEMENT PILOT (GDMP) Asad Samar (Caltech) ACAT 2000, Fermilab October , 2000.
Slides for Grid Computing: Techniques and Applications by Barry Wilkinson, Chapman & Hall/CRC press, © Chapter 1, pp For educational use only.
1 ITC242 – Introduction to Data Communications Week 12 Topic 18 Chapter 19 Network Management.
June 1, 2001 Enterprise Directory Service at College Park David Henry Office of Information Technology University of Maryland College Park
1 An overview Always Best Connected Networks Dênio Mariz Igor Chaves Thiago Souto Aug, 2004.
Data Grid Web Services Chip Watson Jie Chen, Ying Chen, Bryan Hess, Walt Akers.
Office 365: Efficient Cloud Solutions Wednesday March 12, 9AM Chaz Vossburg / Gabe Laushbaugh.
FIM-ig Federated Identity Management Interest Group.
Project Proposal: Academic Job Market and Application Tracker Website Project designed by: Cengiz Gunay Client: Cengiz Gunay Audience: PhD candidates and.
WP6: Grid Authorization Service Review meeting in Berlin, March 8 th 2004 Marcin Adamski Michał Chmielewski Sergiusz Fonrobert Jarek Nabrzyski Tomasz Nowocień.
PaN-data WP4 - Users Gordon Brown STFC-e-Science Alun Ashton DLS Bill Pulford DLS.
Umbrella Federated Identity Management Workshop, Taipei, February 27, 2012Heinz J Weyer, PSI 1 1 Umbrella for Photon / Neutron Community.
Umbrella PaN-data ODI Kickoff meeting, STFC November 3/4, 2011Heinz J Weyer, PSI 1 1 PaN-data ODI WP3 User AAA Service (Umbrella System)
ESUO Meeting ALBA Umbrella AAI for Photon / Neutron Community M van Daalen 1 Mirjam van Daalen, Heinz Weyer, Björn Abt.
Jan Hatje, DESY CSS ITER March 2009: Alarm System, Authorization, Remote Management XFEL The European X-Ray Laser Project X-Ray Free-Electron.
1 Advanced Software Engineering Association for Computing Machinery High School Competition System Prof: Masoud Sadjadi Fall 2004 First Deliverable By:
1 Multi Cloud Navid Pustchi April 25, 2014 World-Leading Research with Real-World Impact!
U.S. Department of Agriculture eGovernment Program August 14, 2003 eAuthentication Agency Application Pre-Design Meeting eGovernment Program.
A Web Based Workorder Management System for California Schools.
Helsinki Institute of Physics (HIP) Liberty Alliance Overview of the Liberty Alliance Architecture Helsinki Institute of Physics (HIP), May 9 th.
SIMDAT Authentification and Autorisation Matteo Dell’Acqua ET-CTS meeting, Toulouse, May 2008.
Developments concerning the Community Plant Variety Office of the European Union (CPVO) online application system Meeting on the development of a prototype.
U.S. Department of Agriculture eGovernment Program July 15, 2003 eAuthentication Initiative Pre-Implementation Status eGovernment Program.
2005 JACoW Team Meeting Thomas Baron/Jose Benito Gonzalez – CERN – IT Managing Events with Indico.
The Grid System Design Liu Xiangrui Beijing Institute of Technology.
Advanced Software Engineering Association for Computing Machinery High School Competition System Prof: Masoud Sadjadi Fall 2004 First Deliverable By: Prasad.
Risk Management in the Province of Tyrol 2nd European Forum for Disaster Risk Reduction October 2011, Skopje Mag. Andreas Koler
Identity Management: A Technical Perspective Richard Cissée DAI-Labor; Technische Universität Berlin
Automated (meta)data collection – problems and solutions Grete Christina Lingjærde and Andora Sjøgren USIT, University of Oslo.
Jamie Hall (ILL). SciencePAD Persistent Identifiers Workshop PANData Software Catalogue January 30th 2013 Jamie Hall Developer IT Services, Institut Laue-Langevin.
State of e-Authentication in Higher Education August 20, 2004.
ESFRI & e-Infrastructure Collaborations, EGEE’09 Krzysztof Wrona September 21 st, 2009 European XFEL.
Ruth Pordes November 2004TeraGrid GIG Site Review1 TeraGrid and Open Science Grid Ruth Pordes, Fermilab representing the Open Science.
Community Sign-On and BEN. Table of Contents  What is community sign-on?  Benefits  How it works (Shibboleth)  Shibboleth components  CSO workflow.
Access Control for NCAR Data Portals A report on work in progress about the future of the NCAR Community Data Portal Luca Cinquini GO-ESSP Workshop, 6-8.
Connect. Communicate. Collaborate Deploying Authorization Mechanisms for Federated Services in the eduroam architecture (DAMe)* Antonio F. Gómez-Skarmeta.
CRISP 2 nd annual meeting PSI; WP 16 CRISP M van Daalen, PSI 1 Mirjam van Daalen, Heinz Weyer, Björn Abt.
Portal Services & Credentials at UT Austin CAMP Identity and Access Management Integration Workshop June 27, 2005.
2003 © SWITCH Authentication and Authorisation Infrastructure - AAI Christoph Graf Project Leader AAI SWITCH.
PanDATA Meeting DESY, June 18/ , WP2/Access O. Schwarzkopf, H.J. Weyer USER ACCESS IRUVX /WP2 + ESRFUP /WP9 PanDATA Meeting/ DESY June 18/
The Registration Alert System LCA Overview. Overview The Registration Alert System (RAS) is web-based software package that allows University of Washington.
EGI Technical Forum 2010, September 14, 2010, Amsterdam H.J. Weyer TOC Photon Facilities and Authentication  The environment  General boundary conditions.
The overview How the open market works. Players and Bodies  The main players are –The component supplier  Document  Binary –The authorized supplier.
1 A Scalable Distributed Data Management System for ATLAS David Cameron CERN CHEP 2006 Mumbai, India.
Thomas Gutberlet HZB User Coordination NMI3-II Neutron scattering and Muon spectroscopy Integrated Initiative WP5 Integrated User Access.
7 th Umbrella Harmonisation Meeting Zürich Airport M van Daalen, PSI 1 Retrospection Umbrella.
Store and exchange data with colleagues and team Synchronize multiple versions of data Ensure automatic desktop synchronization of large files B2DROP is.
CRISP WP 17 1 / 2 Proposed Metadata Catalogue Architecture Document.
Science Gateway and Single Sign-On technology study for the Cherenkov Telescope Array C. Vuerli (INAF), Giovanni Lamanna (LAPP/IN2P3/CNRS), Nadine Neyroud.
Windows Active Directory – What is it? Definition - Active Directory is a centralized and standardized system that automates network management of user.
The Umbrella Project Authentication The minimum user information possible is stored centrally to avoid Data Protection issues. The Authentication is done.
Community Sign-On and BEN. Table of Contents  What is community sign-on?  Benefits  How it works (Shibboleth)  Shibboleth components  CSO workflow.
Umbrella ID Status Mirjam van Daalen.
European photon/neutron facilities The User Umbrella System, Status and Future 1.
A Model for Grid User Management
Future Ideas: Federation and Integration
CRISP WP16 F2F Meeting, RAL Sep 27
WP18, High-speed data recording
Mirjam van Daalen, (Stephan Egli, Derek Feichtinger) :: Paul Scherrer Institut Status Report PSI PaNDaaS2 meeting Grenoble 6 – 7 July 2016.
ESA Single Sign On (SSO) and Federated Identity Management
Technical Outreach Expert
Presentation transcript:

PaN-Data Meeting, October 4/5, 2010, Berlin Gen H.J. Weyer Overview Umbrella Project  Pan-EU Authentication  Proposal handling (prototype)  Coaching  Remote experiment access  Remote data access  Publications  Indico (Integrated Digital Conference)  …

PaN-Data Meeting, October 4/5, 2010, Berlin Gen H.J. Weyer The Umbrella Concept User UOffice2UOffice1UOffice3 Fig.1

WP2 Face to Face Meeting, August 26/ , PSI H.J. Weyer User EUU Coaching Proposals More… WUO1 Central Part Local Part Shibboleth IdP User db Affiliation db EAA WUO2WUO3

PaN-Data Meeting, October 4/5, 2010, Berlin Gen H.J. Weyer IT Projects  Authentication (EU-unique (identification)  Proposal handling (thousands of proposals / year)  Coaching (support of novice users)  Remote experiment login (young scientists; Fedex-style experiments)  But more than authentication (e.g. fire wall, experiment standardization, component protocols …)  Remote data access (terabytes of data)  But more than authentication (e.g. data format, catalogues …) EuroFEL Umbrella prototype Next generation Umbrella Project

PaN-Data Meeting, October 4/5, 2010, Berlin Gen H.J. Weyer  Confidentiality o High competition, especially structural biology o Time-window structured access to experiments and data  User friendliness o Part-time users, small teams, no guru  Flexible, diverse solutions o Responding to diverse requests  Facility friendliness o Limited resources o Prevent any ‘bypass’ solutions  Keep local as much as possible  Distributed actions o Users: manage their personal entries o Facilities: manage their authorizations Required Solution Characteristics Umbrella Project

PaN-Data Meeting, October 4/5, 2010, Berlin Gen H.J. Weyer The Umbrella components, EAA Authentication, Requirements  User friendliness  Single sign on  Unique user identification on EU scale  Full autonomy for WUO’s  Dual EAA and WUO operation  No cross-facility information exchange  Users controls his/her personal info  Facilities control full info and authorization  No specific local software  Prevent ‘special’ databases AAA ≡ Authentication+Authorization+Accounting EAA ≡ European AAA WUO ≡ Web-based User Office (local) Umbrella Project

PaN-Data Meeting, October 4/5, 2010, Berlin Gen H.J. Weyer The Umbrella components, EAA Authentication, Realization  Handshake: Shibboleth, SAML  Hybrid DB, federated + central  Split of user info into central and local  Central= minimum for ID  Local= full + authorization  2-level authentication:  soft: newsletter, proposal  hard: facility access  Curation  User: registration, mutation  WUO: role assignment Uname Passw Birthday Uname Passw Birthday Phone Smail … Registrations Facility Roles … Phone Smail … Registrations Facility Roles … Facility A B C Local Central AAA ≡ Authentication +Authorization +Accounting EAA ≡ European AAA WUO ≡ Web-based User Office (local) Umbrella Project

PaN-Data Meeting, October 4/5, 2010, Berlin Gen H.J. Weyer EAA and WUO’s  WUO to EAA No automatic migration User see’s the EAA option on his local WUO and registers once on EAA May need to get a new Pan-EU user name (prevent multiple user names, nightmare for users!) But user can stay on WUO  EAA to WUO User decides where to go Login to new WUO: can pull his personal info stored at another WUO and push it to the new. Umbrella Project

PaN-Data Meeting, October 4/5, 2010, Berlin Gen H.J. Weyer The Umbrella components, EUU Proposal handling Proposer info Time request … Beamline Sample Proposer info Time request … Beamline Sample Goal Method Results Prev. Work … Goal Method Results Prev. Work … General Local UUU ≡ Unified User Umbrella EUU ≡ EuroFEL UUU (prototype) WUO ≡ Web-based User Office (local)  EUU: export, modify, and submit  Local (facility-specific) and general (scientific) part  Flexibility and confidentiality  Export-type mechanism: up-to-date format  Work on formal agreement  Local WUOs stay fully autonomous  No specific local software Umbrella Project

PaN-Data Meeting, October 4/5, 2010, Berlin Gen H.J. Weyer The Umbrella components EUU Coaching  Support of novice users FAQ (static) Coaching (dynamic)  Structured tool  Advice only  Responsibility always with user  Category tree  Experienced coaches needed Protected against excessive load But free to identify themselves Limited number of iterations  Coaches honored on peer basis  Interesting questions to FAQ db  Support of beamline managers Umbrella Project User Coordinator Coach 1Coach n… FAQ db

PaN-Data Meeting, October 4/5, 2010, Berlin Gen H.J. Weyer EuroFEL Authentication and Authorization (EAA) Interface to Central DB Central EAA Tool Interface to Affiliation DB Interface to WUO DB Parallel WUO And EAA Operation Adaption of WUO part User Update service Basic Communication Protocol Local WUO Update service WUO ≡ Web-Based User Office ( local) EAA ≡ EuroFEL Authentication EuroFEL Authentication

PaN-Data Meeting, October 4/5, 2010, Berlin Gen H.J. Weyer EuroFEL Unified User Umbrella (EUU) Communication protocol Interface to DUO WUO‘s Interface to Affiliation DB Interface to EAA Dialog With user Transfer Proposal to WUO Export proposal From WUO Unified User Umbrella and Coaching EuroFEL Coaching Interface to Affiliation DB Interface to Affiliation DB Interface to Affiliation DB Interface to SMIS WUO‘s WUO ≡ Web-Based User Office, existing local user office DUO ≡ WUO as developed at PSI SMIS ≡ WUO as developed at ESRF EAA ≡ EuroFEL Authentication

PaN-Data Meeting, October 4/5, 2010, Berlin Gen H.J. Weyer Proposed EUU/EAA Roadmap EAA (European Authentication and Authorization) Planning / DesignEUU (European User Umbrella)Prototype readyImplementation 0.5 FTE0.1 FTE EuroFEL / WP2 0.5 FTE

PaN-Data Meeting, October 4/5, 2010, Berlin Gen H.J. Weyer Status and Outlook (September 2010)  Architecture document + road map for prototype ready  Start development of 1 st - generation Umbrella prototype  Shibboleth  deadline March 31, 2011  Discussion 2 nd -generation Umbrella (remote functionalities)  ‘Actors’: o PaN-Data o EuroFEL o ESFRI-Cluster o HDRI Helmholtz  Tools: o GRID? o Specific development?  Type: o Facility-friendly + user-friendly o Two-level?  Slim, simple  Strong, full-beauty IT Umbrella Project

PaN-Data Meeting, October 4/5, 2010, Berlin Gen H.J. Weyer Science-political issues Facilities  Limited manpower  (Ideally) no additional load  No central octopus  Open-heart operation  WUO and EAA parallel operation  no dependence on new system, in principle could go back  Cooperation and competition  No central storage of proposals  Minimum central storage of user info (only for unique ID)  No X-facility exchange of authorization info  No X-facility access to personal user info  Distributed responsibility?  Event logging and confidentiality  To GRID or not to GRID  how much to modify?  support from GRID community?  must it be GRID? Or other system, e.g. Cloud?  Umbrella for GRID ad Cloud? Umbrella Project

PaN-Data Meeting, October 4/5, 2010, Berlin Gen H.J. Weyer Science-political issues Users  Be friendly to IT-skilled users  Cope with occasional, few-times-per-year users  Cope with multi-facility users  No central octopus  Allow multi-level authentication (soft, hard)  No need for special software at user site  Few-month stands  Allow flexible definition of research teams, responsibility delegated to spokespersons  Time-windowed access to experiment data  PhD-Students and Postdocs  Quick registration of users  Foresee remote experiment access  Greenhorns  Coaching Umbrella Project