Download presentation
Presentation is loading. Please wait.
Published byCoral Mathews Modified over 9 years ago
1
Open Science Grid & its Security Technical Group ESCC22 Jul 2004 Bob Cowles bob.cowles@slac.stanford.edu
2
22 Jul 2004ESCC - OSG & SecWG2 Open Science Grid u Open Science Grid is a consortium (not a project) in the US for ensuring our Grid efforts, including and in particular the LHC ones, come together towards a coherent and sustained Grid infrastructure that will u Include the US contribution to LCG u be Open from the start to other experiments and other sciences u Work and interoperates with the Grid infrastructure provided through EGEE u Evolve Grid3 to Open Science Grid for Production u Inclusive Partnerships with Computer Science, Information Technology, Other Sciences, Grid Projects etc…
3
22 Jul 2004ESCC - OSG & SecWG3 Towards a coherent sustained production Grid infrastructure u A 5-10 year roadmap to match life-cycle of Particle Physics Experiments committed to Grids for Data Analysis. u Start from the needs of our experiments today u End-to-end approach delivering to requirements and schedule of participating application communities. u A framework for a coherent system approach through joint projects across the members. u Cooperation across DOE & NSF, Universities and Laboratories, Projects, Middleware and Technology Groups, Experiments and Application Communities, Education and Workforce Development
4
22 Jul 2004ESCC - OSG & SecWG4 EGEE- OSG Partnership L. Bauerdick, L.Robertson
5
22 Jul 2004ESCC - OSG & SecWG5 BaBar, Run II SAMGrid, US Testbeds, Grid3, …an evolution u Babar data distribution with GridFTP & SRB u CDF and D0 >1.5 Petabytes in mass storage at Fermilab. SAMGrid data grid developed for distributed data simulation data analysis over >25sites. LIGO DataGrid for a coherent and uniform LIGO data analysis environment u Joint US-LHC, LIGO, SDSS and Computer Science Laboratory Grid3. u In use for US ATLAS DC2. US CMS gained 50% in overall throughput for 17Million event simulations. SDSS southern “coadd of objects” in progress. ANL GADU biology users. Computer science application demonstrators. D0 files transferred
6
22 Jul 2004ESCC - OSG & SecWG6 Enterprise Consortium Architecture Technical Groups 0…n (small) Consortium Board (1) Research Grid Projects VO Org Researchers Sites Service Providers Campus, Labs activity 1 activity 1 activity 1 activity 0…N (large) Joint committees (0… N small) Participants provide: resources, management, project steering groups OSG Process Framework
7
22 Jul 2004ESCC - OSG & SecWG7 Open Science Grid-0 u First Iteration of Production Infrastructure. u Goal to Launch in Feb ‘05. u Aligned with PPDG Laboratory Grid milestone u Will evolve from Grid3. u Blueprint giving guiding Principles and Technology Roadmap feeding into OSG-0 plans. u Most significant evolution from Grid3 is addition of Storage Services - Persistent at DOE Laboratories - Durable & Transient in many places- to common infrastructure.
8
22 Jul 2004ESCC - OSG & SecWG8 Security Technical Group u Started from an Evolution of PPDG SiteAA group u Reports to the OSG Collaboration Board - a broad mail list osg@opensciencegrid.org u Sponsoring Incident Response Activity u Extended membership with participants from Universities, TeraGrid and Earth System Grid: Bob Cowles (SLAC), Dane Skow (Fermilab), Mike Helm (ESNET), Doug Pearson (Indiana, iVDGL/iGOC), Von Welch (NCSA), Remy Evard (ANL), Tom Throwe (BNL), Doug Olson (LBNL), Veronika Nefedova (ESG)
9
22 Jul 2004ESCC - OSG & SecWG9 Security Technical Group-Mission The Security Technical group is responsible for coordinating the OSG activities that relate to security policy, practices and services. These include: Negotiation of common security principles and expectations for security across the Consortium. Development and oversight of common requirements and architecture for security management across the Consortium.◦ Identification of necessary projects and work needed for a coherent, complete Security infrastructure on the common grid. Interoperability of Security infrastructure across different administrative domains, initially OSG and EGEE through the LCG Joint Security Group. Publish information about security u Scope explicitly includes cooperation with the EGEE/LCG peer groups.
10
22 Jul 2004ESCC - OSG & SecWG10 Issues on the Table to Date u “Top ten” list ++ u How to organize ourselves u acting as both Joint Security Group + JRA3 + MWSG u how to have an impact u first priorities u How to collaborate effectively with u Joint Security Group u JRA3
11
22 Jul 2004ESCC - OSG & SecWG11 General tasks u Security deliverables u Authorization u One time password cross-site implementation u Coordination u across PPDG Projects, Experiments, Sites u with other grid projects, e.g. EGEE, ? u Operational Policies u Guides and Procedures for Sites including incident response and contact lists
12
22 Jul 2004ESCC - OSG & SecWG12 Coordination u Developer’s Guide u Installation & Configuration Guide
13
22 Jul 2004ESCC - OSG & SecWG13 Operational Policies u Cross-site federated authentication u Incident warning u Credential compromise u Machine / service compromise u Cross-grid reporting and warning u Incident Response u Action or information clearinghouse? u Higher-level reporting responsibilities?
14
22 Jul 2004ESCC - OSG & SecWG14 Deliverables u Authorization u SAzP (Simple AuthZ Protocol) definition and document guide for application development u Cross-site OTP u Generalize to federated authentication? u OTP u Kerberos u X.509 certificates u Policies & procedures for sites to follow u Actual implementation
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.