Presentation is loading. Please wait.

Presentation is loading. Please wait.

Www.epikh.eu The EEPIKH Project (Exchange Programme to advance e-Infrastructure Know-How) Giuseppe Andronico, on behalf of Giuseppe LA ROCCA INFN Catania.

Similar presentations


Presentation on theme: "Www.epikh.eu The EEPIKH Project (Exchange Programme to advance e-Infrastructure Know-How) Giuseppe Andronico, on behalf of Giuseppe LA ROCCA INFN Catania."— Presentation transcript:

1 www.epikh.eu The EEPIKH Project (Exchange Programme to advance e-Infrastructure Know-How) Giuseppe Andronico, on behalf of Giuseppe LA ROCCA INFN Catania giuseppe.larocca@ct.infn.it The GENIUS Grid Portal

2 Introduction GENIUS/EnginFrame: new version 4.1 VOMS Proxy Init Service Robot Certificates Summary and Conclusions Outline

3 Grid technology allows users to share a wide pletora of distributed computational resources regardless of their geographical location. Virtual services are exposed to the users through rather complex Command Line Interfaces or API languages. Grid security is indeed based on the Public Key Infrastructure (PKI) of X.509 certificates and the procedure to get and manage those certificates is unfortunately not straightforward; Up to now, the high security policy required to access distributed computing resources has been a rather big limiting factor when trying to broaden the usage of Grids into a wide community of users; + + Introduction

4 User has to adhere to a Virtual Organization (VO) User needs an account on one of the trusted User Interface (UI) + + = Grid portals provide an added value to make Grids more appealing for non-expert users.

5 A grid portal: why and how It can be accessed from everywhere and by “everything” (desktop, laptop, PDA, cell phone). It can keep the same user interface to several back-ends. It must be redundantly “secure” at all levels: – 1) secure for web transactions, – 2) secure for user credentials, – 3) secure for user authentication, – 4) secure at VO/VOMS level. All available grid services must be incorporated in a logic way, just “one mouse click away”. Its layout must be easily understandable and user friendly. 5

6 Grid Portal Benefits A Grid Portal improves usability of Grids – Lowering end-user requirements for accessing the Grid – Hiding the complexity of data and job services management in the Grid A Grid Portal improves utilization of Grids – Making the Grid (r)evolution transparent to the end-user – Providing an appealing user-friendly Web interface – Enforcing Grid utilization policies

7 Interactive Applications Intranet Clients Win LX UXMac Grid / Compute Farm Internal Users Batch Applications Storage and Data Grid Portal / Gateway Project Managers Client Apps Standard protocols Licenses Home Users The Grid Portal / Gateway

8 Introduction GENIUS/EnginFrame: new version 4.1 VOMS Proxy Init Service Robot Certificates Summary and Conclusions

9 What is EnginFrame ? It is a web-based technology able to expose Grid services running on Grid infrastructures It allows organizations to provide application- oriented computing and data services to both users (via Web browsers) and applications (via SOAP/WSDL and/or RSS) ‏ It’s a Grid gateway It greatly simplifies the development of Web Portals exposing computing services that can run on a broad range of different computational Grid systems

10 Spoolers HTML page Custom plugin Script Browser SDF XML EnginFrame Server HTML XSLT Grid Compute Farm Grid Compute Farm MetaFrame + NFuse MetaFrame + NFuse Application Server Application Server EnginFrame Agent Execute Service Req XML output Service Req User Authorize Groups, ACLs XML Layout XSL Service Submission EnginFrame Working Environment

11 gzip sample maximum medium none EF_SPOOLER_NAME="gzip $file” export EF_SPOOLER_NAME ${EF_ROOT}/plugins/lsf/bin/bsub -o output.txt gzip -$level \"$FILE\” Service example

12 Who does use EnginFrame? Mechanical – Ferrari, Audi, BMW, FIAT Auto, Elasis, Magneti Marelli, P+Z, Swagelok, Toyota, TRW Manufacturing – Bridgestone, Procter & Gamble, Galileo Avionica Oil&Gas – Slavneft, Schlumberger, TOTAL, VNIIGaz Electronics – STMicroelectronics, Accent, SensorDynamics, Motorola Biotech – ENEA, EGEE LS community Telecom – Telecom Italia Research – INFN, ASSC, CCLRC, CERN, CILEA, CINECA, CNR, CNRS/IN2P3, ENEA, FzU, ICI, IFAE, ITEP, JSC G.G.M., KU Leuven, SSC-Russia, SDSC Education – Dresda University, Ferrara University, ITU, Messina University, Politecnico of Milan, Technische Universit ä t Dresden, Trinity College Dublin, Salerno University, S-PACI

13 What is GENIUS ? GENIUS is a powerful Grid Portal that allows scientists to exploit Grid resources only using a conventional Web browser It has been built on top of the EnginFrame framework It’s a gateway to European EGEE Project middle-ware It allows to expose gLite-enabled applications via Web- browser as well as Web Services www.enginframe.com www.nice-italy.com www.infn.it

14 What is GENIUS ?

15 GENIUS: Grid Preferences

16 GENIUS: Job Submission 16

17 GENIUS: Job Submission 17

18 Code for Job Queue management rewritten using GridML tags GENIUS: Job(s) Queue

19 New Confirmation Message! GENIUS: Job Retrieving

20 GENIUS: Data Spooler

21 Tight VNC GENIUS: Interactive Services

22 GENIUS: Data Management 22 Local Browse on laptop Remote Browse on UI (GENIUS Server) Extended Remote File Browse on LFC Catalog

23 23 Extended Multiple Remote File Browsing on Catalog! GENIUS: Data Management

24 24 GENIUS: Workflow

25 25 GENIUS: Workflow

26 26 GENIUS: Workflow

27 27 GENIUS: Workflow

28 28 GENIUS: Workflow

29 29 GENIUS: Workflow

30 Introduction GENIUS/EnginFrame: new version 4.1 VOMS Proxy Init Service Robot Certificates Summary and Conclusions

31 VOMS Proxy Init Service A CAPTCHA Code is required to start the VOMS Proxy Applet for the proxy initialization The Java plugin 1.6.0 or higher is mandatory required.

32 Jointly developed by NICE and INFN Catania VOMS Proxy Init Service

33

34

35

36

37 Introduction GENIUS/EnginFrame: new version 4.1 VOMS Proxy Init Service Robot Certificates Summary and Conclusions

38 Robot certificates in a nutshell Robot certificates have been introduced to permit users, who are not familiar with deal personal certificates and don’t belong to any VOs, to experience the Grid paradigm for research activity and reduce the initial barriers. –They are extremely useful for instance to automate grid service monitoring, data processing production, distributed data collection systems. –Basically these certificates can be used to identify a person responsible for an unattended service or process acting as client and/or server.

39 Robot certificates in a nutshell In order to strong reduce the risks to have the portal certificate compromised the INFN CA decided to issue this new certificate on board of the Aladdin eToken PRO 32K smart card. Each smart card can support several robot certificates: one for each application user wants to share with the other. – An user’s PIN is prompted every time user try to read the certificate stored on the smart card to generate a proxy. – A first prototype of Grid Portal using robot certificate to generate an user’s proxy has been successfully designed.

40 1. ask for a service 2. create a proxy with the robot certificate 5. get the results 3. execute action 4. get output 2’,3’. track user User Admin The GENIUS Portal & Robot Certificates

41 The Users Tracking System (UTS) ACL-based services that enable easier access control customization for users not belonging to any group!

42 Porting the „MrBayes” application to Grid Case study from CNR - ITB

43 General Introduction MrBayes is a program for the Bayesian estimation of phylogeny. Bayesian inference of phylogeny is based on the posterior probability distribution of trees, which is the probability of a tree conditioned on the observations. – To approximate the posterior probability distribution of trees MrBayes uses a simulation technique called Markov Chain Monte Carlo (or MCMC). The program takes as input a character matrix in a NEXUS file format. The output is several files with the parameters that were sampled by the MCMC algorithm. The application is CPU demanding, especially if the MPI version of the software is used.

44 Phylogenetic analysis on large scale WMS LFC Catalog SE Robot Certificate UI + GENIUS Portal Job Submission Tool GRID

45 JST characteristics Job Submission Tool: is driven by the concept of “Task” as the applications are – Each task could be independent or could be described as depended from another “Task” – Each task is described by a “status” – The task is executed by a wrapper that takes care of monitoring the task:  If the task is correctly executed the wrapper can change the status of the task from “Free” to “Done”  If a single step on the job execution fails, the whole task is considered failed and automatically rescheduled JST tool takes care of submitting jobs, retrieving the output and monitoring the status of each task It is able to deal with accidental failure of grid services It is possible to change at run time the priority of each task/application

46 Web Interfaces & Video https://glite-tutor1.ct.infn.it

47 Introduction GENIUS/EnginFrame: new version 4.1 VOMS Proxy Init Service Robot Certificates Summary and Conclusions

48 GENIUS offers the following advantages: it is a complete production-ready environment which combines the concepts of “user portal” and “science portal”; absolutely no client software needs to be installed on the user’s workstation apart from the web browser with its usual plug-ins like Java (at least JRE 1.6.0 or higher); it provides a new unique tool to authorize users, in a very strong secure way, into the grid environment with or without VOMS support as well, easy to use; it includes support for both single and composite jobs (including DAG’s); interactive analysis and web access to personal spooling areas are possible; environment and settings customizable for the users; security for data management and sessions.

49 References NICE web-site http://www.nice-italy.comhttp://www.nice-italy.com EnginFrame Framework http://www.enginframe.com http://www.enginframe.com GENIUS Portal https://genius.ct.infn.ithttps://genius.ct.infn.it GENIUS Repository at https://geniuscvs.ct.infn.ithttps://geniuscvs.ct.infn.it GENIUS based on gLite at https://glite- tutor.ct.infn.ithttps://glite- tutor.ct.infn.it GENIUS Installation GENIUS Repository at https://geniuscvs.ct.infn.ithttps://geniuscvs.ct.infn.it Write an email message to alberto.falzone@nice- italy.com or nicola.venuti@nice-italy.com for an account request to download the GENIUS packagealberto.falzone@nice- italy.comnicola.venuti@nice-italy.com


Download ppt "Www.epikh.eu The EEPIKH Project (Exchange Programme to advance e-Infrastructure Know-How) Giuseppe Andronico, on behalf of Giuseppe LA ROCCA INFN Catania."

Similar presentations


Ads by Google