Www.egi.eu EGI-InSPIRE RI-261323 www.egi.eu EGI-InSPIRE RI-261323 EGI-InSPIRE EGI services for the long tail of science Peter Solagna Senior Operations.

Slides:



Advertisements
Similar presentations
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
Advertisements

EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI GGUS user authentication Tiziana Ferrari/EGI.eu Peter Solagna/EGI.eu
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI - Identity Management Steven Newhouse Director, EGI.eu Federated Identity.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI support for scientific communities Gergely Sipos EGI.eu Technical Outreach.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI Security Policy Group Summary EGI TF David Kelsey 6/28/
EGI-Engage EGI-Engage Engaging the EGI Community towards an Open Science Commons Project Overview 9/14/2015 EGI-Engage: a project.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Future support of EGI services Tiziana Ferrari/EGI.eu Future support of EGI.
EGI-InSPIRE RI EGI-InSPIRE RI European Grid Infrastructure: status and services for users 04/11/ Gergely Sipos.
European Grid Initiative Federated Cloud update Peter solagna Pre-GDB Workshop 10/11/
EMI AAI Strategy & Plans John White / Helsinki Institute of Physics Federated Identity Systems for Scientific Collaborations Workshop , CERN,
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI Federated Cloud F2F Security Issues in the cloud Introduction Linda Cornwall,
Evolution of the Open Science Grid Authentication Model Kevin Hill Fermilab OSG Security Team.
RI EGI-InSPIRE RI EGI Future activities Peter Solagna – EGI.eu.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Enforcement of the personal data retention policy Peter Solagna, EGI.eu WLCG.
Summary of AAAA Information David Kelsey Infrastructure Policy Group, Singapore, 15 Sep 2008.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI (Present and) Future of the EGI Services for WLCG Peter Solagna – EGI.eu.
Authentication and Authorisation for Research and Collaboration Peter Solagna Milano, AARC General meeting Current status and plans.
DTI Mission – 29 June LCG Security Ian Neilson LCG Security Officer Grid Deployment Group CERN.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI and MeDIA Steven Newhouse EGI.eu MeDIA - April
Security Policy: From EGEE to EGI David Kelsey (STFC-RAL) 21 Sep 2009 EGEE’09, Barcelona david.kelsey at stfc.ac.uk.
EGI-InSPIRE RI EGI EGI-InSPIRE RI Establishing Identity in EGI the authentication trust fabric of the IGTF and EUGridPMA.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
JSPG Update David Kelsey MWSG, Zurich 31 Mar 2009.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI strategy and Grand Vision Ludek Matyska EGI Council Chair EGI InSPIRE.
1 st EGI CTA VT meeting 18 January 2013 C. Vuerli (INAF, Italy), N. Neyroud (CNRS/IN2P3/LAPP, France)
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Plans for PY2 Steven Newhouse Project Director, EGI.eu 30/05/2011 Future.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI CSIRT Procedure for Compromised Certificates and Central Security Emergency.
European Grid Initiative AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
Resource Provisioning EGI_DS WP3 consolidation workshop, CERN Fotis Karayannis, GRNET.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI VT Activity Report and Proposed Workplan for EGI
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI User Support services and activities Gergely Sipos User Community Support.
EGI-Engage is co-funded by the Horizon 2020 Framework Programme of the European Union under grant number GGUS Service Provider GGUS –
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI-InSPIRE PY5 new activities Peter Solagna – EGI.eu.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Enabling SSO capabilities in the EGI Cloud services Peter Solagna – EGI.eu.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Questionnaires to Cloud technology providers and sites Linda Cornwall, STFC,
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Status of ARGUS support Peter Solagna – EGI.eu.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI Technology Sustainability Discussion Points DCI Sustainability Meeting.
CERN IT Department CH-1211 Geneva 23 Switzerland t OIS Operating Systems & Information Services CERN IT Department CH-1211 Geneva 23 Switzerland.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI Services for Distributed e-Infrastructure Access Tiziana Ferrari on behalf.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evaluation of Liferay modules EGI-InSPIRE mini-project Gergely Sipos EGI.eu.
EGI-Engage EGI Webinar - Introduction - Gergely Sipos EGI.eu / MTA SZTAKI 6/26/
EGI-InSPIRE EGI-InSPIRE RI The European Grid Infrastructure Steven Newhouse Director, EGI.eu Project Director, EGI-InSPIRE 29/06/2016CoreGrid.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI A pan-European Research Infrastructure supporting the digital European Research.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI Engagement meeting Gergely Sipos EGI.eu 1.
EGI-InSPIRE RI EGI Compute and Data Services for Open Access in H2020 Tiziana Ferrari Technical Director, EGI.eu
RI EGI-InSPIRE RI Pre-OMB meeting Preparation for the Workshop “EGI towards H2020” NGI_UK John Gordon and.
EGI-InSPIRE EGI-InSPIRE RI EGI strategy towards the Open Science Commons Tiziana Ferrari EGI-InSPIRE Director at EGI.eu.
EGI-InSPIRE RI EGI-InSPIRE RI EGI-InSPIRE Software provisioning and HTC Solution Peter Solagna Senior Operations Manager.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI Overview for ENVRI Gergely Sipos, Malgorzata Krakowian EGI.eu
EGI-InSPIRE RI An Introduction to European Grid Infrastructure (EGI) March An Introduction to the European Grid Infrastructure.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI New GOCDB roles schema OMB January 2012 Peter Solagna – EGI.eu 9/30/2016.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI solution for high throughput data analysis Peter Solagna EGI.eu Operations.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Role and Challenges of the Resource Centre in the EGI Ecosystem Tiziana Ferrari,
Accessing the VI-SEEM infrastructure
AENEAS WP6 first conference call
EGI: advanced computing for research in Europe… and beyond!
Tweaking the Certificate Lifecycle for the UK eScience CA
EGI-Engage Engaging the EGI Community towards an Open Science Commons
Status report of the LToS platform
Małgorzata Krakowian, Gergely Sipos
Federated Identity Management: Status and perspectives of EGI
EGI Webinar - Introduction -
Operations Management Board April 30
David Kelsey (STFC-RAL)
Sergio Andreozzi Strategy and Policy Manager (EGI.eu)
EGI FedCloud User Support coordination meeting
AAI in EGI Status and Evolution
User Support in EGI Reactive and proactive services
Support services for EGI portal-* communities
Check-in Identity and Access Management solution that makes it easy to secure access to services and resources.
Presentation transcript:

EGI-InSPIRE RI EGI-InSPIRE RI EGI-InSPIRE EGI services for the long tail of science Peter Solagna Senior Operations Manager Gergely Sipos Technical Outreach Manager wiki

EGI-InSPIRE RI EGI Infrastructure 2 European –Over 35 countries Grid –HTC services –Cloud services –Storage services Infrastructure –350 resource centres –400,000 cpu cores –190 PB storage EGI.eu For European researchers and their international collaborators VO SLA AUP VO SLA AUP ?? To support the long tail of science researchers EGI is developing a dedicated platform to address users’ requirements 3 February 2015 EGI services for the long tail of science FIM4R – CERN

EGI-InSPIRE RI Users requirements for a LToS platform Availability of resources HTC, cloud and storage –Short-medium term access –Quick access, avoid unnecessary bureaucracy Long-term, dedicated resource access, dedicated SLAs, will still require separate community Vos –Pilot with resources from NGI_PL, NGI_GR, NGI_IT Zero-barrier access: any user who carries out relevant research can access resources –No need for specialised relationship with an NREN, a CA –No need to establish an Registration Authority at user’s institute User support –Available through the NGIs 3 February 2015 EGI services for the long tail of science FIM4R – CERN

EGI-InSPIRE RI EGI requirements for a LToS platform Realistic: reuse existing technology building blocks as much as possible Secure: provide acceptable level of tracking of users and user activities Scalable: can scale up to support large number resource providers, technology providers, use cases and users Valuable: tangible outcomes –Traceable scientific publications from the long tail – with EGI acknowledgements –User stories from the long-tail –Easier to involve users in EGI 3 February 2015 EGI services for the long tail of science FIM4R – CERN

EGI-InSPIRE RI X509 credential s factory Long tail of science platform architecture 5 IdP EGI SSO User Management Portal Science Gateway Users DB Science Gateway Realistic Secure Zero-barrier Resources Security Policy VO AUP 3 February 2015 EGI services for the long tail of science FIM4R – CERN IdP User support

EGI-InSPIRE RI User Management Portal for the LToS User facing features, users can: –Log in using their federated identity –Provide the additional information not available in the IdP –Submit a request for resources EGI/NGIs facing features: –Assign a UID to all the users of the long tail of science platform –Approve the user’s request, or suspend a user –Check the user’s usage of resources 3 February 2015 EGI services for the long tail of science FIM4R – CERN 6

EGI-InSPIRE RI Improve User tracking For EGI X509 certificates are at the moment still a requirement Most of the science gateways are using robot certificates to generate short-term proxies for the users Use of robot certificates proxies can be extended for the LToS platform 7 Robot Certificate infoVO Information X509 Proxy DN: The same for every user of the gateway User UID For the LToS platform the UID is provided by the User Portal. The user will have the same UID using different science gateways. It’s a per-user sub-proxy 3 February 2015 EGI services for the long tail of science FIM4R – CERN

EGI-InSPIRE RI Advantages of the per-user sub-proxy User tracking –Services get “different” credentials for individual users –It’s possible to block one user without blocking all the users using the same robot certificate Security –Individual users can be isolated, e.g. preventing them to access other users’ workspace Accunting –Account for individual users’ usage –Report the actual number of real users accessing the infrastructrure And the online CA? It’s an alternative (more elegant?) solution for the same problem Not commonly available as the robot-certificates Robot-certificates at the moment are the easiest solution to have the platform online in few months 8 3 February 2015 EGI services for the long tail of science FIM4R – CERN

EGI-InSPIRE RI Summary Problems we want to solve: Fragmentation of resources for the long-tail –Catch-all European VO Lack of support for the long tail in some NGIs –European community with EGI.eu leadership X509-based access even for individual users –Per-user sub-proxy mechanism Restricted usability of robot certificates –Extended possibilities for user code on the new VO Difficulties in engaging with individual researchers –User registration portal with links to NGI staff Next steps Science gateways are already in production Developments to support per-user sub-proxies available in a couple of months User Management Portal to be presented during the EGI Conference in May –Open for testing during the conference Project wiki: February 2015 EGI services for the long tail of science FIM4R – CERN

EGI-InSPIRE RI Thank you for your attention! Questions? 10 3 February 2015 EGI services for the long tail of science FIM4R – CERN