European Life Sciences Infrastructure for Biological Information www.elixir-europe.org ELIXIR and Identity Management 2 nd Workshop on Federated Identity.

Slides:



Advertisements
Similar presentations
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
Advertisements

Development on Nordic platform for sensitive biomedical data The Tryggve project Antti Pursula.
Federated Identity Management for Researchers – A quick overview from GÉANT BoF TNC May 2014 Dublin.
Identity management – life sciences perspective Ugis Sarkans European Bioinformatics Institute.
Resource Entitlement Management System Manne Miettinen Mikael Linden Janne Lauros CSC – IT Center for Science.
Steven KrauwerLREC20081 CLARIN: Common Language Resources and Technology Infrastructure for the Humanities and Social Sciences Kimmo Koskenniemi (University.
Federated Identity Management for Research Communities (FIM4R) David Kelsey (STFC-RAL) EGI TF, AAI workshop 19 Sep 2012.
Open Workshop on e-Infrastructures, Helsinki October 4 – 5, 2006 Roadmap Parallel Session on last chapter of e-IRG Roadmap: Crossing the Boundaries of.
New DFG Information Infrastructure Projects Dr. Stefan Winkler-Nees; Birmingham, 28. March 2011 New DFG Information Infrastructure Projects.
Tryggve project developing services for sensitive biomedical data: Call for Nordic use cases NeiC 2015 Conference Workshop on sensitive data Antti Pursula.
Research and Innovation Research and Innovation Research and Innovation Research and Innovation Research Infrastructures and Horizon 2020 The EU Framework.
Scientific Publication in the European Research Area: moving towards change Pēteris Zilgalvis Head of Unit, Governance and Ethics European Commission,
A Robust Health Data Infrastructure P. Jon White, MD Director, Health IT Agency for Healthcare Research and Quality
FIM-ig Federated Identity Management Interest Group.
European Life Sciences Infrastructure for Biological Information ELIXIR FI for BBMRI IT Morris FIMM and THL Tommi Nyrönen.
European Life Sciences Infrastructure for Biological Information ELIXIR
EGI-Engage EGI-Engage Engaging the EGI Community towards an Open Science Commons Project Overview 9/14/2015 EGI-Engage: a project.
Final evaluation of the Research Programme on Social Capital and Networks of Trust (SoCa) 2004 – 2007: What should the Academy of Finland learn.
1 Common Challenges Across Scientific Disciplines Laurence Field CERN 18 th November 2013.
AARC Overview Licia Florio, David Groep 21 Jan 2015 presented by David Groep, Nikhef.
1 Multi Cloud Navid Pustchi April 25, 2014 World-Leading Research with Real-World Impact!
Future Use of Stored Samples & Data and the NIH Policy on GWAS and dbGaP NIAID/DAIDS Dione Washington, M.S. -- ProPEP Sudha Srinivasan, Ph.D.-- TRP Tanisha.
Federated Identity Management for HEP David Kelsey WLCG GDB 9 May 2012.
The Scientific Publications System: A Key Factor for EU Research Policy Celina Ramjoué European Commission, Research Directorate-General Science, Economy.
Access to Personalised Medicine for PDAC patients STSM of the application of an EU-index for barriers Denis Horgan (EAPM) & Angela Brand (IPHG) on behalf.
EMI AAI Strategy & Plans John White / Helsinki Institute of Physics Federated Identity Systems for Scientific Collaborations Workshop , CERN,
Authentication and Authorisation for Research and Collaboration Licia Florio (GÉANT) Christos Kanellopoulos (GRNET) Service orientation.
European Life Sciences Infrastructure for Biological Information Life science community update for the 7 th Federated Identity Management.
Resource Entitlement Management System Mikael Linden CSC – IT Center for Science.
Federated Identity Management for Research Collaborations Bob Jones, CERN Daan Broeder, Max-Planck Institute for Psycholinguistics David Kelsey, Particle.
Innovation through participation eduGAIN interfederation service for research and education Cern FedID workshop in RAL, UK 2-3 Nov 2011 Mikael Linden,
Authentication and Authorisation for Research and Collaboration Licia Florio REFEDS Meeting The AARC Project I2 Technology Exchange.
Authentication and Authorisation for Research and Collaboration Licia Florio AARC Workshop The AARC Project Brussels, 26 October.
Identity Management in DEISA/PRACE Vincent RIBAILLIER, Federated Identity Workshop, CERN, June 9 th, 2011.
JRA1.4 Models for implementing Attribute Providers and Token Translation Services Andrea Biancini.
EResearchers Requirements ELIXIR AAI Workshop Presenter: Mikael Linden (ELIXIR AAI-TF)
Licensing in a European Perspective - case Finnish National Consortium ELAG 2001, Prague Kristiina Hormia-Poutanen.
EUDAT receives funding from the European Union's Horizon 2020 programme - DG CONNECT e-Infrastructures. Contract No B2ACCESS LSDMA.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
Networks ∙ Services ∙ People Thomas Bärecke Journée Fédération, Paris Collaboration européenne GÉANT SA5 03/07/2015 SA5 T5 team
Shibboleth Use at the National e-Science Centre Hub Glasgow at collaborating institutions in the Shibboleth federation depending.
Authentication and Authorisation for Research and Collaboration Licia Florio REFEDS Meeting AARC and AARC2 Vienna, 1 st December.
European Life Sciences Infrastructure for Biological Information EGI 2015, Lisbon, 18 May 2015 Rafael C Jimenez, ELIXIR CTO ELIXIR.
Authentication and Authorisation for Research and Collaboration Bari, Italy Training and Outreach Authentication and Authorisation.
David Groep Nikhef Amsterdam PDP & Grid AARC Authentication and Authorisation for Research and Collaboration an impression of the road ahead.
European Life Sciences Infrastructure for Biological Information ELIXIR’s needs from the EOSC Steven Newhouse, EMBL-EBI Part of the.
Networks ∙ Services ∙ People Licia Florio TNC, Lisbon Consuming identities across e- Infrastructures 16 June 2015 PDO GÈANT.
Authentication and Authorisation for Research and Collaboration Licia Florio AARC CORBEL Workshop The AARC Project Paris, 31 May.
European Life Sciences Infrastructure for Biological Information European Life Sciences Infrastructure for Biological Information.
EGI-Engage EGI Webinar - Introduction - Gergely Sipos EGI.eu / MTA SZTAKI 6/26/
Authentication and Authorisation for Research and Collaboration Peter Solagna, Nicolas EGI AAI integration experiences AARC Project.
Authentication and Authorisation for Research and Collaboration AARC/CORBEL Workshop for Life Sciences AAI AARC Draft Blueprint.
European Life Sciences Infrastructure for Biological Information European Life Sciences Infrastructure for Biological Information.
Co-ordination & Harmonisation of Advanced e-Infrastructures for Research and Education Data Sharing Grant.
EGI-InSPIRE EGI-InSPIRE RI EGI strategy towards the Open Science Commons Tiziana Ferrari EGI-InSPIRE Director at EGI.eu.
Authentication and Authorisation for Research and Collaboration Taipei - Taiwan Mechanisms of Interfederation 13th March 2016 Alessandra.
E-Infrastructure for Sensitive biomedical data NeiC 2015 Conference Espoo, Finland Antti Pursula.
Ian Bird, CERN WLCG Project Leader Amsterdam, 24 th January 2012.
Introduction to AAI Services
Project Facts Partners: DANTE (UK), GARR (IT), RedCLARA (UY), RedIRIS (ES), RENATA (CO), RNP (BR), TERENA (NL) Coordinator: RedCLARA Project Duration:
ELIXIR: Potential areas for collaboration with e-Infrastructures
ELIXIR: Authentication and Authorization Infrastructure Requirements
KIOS Open Knowledge: A pillar for excellence
EGI-Engage Engaging the EGI Community towards an Open Science Commons
ELIXIR Safeguarding the results of life science research in Europe
EGI Webinar - Introduction -
Common Authentication and Authorisation Service for Life Science Research Mikael Linden, ELIXIR Finland.
High Performance Computing Center – HLRS
WP6 – EOSC integration J-F. Perrin (ILL) 15th Jan 2019
Common Authentication and Authorisation Service for Life Science Research Mikael Linden, ELIXIR Finland.
Presentation transcript:

European Life Sciences Infrastructure for Biological Information ELIXIR and Identity Management 2 nd Workshop on Federated Identity Systems for Scientific Collaboration STFC Rutherford Appleton Laboratory, Harwell Wednesday 2 November, 2011 Andrew Lyall, PhD

ELIXIR : Europe’s emerging infrastructure for biological information AIM – To build a sustainable European infrastructure for biological information, supporting life science research and its translation to medicine, the environment, the bio- industries and society. Services: Management of Europe’s growing volume and variety of biological data which are heterogeneous, complex and heavily linked Interaction with and support for data in other ESFRI projects in medicine, agriculture and environment. Biological domain expertise Computer Tools Infrastructure Computational infrastructure Training centres for users of ELIXIR. Industry translational services 3 million users growing to 10 million in 2020 Petabytes now growing to exabytes in 2020

Life sciences Medicine Agriculture Pharmaceuticals Biotechnology Environment Bio-fuels Cosmaceuticals Neutraceuticals Consumer products Personal genomes Etc… Comprehensive, universal, integrated…

ELIXIR: Requirements for access control The Human Genome belongs to the Human Race and must be freely available to everyone without any authentication Access to personally identifiable data is a political and societal problem and will require special measures, including authorisation, certification and authentication

European Genome-Phenome Archive (EGA) Stores data collected for investigations involving variants of genes that may be of clinical significance including information about participants who are potentially identifiable Primary archive for research data that is not for public distribution – all data must be de-identified and must be handled and utilized in accordance with the specific informed consent associated with them Controlled access to the data – distributed access policy – access granted by a Data Access Committee (DAC): currently 20+ – data release policy: data access application and data access agreement – any attempt to re-identify is specifically prohibited EGA supports only data access decisions that are based on original consent – authorized users have personal accounts in our system – access to the data requires account password – data decryption requires a separate key that must be requested and is sent off line

Data Access Committees grant access to EGA

EGA Security Infrastructure Schematic 7 Authentication of FTP clients is inherently insecure; we may have to require FTPS compliant clients (RFC 4217)RFC 4217 Secure Server EGA provides archival encryption key and file path in the archive. This requires a secure API to facilitate access into the EGA master database EGA secure layer (3) EGA secure layer FTP Client Request for whole file for download (with username/ password) (1) EGA verifies user and provides list of authorized list of files. (2) (4) Requested BAM data decrypted, and re-encrypted using client key (5) Secure Server responds to FTP requests directly; FTP client downloads the custom-encrypted file EGA Security Infrastructure Schematic

Thank you for your attention... Next: Steps towards IDF – bio-SP pilot Tommi Nyrönen CSC (NCP for ELIXIR Finland)

Recommendations from IRISC 2011 Helsinki IDFs should pay attention to outreach activities among the biological service providers and infrastructures – Raising overall awareness of technical and non-technical issues – Increase coordination in – largely unconnected – community Attribute release to bio SP’s should be easy, and SP’s should not need to contact individual IdP’s to get attributes Encourage federations to adopt a “zero-cost” funding model for academic service providers Pilot use case on federated access management could be established with biomedical data provider together with EGA, eduGAIN and relevant IDFs and e-Infrastructures

Data produced from national biobank collections (BBMRI) will require restricted secure access management Integration of this data with fully open access (ELIXIR) reference data is needed – data processing and interpretation e.g. cancer diagnostics Federated identity management e-Infrastructure can support biomedical data services achieve this – National identity federations and eduGAIN service for correctly identifying academic data access applicants – Common ways for management of authenticated users' entitlements to data and IT resource access – Automating a process for granting access to biomedical data sets with data owners like ethical committees – Pilot preparations are ongoing Steps towards IDF use case

Everything should interoperate without forgetting …