DICE: Authorizing Dynamic Networks for VOs Jeff W. Boote Senior Network Software Engineer, Internet2 Cándido Rodríguez Montes RedIRIS TNC2009 Malaga, Spain.

Slides:



Advertisements
Similar presentations
Connect communicate collaborate A Network Management Architecture proposal for the GEANT-NREN environment Pavle Vuletić, Afrodite Sevasti TNC 2010, ,
Advertisements

Connect. Communicate. Collaborate Click to edit Master title style MODULE 1: perfSONAR TECHNICAL OVERVIEW.
Connect. Communicate. Collaborate Towards Multi-domain Monitoring for the Research Networks Nicolas Simar, Dante TNC 2005, Poznan, June 2005.
Connect. Communicate. Collaborate WI5 – tools implementation Stephan Kraft October 2007, Sevilla.
Connect. Communicate. Collaborate GÉANT2 JRA1 & perfSONAR Loukik Kudarimoti, DANTE 28 th May, 2006 RNP Workshop, Curitiba.
Feb On*Vector Workshop Semantic Web for Hybrid Networks Dr. Paola Grosso SNE group University of Amsterdam The Netherlands.
1 ESnet Network Measurement Current Status Joe Metzger Jan 24th 2008 ESCC meeting Energy Sciences Network Lawrence Berkeley National Laboratory Networking.
ESnet On-demand Secure Circuits and Advance Reservation System (OSCARS) Chin Guok Network Engineering Group Thomas Ndousse Visit February Energy.
Omniran IEEE 802 Scope of OmniRAN Date: Authors: NameAffiliationPhone Max RiegelNSN
PerfSONAR Performance Monitoring Framework Matt Zekauskas, GENI Measurement Workshop June 26, 2009 Madison, Wisconsin.
TeraPaths: A QoS Collaborative Data Sharing Infrastructure for Petascale Computing Research Bruce Gibbard & Dantong Yu High-Performance Network Research.
PerfSONAR Eric L. Boyd. 2 perfSONAR: Overview Joint effort of ESnet, GÉANT2 JRA1 and Internet2 Herding cats or babysitting rottweilers? Webservices network.
FIRE – GENI collaboration workshop Sep 2015 Washington.
Rick Summerhill Chief Technology Officer, Internet2 Internet2 Fall Member Meeting 9 October 2007 San Diego, CA The Dynamic Circuit.
Internet2 Performance Update Jeff W. Boote Senior Network Software Engineer Internet2.
InterDomain Dynamic Circuit Network Demo Joint Techs - Hawaii Jan 2008 John Vollbrecht, Internet2
1 Measuring Circuit Based Networks Joint Techs Feb Joe Metzger
The Grid System Design Liu Xiangrui Beijing Institute of Technology.
Improving pS-PS Service Architecture , perfSONAR-PS Developers Meeting Aaron Brown, Andrew Lake, Eric Pouyoul.
A Framework for Internetworking Heterogeneous High-Performance Networks via GMPLS and Web Services Xi Yang, Tom Lehman Information Sciences Institute (ISI)
Connect. Communicate. Collaborate eduGAIN in Real Life! Ajay Daryanani, RedIRIS TERENA Networking Conference Brugge, 20th May 2008.
Hybrid MLN DOE Office of Science DRAGON Hybrid Network Control Plane Interoperation Between Internet2 and ESnet Tom Lehman Information Sciences Institute.
The Anatomy of the Grid Mahdi Hamzeh Fall 2005 Class Presentation for the Parallel Processing Course. All figures and data are copyrights of their respective.
DataTAG Research and Technological Development for a Transatlantic Grid Abstract Several major international Grid development projects are underway at.
Connect communicate collaborate GÉANT3 Services Connectivity and Monitoring Services by and for NRENs Ann Harding, SWITCH TNC 2010.
OGF Network Measurement Control WG Jeff Boote Internet2 Martin Swany University of Delaware Jason Zurawski Internet2.
ASCR/ESnet Network Requirements an Internet2 Perspective 2009 ASCR/ESnet Network Requirements Workshop April 15/16, 2009 Richard Carlson -- Internet2.
NA-MIC National Alliance for Medical Image Computing UCSD: Engineering Core 2 Portal and Grid Infrastructure.
Cracow Grid Workshop ‘06 17 October 2006 Execution Management and SLA Enforcement in Akogrimo Antonios Litke Antonios Litke, Kleopatra Konstanteli, Vassiliki.
1 Network Measurement Summary ESCC, Feb Joe Metzger ESnet Engineering Group Lawrence Berkeley National Laboratory.
OGF DMNR BoF Dynamic Management of Network Resources Documents available at: Guy Roberts, John Vollbrecht.
Connect. Communicate. Collaborate The authN and authR infrastructure of perfSONAR MDM Ann Arbor, MI, September 2008.
Connect. Communicate. Collaborate perfSONAR MDM Service for LHC OPN Loukik Kudarimoti DANTE.
Dynamic Lightpath Services on the Internet2 Network Rick Summerhill Director, Network Research, Architecture, Technologies, Internet2 TERENA May.
Building Dynamic Lightpaths in GÉANT Tangui Coulouarn, DeIC E-Infrastructure Autumn Workshop, Chiinău 8 September 2014.
Network Schemata Martin Swany. Perspective UNIS – Uniform Network Information Schema –Unification of perfSONAR Lookup Service (LS) and Topology Service.
Information Services, Topology and Discovery Working Group IS-WG Spring Member Meeting April 28th, 2009.
Connect. Communicate. Collaborate AAI scenario: How AutoBAHN system will use the eduGAIN federation for Authentication and Authorization Simon Muyal,
PerfSONAR-PS Functionality February 11 th 2010, APAN 29 – perfSONAR Workshop Jeff Boote, Assistant Director R&D.
© 2006 Open Grid Forum Network Monitoring and Usage Introduction to OGF Standards.
LAMP: Leveraging and Abstracting Measurements with perfSONAR Guilherme Fernandes
January 16 GGF14 NMWG Chicago (June 05) Jeff Boote – Internet2 Eric Boyd - Internet2.
Connect. Communicate. Collaborate Global On-demand Light Paths – Developing a Global Control Plane R.Krzywania PSNC A.Sevasti GRNET G.Roberts DANTE TERENA.
Diego R. Lopez, RedIRIS JRES2005, Marseille On eduGAIN and the Coming GÉANT Middleware Infrastructure.
Internet2 End-to-End Performance Initiative Eric L. Boyd Director of Performance Architecture and Technologies Internet2.
Dynamic Circuit Network An Introduction John Vollbrecht, Internet2 May 26, 2008.
Connect. Communicate. Collaborate Deploying Authorization Mechanisms for Federated Services in the eduroam architecture (DAMe)* Antonio F. Gómez-Skarmeta.
PerfSONAR-PS Working Group Aaron Brown/Jason Zurawski January 21, 2008 TIP 2008 – Honolulu, HI.
PerfSONAR WG 2006 Spring Member Meeting Jeff W. Boote 24 April 2006.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
22-Mar-2005 Internet2 Performance Architecture & Technologies Update Jeff W. Boote.
EGEE is a project funded by the European Union under contract IST JRA4 Overview Javier Orellana JRA4 Coordinator EGEE Kick Off Meeting SA2.
DICE Diagnostic Service Joe Metzger Joint Techs Measurement Working Group January
Connect communicate collaborate perfSONAR MDM News Domenico Vicinanza DANTE (UK)
1 Network related topics Bartosz Belter, Wojbor Bogacki, Marcin Garstka, Maciej Głowiak, Radosław Krzywania, Roman Łapacz FABRIC meeting Poznań, 25 September.
Advanced Network Diagnostic Tools Richard Carlson EVN-NREN workshop.
Campana (CERN-IT/SDC), McKee (Michigan) 16 October 2013 Deployment of a WLCG network monitoring infrastructure based on the perfSONAR-PS technology.
1 Deploying Measurement Systems in ESnet Joint Techs, Feb Joseph Metzger ESnet Engineering Group Lawrence Berkeley National Laboratory.
Status of perfSONAR Tools Jason Zurawski April 23, 2007 Spring Member Meeting.
LHC Path Monitoring Tools Deployment Planning Jeff Boote Internet2/R&D May 27, 2008 US ATLAS T2/T3 Workshop at UM.
Bob Jones EGEE Technical Director
Path Monitoring Tools Deployment Planning for U.S. T123
InterDomain Dynamic Circuit Network Demo
Robert Szuman – Poznań Supercomputing and Networking Center, Poland
PerfSONAR: Development Status
Integration of Network Services Interface version 2 with the JUNOS Space SDK
Internet2 Performance Update
Multi-Domain User Applications Research (JRA3)
Interdomain Dynamic Circuits
Presentation transcript:

DICE: Authorizing Dynamic Networks for VOs Jeff W. Boote Senior Network Software Engineer, Internet2 Cándido Rodríguez Montes RedIRIS TNC2009 Malaga, Spain 8 June, 2009

DICE Informal partnership made up of: CANARIE, ESnet, GÉANT, Internet2, USLHCnet Focus of collaboration is in aligning respective resources to best support the shared user base Coordinating network infrastructure Coordinating new service development Basis for perfSONAR collaboration and DICE control-plane (dynamic circuit) collaborations Started discussing a common framework for middleware to support monitoring and dynamic circuit efforts about a year ago

Outline Goals Use cases History of AA in perfSONAR and DCN Current implementations Future directions

AAI Integration Goal AAI Systems that are interoperable and support Dynamic Circuit Networks (IDC) and perfSONAR (PS). They may be built out of different components for various organizations, but having a common interface IDC and PS components then need to be modified to support that common AAI interface Desire to leverage existing middleware infrastructure Necessary because a common identity infrastructure is needed from a complete network management perspective. Those who provision the network, need to be able to diagnose performance issues with it.

What is perfSONAR An architecture & a set of protocols Services Oriented Architecture (SOA) Web Services Interfaces Protocols being standardized in the OGF NMC-WG Also A collaboration Production network operators focused on designing and building tools that they will deploy and use on their networks to provide monitoring and diagnostic capabilities to themselves and their user communities. Several interoperable software implementations Java & Perl A Federated set of Deployed Measurement Infrastructures

perfSONAR Architecture Interoperable network measurement middleware: Modular Web services-based Decentralized Locally controlled Integrates: Network measurement tools and archives Discovery Authentication and authorization Data manipulation Topology Based on: Open Grid Forum Network Measurement Working Group schema.

Decouple 3 phases of a Measurement Infrastructure

perfSONAR Components Measurement Points Data Services Measurement Archives Transformations Service Configuration Auth(n/z) Services Infrastructure Information Services Topology Service Lookup Analysis/Visualization User GUIs Web Pages NOC Alarms

perfSONAR 9 FNAL (AS3152) [US] ESnet (AS293) [US] GEANT (AS20965) [Europe] DFN (AS680) [Germany] DESY (AS1754) [Germany] measurement archive m1 m4 m3 measurement archive m1 m4 m3 measurement archive m1 m4 m3 m1 m4 m3 m1 m4 m3 measurement archive performance GUI user Analysis tool perfSONAR allows autonomous measurement systems to be aggregated in analysis

perfSONAR – AAI issues Not all clients are web browsers Interesting data for a single end-to-end path is typically ‘owned’ by several different organizations May have different release policies Related to home institution, job function, VO membership On demand multi-domain measurements create a real need for multi-domain AAI

DCN Comparisons to IP

Parallels with the IP Network IP Network Hosts have one-armed connections Can communicate with other hosts on the network Data paths are shared – the “atomic” elements are packets on shared data paths Control plane protocols include IGP and EGP protocols Dynamic Circuit Networks Hosts have one-armed connections Can communicate with other hosts on the network Data paths are dedicated – the “atomic” elements are circuits with non-shared data flows Control plane protocols being developed – Interdomain (IDC) protocol

IDC Control Plane Intradomain is domain dependent Interdomain – IDC is agreed upon between domains

IDC Flow Diagram - Web Service Based Four Primary Web Services Areas: Topology Exchange, Resource Scheduling, Signaling, User Request

Web Service Based Components Topology Topology Exchange Domain Abstraction Varying levels of dynamic information Resource Scheduling and Path Computation Multi-Domain path computation techniques Resource identification, reservation, confirmation Signaling path setup, service instantiation Host Lookup Service (Information Services - think DNS in the IP world) Uses DNS pointers AAI integration (Architecture under investigation) There is significant overlap with perfSONAR!

Dynamic Circuits – AAI issues Not all clients are web browsers Interesting data for a single end-to-end path is typically ‘owned’ by several different organizations May have different release policies Related to home institution, job function, VO membership On demand provisioning creates a real need for multi-domain AAI

Basic Architecture - PS

Basic Architecture - IDC

Currently Exploring N-tier issue ShibuPortal work may be a solution here Advantage is to more closely align pS/IDC efforts with MACE efforts SAML ECP profile Deal with non-web browser issues Hope to leverage attribute aggregation solutions for virtual/collaborative organizations

Conclusion All of this is a work in progress! We are interested in your input! Thanks!

Demonstration Demonstration of current work in perfSONAR