首页> 外文会议>IEEE International Conference on e-Science >Globus auth: A research identity and access management platform
【24h】

Globus auth: A research identity and access management platform

机译:Globus auth:研究身份和访问管理平台

获取原文

摘要

Globus Auth is a foundational identity and access management platform service designed to address unique needs of the science and engineering community. It serves to broker authentication and authorization interactions between end-users, identity providers, resource servers (services), and clients (including web, mobile, desktop, and command line applications, and other services). Globus Auth thus makes it easy, for example, for a researcher to authenticate with one credential, connect to a specific remote storage resource with another identity, and share data with colleagues based on another identity. By eliminating friction associated with the frequent need for multiple accounts, identities, credentials, and groups when using distributed cyberinfrastructure, Globus Auth streamlines the creation, integration, and use of advanced research applications and services. Globus Auth builds upon the OAuth 2 and OpenID Connect specifications to enable standards-compliant integration using existing client libraries. It supports identity federation models that enable diverse identities to be linked together, while also providing delegated access tokens via which client services can obtain short term delegated tokens to access other services. We describe the design and implementation of Globus Auth, and report on experiences integrating it with a range of research resources and services, including the JetStream cloud, XSEDE, NCAR's Research Data Archive, and FaceBase.
机译:Globus Auth是一项基础身份和访问管理平台服务,旨在满足科学和工程界的独特需求。它用于代理最终用户,身份提供者,资源服务器(服务)和客户端(包括Web,移动,桌面和命令行应用程序以及其他服务)之间的身份验证和授权交互。因此,Globus Auth使研究人员可以轻松地使用一个凭据进行身份验证,使用另一个身份连接到特定的远程存储资源,并根据另一个身份与同事共享数据。通过消除在使用分布式网络基础架构时经常需要多个帐户,身份,凭据和组所带来的摩擦,Globus Auth简化了高级研究应用程序和服务的创建,集成和使用。 Globus Auth建立在OAuth 2和OpenID Connect规范的基础上,可使用现有客户端库实现符合标准的集成。它支持身份联合模型,该模型使各种身份可以链接在一起,同时还提供委托访问令牌,客户端服务可通过该委托访问令牌获得短期委托令牌来访问其他服务。我们描述了Globus Auth的设计和实现,并报告了将其与一系列研究资源和服务(包括JetStream云,XSEDE,NCAR的研究数据存档和FaceBase)集成的经验。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号