首页> 外文会议>IEEE International Conference on e-Science >Apache Airavata security manager: Authentication and authorization implementations for a multi-tenant escience framework
【24h】

Apache Airavata security manager: Authentication and authorization implementations for a multi-tenant escience framework

机译:Apache iiravata安全管理器:用于多租户簧级架构的身份验证和授权实现

获取原文

摘要

eScience middleware frameworks integrating multiple virtual organizations must incorporate comprehensive user identity and access management solutions. In this paper we examine usage patterns for these systems and map the patterns to widely used security standards and approaches. We focus on science gateways, a class of distributed system cyberinfrastructure. Science gateways are end user environments that provide access to a wide range of academic and commercial computing and storage resources for virtual organizations. Successful gateways focus on specific scientific communities and domains, but they build on many reusable features that can be provided by general purpose hosted platform services that can support multiple tenants. Providing a security framework for identity and access management for such hosted service removes the burden for each gateway to handle its user identity management and control access to its critical resources. From the resource provider's point of view, it provides a basis for more uniform accounting and auditing. Challenges arise from the range of gateways (both legacy and newly created), the range of technologies used to build them, and the range of end user environments (Web, mobile, desktop, and programmatic API clients) that gateways provide. Using Apache Airavata as an implementation, we examine three common gateway types based on where the user identity information is held and how these can be treated in a unified manner using OAuth2 and OpenID-Connect. Our solutions for identity and access management are not specific to Apache Airavata but can be generally applied to any e-Science platform.
机译:集成多个虚拟组织的簧片中间件框架必须包含全面的用户身份和访问管理解决方案。在本文中,我们检查这些系统的使用模式,并将模式映射到广泛使用的安全标准和方法。我们专注于科学网关,一类分布式系统Cyber​​Infrastructure。科学网关是最终用户环境,可提供对虚拟组织的广泛的学术和商业计算和存储资源的访问。成功的网关侧重于特定的科学社区和域,但它们构建了许多可重复使用的功能,可以通过可以支持多个租户的通用托管平台服务提供。为此类托管服务提供身份和访问管理的安全框架会消除每个网关处理其用户身份管理和控制其关键资源的访问的负担。从资源提供商的角度来看,它为更统一的会计和审计提供了基础。挑战来自网关范围(传统和新创建的),用于构建它们的技术范围,以及网关提供的最终用户环境(Web,移动,桌面和程序化API客户端)。使用Apache Airavata作为实现,我们基于保留用户身份信息以及如何使用OAuth2和OpenID-Connect以统一的方式处理三种公共网关类型。我们的身份和访问管理的解决方案不具体到Apache Airavata,但通常可以应用于任何电子科学平台。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号