Cloud bursting galaxy: federated identity and access management

被引:4
|
作者
Jalili, Vahid [1 ]
Afgan, Enis [2 ]
Taylor, James [2 ]
Goecks, Jeremy [1 ]
机构
[1] Oregon Hlth & Sci Univ, Dept Biomed Engn, Portland, OR 97201 USA
[2] Johns Hopkins Univ, Dept Biol, Baltimore, MD 21218 USA
基金
美国国家科学基金会; 美国国家卫生研究院;
关键词
D O I
10.1093/bioinformatics/btz472
中图分类号
Q5 [生物化学];
学科分类号
071010 ; 081704 ;
摘要
Motivation Large biomedical datasets, such as those from genomics and imaging, are increasingly being stored on commercial and institutional cloud computing platforms. This is because cloud-scale computing resources, from robust backup to high-speed data transfer to scalable compute and storage, are needed to make these large datasets usable. However, one challenge for large-scale biomedical data on the cloud is providing secure access, especially when datasets are distributed across platforms. While there are open Web protocols for secure authentication and authorization, these protocols are not in wide use in bioinformatics and are difficult to use for even technologically sophisticated users. Results We have developed a generic and extensible approach for securely accessing biomedical datasets distributed across cloud computing platforms. Our approach combines OpenID Connect and OAuth2, best-practice Web protocols for authentication and authorization, together with Galaxy (https://galaxyproject.org), a web-based computational workbench used by thousands of scientists across the world. With our enhanced version of Galaxy, users can access and analyze data distributed across multiple cloud computing providers without any special knowledge of access/authorization protocols. Our approach does not require users to share permanent credentials (e.g. username, password, API key), instead relying on automatically generated temporary tokens that refresh as needed. Our approach is generalizable to most identity providers and cloud computing platforms. To the best of our knowledge, Galaxy is the only computational workbench where users can access biomedical datasets across multiple cloud computing platforms using best-practice Web security approaches and thereby minimize risks of unauthorized data access and credential use. Availability and implementation Freely available for academic and commercial use under the open-source Academic Free License (https://opensource.org/licenses/AFL-3.0) from the following Github repositories: https://github.com/galaxyproject/galaxy and https://github.com/galaxyproject/cloudauthz.
引用
收藏
页码:1 / 9
页数:9
相关论文
共 50 条
  • [21] A Metric-Based Approach to Assess Risk for "On Cloud" Federated Identity Management
    Arias-Cabarcos, Patricia
    Almenarez-Mendoza, Florina
    Marin-Lopez, Andres
    Diaz-Sanchez, Daniel
    Sanchez-Guerrero, Rosa
    JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2012, 20 (04) : 513 - 533
  • [22] PRIAM: Privacy Preserving Identity and Access Management Scheme in Cloud
    Xiong, Jinbo
    Yao, Zhiqiang
    Ma, Jianfeng
    Liu, Ximeng
    Li, Qi
    Ma, Jun
    KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2014, 8 (01): : 282 - 304
  • [23] Advanced Authentication Mechanisms for Identity and Access Management in Cloud Computing
    Alsirhani, Amjad
    Ezz, Mohamed
    Mostafa, Ayman Mohamed
    COMPUTER SYSTEMS SCIENCE AND ENGINEERING, 2022, 43 (03): : 967 - 984
  • [24] Identity Access Management for Multi-tier Cloud Infrastructures
    Faraji, Mohammad
    Kang, Joon-Myung
    Bannazadeh, Hadi
    Leon-Garcia, Alberto
    2014 IEEE NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM (NOMS), 2014,
  • [25] Identity and access management as a service in e-healthcare cloud
    Dhanabagyam, S. N.
    Karpagam, G. R.
    INTERNATIONAL JOURNAL OF BIOMEDICAL ENGINEERING AND TECHNOLOGY, 2018, 26 (3-4) : 250 - 265
  • [26] Managing Access to Service Providers in Federated Identity Environments: A Case Study in a Cloud Storage Service
    Diniz, Thomas
    de Felippe, Andre Castro
    Medeiros, Taina
    da Silva, Carlos Eduardo
    Araujo, Roberto
    2015 XXXIII BRAZILIAN SYMPOSIUM ON COMPUTER NETWORKS AND DISTRIBUTED SYSTEMS, 2015, : 199 - 207
  • [27] Assurance for federated identity management
    Baldwin, Adrian
    Casassa Mont, Marco
    Beres, Yolanta
    Shiu, Simon
    JOURNAL OF COMPUTER SECURITY, 2010, 18 (04) : 541 - 572
  • [28] Federated Identity Management for Research
    Barton, Thomas
    Gietz, Peter
    Kelsey, David
    Koranda, Scott
    Short, Hannah
    Stevanovic, Uros
    23RD INTERNATIONAL CONFERENCE ON COMPUTING IN HIGH ENERGY AND NUCLEAR PHYSICS (CHEP 2018), 2019, 214
  • [29] Federated Identity Management Challenges
    Jensen, Jostein
    2012 SEVENTH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY (ARES), 2012, : 230 - 235
  • [30] Federated Identity Management for Android
    Fongen, Anders
    PROCEEDINGS OF THE FIFTH INTERNATIONAL CONFERENCE ON EMERGING SECURITY INFORMATION, SYSTEMS AND TECHNOLOGIES (SECURWARE 2011), 2011, : 77 - 82