Cloud bursting galaxy: federated identity and access management

被引:4
|
作者
Jalili, Vahid [1 ]
Afgan, Enis [2 ]
Taylor, James [2 ]
Goecks, Jeremy [1 ]
机构
[1] Oregon Hlth & Sci Univ, Dept Biomed Engn, Portland, OR 97201 USA
[2] Johns Hopkins Univ, Dept Biol, Baltimore, MD 21218 USA
基金
美国国家科学基金会; 美国国家卫生研究院;
关键词
D O I
10.1093/bioinformatics/btz472
中图分类号
Q5 [生物化学];
学科分类号
071010 ; 081704 ;
摘要
Motivation Large biomedical datasets, such as those from genomics and imaging, are increasingly being stored on commercial and institutional cloud computing platforms. This is because cloud-scale computing resources, from robust backup to high-speed data transfer to scalable compute and storage, are needed to make these large datasets usable. However, one challenge for large-scale biomedical data on the cloud is providing secure access, especially when datasets are distributed across platforms. While there are open Web protocols for secure authentication and authorization, these protocols are not in wide use in bioinformatics and are difficult to use for even technologically sophisticated users. Results We have developed a generic and extensible approach for securely accessing biomedical datasets distributed across cloud computing platforms. Our approach combines OpenID Connect and OAuth2, best-practice Web protocols for authentication and authorization, together with Galaxy (https://galaxyproject.org), a web-based computational workbench used by thousands of scientists across the world. With our enhanced version of Galaxy, users can access and analyze data distributed across multiple cloud computing providers without any special knowledge of access/authorization protocols. Our approach does not require users to share permanent credentials (e.g. username, password, API key), instead relying on automatically generated temporary tokens that refresh as needed. Our approach is generalizable to most identity providers and cloud computing platforms. To the best of our knowledge, Galaxy is the only computational workbench where users can access biomedical datasets across multiple cloud computing platforms using best-practice Web security approaches and thereby minimize risks of unauthorized data access and credential use. Availability and implementation Freely available for academic and commercial use under the open-source Academic Free License (https://opensource.org/licenses/AFL-3.0) from the following Github repositories: https://github.com/galaxyproject/galaxy and https://github.com/galaxyproject/cloudauthz.
引用
收藏
页码:1 / 9
页数:9
相关论文
共 50 条
  • [31] My private cloud - granting federated access to cloud resources
    Chadwick, David W.
    Casenove, Matteo
    Siu, Kristy
    JOURNAL OF CLOUD COMPUTING-ADVANCES SYSTEMS AND APPLICATIONS, 2013, 2 (02): : 1 - 16
  • [32] Towards Federated Service Discovery and Identity Management in Collaborative Data and Compute Cloud Infrastructures
    Shiraz Memon
    Jensen Jens
    Elbers Willem
    Helmut Neukirchen
    Matthias Book
    Morris Riedel
    Journal of Grid Computing, 2018, 16 : 663 - 681
  • [33] Towards Federated Service Discovery and Identity Management in Collaborative Data and Compute Cloud Infrastructures
    Memon, Shiraz
    Jens, Jensen
    Willem, Elbers
    Neukirchen, Helmut
    Book, Matthias
    Riedel, Morris
    JOURNAL OF GRID COMPUTING, 2018, 16 (04) : 663 - 681
  • [34] Security Compliance Auditing of Identity and Access Management in the Cloud: Application to OpenStack
    Majumdar, Suryadipta
    Madi, Taous
    Wang, Yushun
    Jarraya, Yosr
    Pourzandi, Makan
    Wang, Lingyu
    Debbabi, Mourad
    2015 IEEE 7TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING TECHNOLOGY AND SCIENCE (CLOUDCOM), 2015, : 58 - 65
  • [35] Identity and Access Management for Cloud Services Used by the Payment Card Industry
    Schulze, Ruediger
    CLOUD COMPUTING - CLOUD 2018, 2018, 10967 : 206 - 218
  • [36] The Use of Blockchain for Identity and Access Management (IAM) in Multi-cloud
    Moyo, Lenience
    du Toit, Jaco
    PROCEEDINGS OF NINTH INTERNATIONAL CONGRESS ON INFORMATION AND COMMUNICATION TECHNOLOGY, ICICT 2024, VOL 7, 2024, 1003 : 149 - 159
  • [37] Appliance Management for Federated Cloud Environments
    Airaj, Mohammed
    Blanchet, Christophe
    Kenny, Stuart
    Loomis, Charles
    2013 IEEE FIFTH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING TECHNOLOGY AND SCIENCE (CLOUDCOM), VOL 1, 2013, : 232 - 239
  • [38] The Venn of identity - Options and issues in federated identity management
    Maler, Eve
    Reed, Drummond
    IEEE SECURITY & PRIVACY, 2008, 6 (02) : 16 - 23
  • [39] On Identity Assurance in the Presence of Federated Identity Management Systems
    Baldwin, Adrian
    Mont, Marco Casassa
    Beres, Yolanta
    Shiu, Simon
    DIM'07: PROCEEDINGS OF THE 2007 ACM WORKSHOP ON DIGITAL IDENTITY MANAGEMENT, 2007, : 27 - 35
  • [40] A Federated Cloud of Things for Emergency Management
    Taccari, Gilberto
    PROCEEDINGS OF THE 2014 INTERNATIONAL CONFERENCE ON COLLABORATION TECHNOLOGIES AND SYSTEMS (CTS), 2014, : 647 - 651