Cloud bursting galaxy: federated identity and access management

被引:4
|
作者
Jalili, Vahid [1 ]
Afgan, Enis [2 ]
Taylor, James [2 ]
Goecks, Jeremy [1 ]
机构
[1] Oregon Hlth & Sci Univ, Dept Biomed Engn, Portland, OR 97201 USA
[2] Johns Hopkins Univ, Dept Biol, Baltimore, MD 21218 USA
基金
美国国家科学基金会; 美国国家卫生研究院;
关键词
D O I
10.1093/bioinformatics/btz472
中图分类号
Q5 [生物化学];
学科分类号
071010 ; 081704 ;
摘要
Motivation Large biomedical datasets, such as those from genomics and imaging, are increasingly being stored on commercial and institutional cloud computing platforms. This is because cloud-scale computing resources, from robust backup to high-speed data transfer to scalable compute and storage, are needed to make these large datasets usable. However, one challenge for large-scale biomedical data on the cloud is providing secure access, especially when datasets are distributed across platforms. While there are open Web protocols for secure authentication and authorization, these protocols are not in wide use in bioinformatics and are difficult to use for even technologically sophisticated users. Results We have developed a generic and extensible approach for securely accessing biomedical datasets distributed across cloud computing platforms. Our approach combines OpenID Connect and OAuth2, best-practice Web protocols for authentication and authorization, together with Galaxy (https://galaxyproject.org), a web-based computational workbench used by thousands of scientists across the world. With our enhanced version of Galaxy, users can access and analyze data distributed across multiple cloud computing providers without any special knowledge of access/authorization protocols. Our approach does not require users to share permanent credentials (e.g. username, password, API key), instead relying on automatically generated temporary tokens that refresh as needed. Our approach is generalizable to most identity providers and cloud computing platforms. To the best of our knowledge, Galaxy is the only computational workbench where users can access biomedical datasets across multiple cloud computing platforms using best-practice Web security approaches and thereby minimize risks of unauthorized data access and credential use. Availability and implementation Freely available for academic and commercial use under the open-source Academic Free License (https://opensource.org/licenses/AFL-3.0) from the following Github repositories: https://github.com/galaxyproject/galaxy and https://github.com/galaxyproject/cloudauthz.
引用
收藏
页码:1 / 9
页数:9
相关论文
共 50 条
  • [41] Identity Harmonization for Federated HPC, Grid and Cloud Services
    Ertl, Benjamin
    Stevanovic, Uros
    Hayrapetyan, Arsen
    Wegh, Bas
    Hardt, Marcus
    2016 INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE COMPUTING & SIMULATION (HPCS 2016), 2016, : 621 - 627
  • [42] Federated identity-management protocols
    Pfitzmann, B
    Waidner, M
    SECURITY PROTOCOLS, 2005, 3364 : 153 - 177
  • [43] Adding Federated Identity Management to OpenStack
    David W. Chadwick
    Kristy Siu
    Craig Lee
    Yann Fouillat
    Damien Germonville
    Journal of Grid Computing, 2014, 12 : 3 - 27
  • [44] Adding Federated Identity Management to OpenStack
    Chadwick, David W.
    Siu, Kristy
    Lee, Craig
    Fouillat, Yann
    Germonville, Damien
    JOURNAL OF GRID COMPUTING, 2014, 12 (01) : 3 - 27
  • [45] Cloud-based federated identity for the Internet of Things
    Paul Fremantle
    Benjamin Aziz
    Annals of Telecommunications, 2018, 73 : 415 - 427
  • [46] A Survey on Security Issues of Federated Identity in the Cloud Computing
    Ghazizadeh, Eghbal
    Ab Manan, Jamalul-lail
    Zamani, Mazdak
    Pashang, Abolghasem
    2012 IEEE 4TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING TECHNOLOGY AND SCIENCE (CLOUDCOM), 2012,
  • [47] Cloud-based federated identity for the Internet of Things
    Fremantle, Paul
    Aziz, Benjamin
    ANNALS OF TELECOMMUNICATIONS, 2018, 73 (7-8) : 415 - 427
  • [48] Survey on Federated Identity Management Systems
    Sharma, Arvind Kumar
    Lamba, Chattar Singh
    RECENT TRENDS IN NETWORKS AND COMMUNICATIONS, 2010, 90 : 509 - 517
  • [49] Privacy by Design in Federated Identity Management
    Hoerbe, Rainer
    Hoetzendorfer, Walter
    2015 IEEE SECURITY AND PRIVACY WORKSHOPS (SPW), 2015, : 167 - 174
  • [50] ATTRIBUTE AGGREGATION IN FEDERATED IDENTITY MANAGEMENT
    Chadwick, David W.
    Inman, George
    COMPUTER, 2009, 42 (05) : 33 - 40