Globus Nexus: Research Identity, Profile, and Group Management as a Service

被引:4
作者
Chard, Kyle [1 ,2 ]
Lidman, Mattias
Bryan, Josh
Howe, Tom
McCollam, Brendan
Ananthakrishnan, Rachana
Tuecke, Steven
Foster, Ian
机构
[1] Univ Chicago, Computat Inst, Chicago, IL 60637 USA
[2] Argonne Natl Lab, Chicago, IL USA
来源
2014 IEEE 10TH INTERNATIONAL CONFERENCE ON E-SCIENCE (E-SCIENCE), VOL 1 | 2014年
关键词
SCIENCE;
D O I
10.1109/eScience.2014.25
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Collaborative e-Science applications often need to manage large numbers of user identities, profiles, and groups. However, developing and maintaining such capabilities is often challenging given the plethora of security protocols available and requirements for scalable, robust, and highly available implementations. Globus Nexus is a professionally hosted Platform-as-a-Service that provides these capabilities for collaborative e-Science applications, with a particular focus on the needs of scientific communities. It provides features such as identity provisioning, identity federation, profile management, user-oriented group management, and branded web interfaces that are important to many e-Science applications. Globus Nexus implements best practices approaches for each of these features for example using delegated security protocols such as OAuth; provides sophisticated workflows for actions such as email validation; and implements complex user-defined policies regarding permissible actions. We present here Globus Nexus' capabilities, motivate design choices, and present results that characterize the scalability, reliability, and availability of its implementation and deployment.
引用
收藏
页码:31 / 38
页数:8
相关论文
共 17 条
[1]   From gridmap-file to VOMS: managing authorization in a Grid environment [J].
Alfieri, R ;
Cecchini, R ;
Ciaschini, V ;
dell'Agnello, L ;
Frohner, A ;
Lorentey, K ;
Spataro, E .
FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2005, 21 (04) :549-558
[2]   Software as a Service for Data Scientists [J].
Allen, Bryce ;
Bresnahan, John ;
Childers, Lisa ;
Foster, Ian ;
Kandaswamy, Gopi ;
Kettimuthu, Raj ;
Kordas, Jack ;
Link, Mike ;
Martin, Stuart ;
Pickett, Karl ;
Tuecke, Steven .
COMMUNICATIONS OF THE ACM, 2012, 55 (02) :81-88
[3]  
Ananthakrishnan R., 2013, Proc. of 2013 IEEE International Conference on Cluster Computing (CLUSTER), P1
[4]  
Basney J., 2013, XSEDE 13
[5]  
Basney J., 2012, OAUTH MYPROXY PROTOC
[6]  
Ferg B., 2007, OPENID AUTHENTICATIO
[8]  
Guo Z., 2009, GCE 09
[9]  
Hardt D., 2012, The OAuth 2.0 Authorization Framework, DOI DOI 10.17487/RFC6749
[10]   Enabling collaborative research using the Biomedical Informatics Research Network (BIRN) [J].
Helmer, Karl G. ;
Ambite, Jose Luis ;
Ames, Joseph ;
Ananthakrishnan, Rachana ;
Burns, Gully ;
Chervenak, Ann L. ;
Foster, Ian ;
Liming, Lee ;
Keator, David ;
Macciardi, Fabio ;
Madduri, Ravi ;
Navarro, John-Paul ;
Potkin, Steven ;
Rosen, Bruce ;
Ruffins, Seth ;
Schuler, Robert ;
Turner, Jessica A. ;
Toga, Arthur ;
Williams, Christina ;
Kesselman, Carl .
JOURNAL OF THE AMERICAN MEDICAL INFORMATICS ASSOCIATION, 2011, 18 (04) :416-422