SciTokens: Capability-Based Secure Access to Remote Scientific Data

07/12/2018
by   Alex Withers, et al.
0

The management of security credentials (e.g., passwords, secret keys) for computational science workflows is a burden for scientists and information security officers. Problems with credentials (e.g., expiration, privilege mismatch) cause workflows to fail to fetch needed input data or store valuable scientific results, distracting scientists from their research by requiring them to diagnose the problems, re-run their computations, and wait longer for their results. In this paper, we introduce SciTokens, open source software to help scientists manage their security credentials more reliably and securely. We describe the SciTokens system architecture, design, and implementation addressing use cases from the Laser Interferometer Gravitational-Wave Observatory (LIGO) Scientific Collaboration and the Large Synoptic Survey Telescope (LSST) projects. We also present our integration with widely-used software that supports distributed scientific computing, including HTCondor, CVMFS, and XrootD. SciTokens uses IETF-standard OAuth tokens for capability-based secure access to remote scientific data. The access tokens convey the specific authorizations needed by the workflows, rather than general-purpose authentication impersonation credentials, to address the risks of scientific workflows running on distributed infrastructure including NSF resources (e.g., LIGO Data Grid, Open Science Grid, XSEDE) and public clouds (e.g., Amazon Web Services, Google Cloud, Microsoft Azure). By improving the interoperability and security of scientific workflows, SciTokens 1) enables use of distributed computing for scientific domains that require greater data protection and 2) enables use of more widely distributed computing resources by reducing the risk of credential abuse on remote systems.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
05/22/2019

SciTokens: Demonstrating Capability-Based Access to Remote Scientific Data using HTCondor

The management of security credentials (e.g., passwords, secret keys) fo...
research
02/03/2022

Astronomical data organization, management and access in Scientific Data Lakes

The data volumes stored in telescope archives is constantly increasing d...
research
11/11/2022

A Secure Future for Open-Source Computational Science and Engineering

Journalists, public policy analysts, and economists have called attentio...
research
12/23/2020

Enabling Secure and Effective Biomedical Data Sharing through Cyberinfrastructure Gateways

Dynaswap project reports on developing a coherently integrated and trust...
research
11/09/2022

A Capability-based Distributed Authorization System to Enforce Context-aware Permission Sequences

Controlled sharing is fundamental to distributed systems. We consider a ...
research
06/02/2022

A Serverless Engine for High Energy Physics Distributed Analysis

The Large Hadron Collider (LHC) at CERN has generated in the last decade...
research
02/25/2019

Addressing Scalability with Message Queues: Architecture and Use Cases for DIRAC Interware

The Message Queue (MQ) architecture is an asynchronous communication sch...

Please sign up or login with your details

Forgot password? Click here to reset