EMBL Identity & Access Management



Similar documents
Euro-BioImaging European Research Infrastructure for Imaging Technologies in Biological and Biomedical Sciences

European Molecular Biology Laboratory Case Example

Big Data in BioMedical Sciences. Steven Newhouse, Head of Technical Services, EMBL-EBI

EMBL. International PhD Training. Mikko Taipale, PhD Whitehead Institute/MIT Cambridge, MA USA

Euro-BioImaging European Research Infrastructure for Imaging Technologies in Biological and Biomedical Sciences

Cluster, Grid, Cloud Concepts

CERN, Information Technology Department

Appendix C to DIR Contract Number DIR-TSO-2736 SunGard Availability Services Discount Level: 25% Managed Data Center Services - Cloud Hosting

Private Cloud for WebSphere Virtual Enterprise Application Hosting

identity management in Linux and UNIX environments

Oracle Desktop Virtualization

Password Management Guide

locuz.com HPC App Portal V2.0 DATASHEET

Patrick Fuhrmann. The DESY Storage Cloud

LEARNING SOLUTIONS website milner.com/learning phone

Going Hybrid. The first step to your! Enterprise Cloud journey! Eric Sansonny General Manager!

Backup and Recovery for SAP Environments using EMC Avamar 7

HPC Cloud. Focus on your research. Floris Sluiter Project leader SARA

Novell Identity Manager

Dell SonicWALL and SecurEnvoy Integration Guide. Authenticating Users Using SecurAccess Server by SecurEnvoy

Implementing Microsoft Azure Infrastructure Solutions

(Scale Out NAS System)

White Paper. Anywhere, Any Device File Access with IT in Control. Enterprise File Serving 2.0

Technical. Overview. ~ a ~ irods version 4.x

IDENTITY MANAGEMENT ROLLOUT: IN A HURRY. Jason Blackader, UNIX Systems Administrator

HP A-IMC Firewall Manager

Course 20533: Implementing Microsoft Azure Infrastructure Solutions

HETEROGENEOUS DATA INTEGRATION FOR CLINICAL DECISION SUPPORT SYSTEM. Aniket Bochare - aniketb1@umbc.edu. CMSC Presentation

Enterprise Identity Management Reference Architecture

Leostream Corporation leostream.com Share this Whitepaper!

ST ALOYSIUS COLLEGE (AUTONOMOUS)

Active Directory Sync (AD) How to Setup

ProtectID. for Financial Services

10 Strategies to Optimize IT Spending in an Economic Downturn. Wong Kang Yeong, CISA, CISM, CISSP Regional Security Architect, ASEAN

Evolutyz Corp. is a future proof evolution of endless opportunities with a fresh mind set in Technology Consulting and Professional Services.

PZVM1 Administration Guide. V1.1 February 2014 Alain Ganuchaud. Page 1/27

OnCommand Performance Manager 1.1

Requirements Collax Security Gateway Collax Business Server or Collax Platform Server including Collax SSL VPN module

Stonesoft Corp. Stonegate Firewall and VPN

Scientific and Technical Applications as a Service in the Cloud

How to leverage SAP NetWeaver Identity Management and SAP Access Control combined solutions

Implementing Microsoft Azure Infrastructure Solutions 20533B; 5 Days, Instructor-led

Scaling Objectivity Database Performance with Panasas Scale-Out NAS Storage

ipecs UCS Unified Communications Solution Easy to access and activate Highlights Single server solution

Bioinformatics Grid - Enabled Tools For Biologists.

Course 20533B: Implementing Microsoft Azure Infrastructure Solutions

Getting value Changing the way people communicate and how businesses can take advantage of new opportunities.

Entrust IdentityGuard Comprehensive

BlueArc unified network storage systems 7th TF-Storage Meeting. Scale Bigger, Store Smarter, Accelerate Everything

Active Directory - User, group, and computer account management in active directory on a domain controller. - User and group access and permissions.

ecopy ShareScan v4.3 Pre-Installation Checklist

#jenkinsconf. Jenkins as a Scientific Data and Image Processing Platform. Jenkins User Conference Boston #jenkinsconf

Optimizing IT Deployment Issues

MS 10751A - Configuring and Deploying a Private Cloud with System Center 2012

Transparent fileservices for Windows, Unix and Mac

Enterprise GIS Architecture Deployment Options. Andrew Sakowicz


Mark Bennett. Search and the Virtual Machine

What is ArcGIS Comprised Of?

Using Microsoft Active Directory for Checkpoint NG AI SecureClient

Introduction to Computing Facilities

Administration Guide. WatchDox Server. Version 4.8.0

Enterprise Data Integration (EDI)

Red Hat Enterprise ipa

HP IMC Firewall Manager

Early Cloud Experiences with the Kepler Scientific Workflow System

IBM ELASTIC STORAGE SEAN LEE

Intelligent Inventory and Professional License Management

Synthetic Application Monitoring

Continuous Integration & Automated Testing in a multisite.net/cloud Project

ManageEngine (division of ZOHO Corporation) Infrastructure Management Solution (IMS)

Various Load Testing Tools

Google Apps and Open Directory. Randy Saeks

<Insert Picture Here> Move to Oracle Database with Oracle SQL Developer Migrations

qliqdirect Active Directory Guide

Cloud Computing Solutions for Genomics Across Geographic, Institutional and Economic Barriers

Electronic Laboratory Notebook in the Graduate Level Laboratory Informatics Program

Building Storage Service in a Private Cloud

Enterprise File Share and Sync Fabric. Feature Briefing

How To Use Directcontrol With Netapp Filers And Directcontrol Together

Intra- and interorgan communication of the cardiovascular system

ZyWALL OTP Co works with Active Directory Not Only Enhances Password Security but Also Simplifies Account Management

Transcription:

EMBL Identity & Access Management Rupert Lück EMBL Heidelberg e IRG Workshop Zürich Apr 24th 2008

Outline EMBL Overview Identity & Access Management for EMBL IT Requirements & Strategy Project Goal and Features Defining the scope Integrated User Management Benefits 2

EMBL European Molecular Biology Laboratory Supported by 20 Member States (+1 associated: ) 1500 staff & researchers from 60 nations 3

EMBL Sites Heidelberg, DE: Main Lab, Basic molecular biology research Hinxton, UK: EBI, Bioinformatics databases, research & services Grenoble, F & Hamburg, DE: Structural Biology Monterotondo, I: Mouse Biology 4

EMBL s Mission Flagship Lab for Basic Research in Molecular Biology Instrumentation & Technology Development Services Advanced Training Technology transfer 5

Systems Biology: From Molecules to Organisms Genome Protein/DNA Cell Embryo Fruitfly Mouse Human Development, Ageing, Disease 6

Systems Biology Understand Cell Function as a dynamic biological system Away from one gene one function concept Towards quantitative understanding of living systems Involves Interdisciplinary Research across scientific domains Collaboration infrastructures Data sharing & data integration Quantitative studies & Integration of information Technologically complex experimentation Computational approaches modeling and simulation Highly compute and storage intensive (Grid technology) 7

Instrumentation & Technology Development NG Sequencing, microarrays, databases, screens Light Microscopy (4D confocal microscopy, cell assays screening, ) Electron & Synchrotron tomography High throughput proteomics and structure analysis Modelling of biological processes small animal imaging Large amounts of heterogeneous data (PetaByte+ range) Significant needs for Network, Compute & Storage Resources Scalability of IT 8

EMBL Services More than 2000 Facility Users per year use the radiation sources for structural biology More than 200,000 scientists per year from all life sciences branches use the EMBL bioinformatic data resources More than 1000 visitors per year benefit from state of the art equipment learn new techniques carry out collaborative projects 9

EBI Services Reference site for biological data 150 different databases 120+ different tools. 9 different data submission systems. 8 major query interfaces. User base Rapidly growing > 100.000 different Users / Month Scientific community Pharma & Biotech Industry Trends Rapid growth of data Faster than Moore s law => Service oriented architecture Web Service based access Database Federation Grid approach web reqs/day (millions) 100 90 80 70 60 50 40 30 20 10 0 Jun 82 Jun 84 Jun 86 Jun 88 Jun 90 Jun 92 Jun 94 Jun 96 Jun 98 Jun 00 Jun 02 Jun 04 Gbases 2 1.8 1.6 1.4 1.2 1 0.8 0.6 0.4 0.2 0 EBI web requests / day (millions) 1999 2000 2001 2002 2003 2004 2005 year EMBL Bank Growth in Gbases 1982 2005 [ Source: Peter Stoehr, EBI ] 10

Outline EMBL Overview Identity & Access Management for EMBL IT Requirements & Strategy Project Goal and Features Defining the scope Integrated User Management Benefits 11

IT Requirements & Strategy IT Requirements Collaboration IT Environment to support Interdisciplinary research Scalability, Efficiency & Reliability of IT infrastructure and processes Strategy Institution wide Collaboration Platform Identity & Access management solution Consolidation IT Standards 12

Project: Identity & Access Management for EMBL Project goal Provide an EMBL wide user database EMBL Network Passport Key features Based on an LDAP Identity management and provisioning infrastructure Unified Login and Single Sign On where reasonable Automated fine grained provisioning of resources to different user populations Balanced implementation effort and cost Future flexibility 13

Defining the scope Resources User & Client populations Access roles IT Security domains 14

IT Resource Landscape HPC Clusters Several 1000 CPU cores mainly in Heidelberg and at the EBI NIS Storage Systems > 700 TByte primary storage on NetApp and BlueArc NAS 3 PB secondary storage NIS, AD Network WLAN (Radius) VPN (Radius) Multiple VLANs Inter campus VPN Applications Small to enterprise level application server based Web apps and native clients Scientific and commercial line of business systems LDAP, individual access silos Database systems Oracle MySQL Desktop and Server Systems Operating systems (Windows, MacOS X and Linux) 15

User / Client populations Named users Staff: ~1500 across 5 different EMBL sites 9yr contracts max. Visitors: >1000 / Year Facility users: >2000 / Year Contractors & Consultants High fluctuation Even between populations e Collaborators: >500 Alumni: >4000 Industry: collaborations & programme Public access: Scientific tool and content DB user populations (200.000+) 16

Access Roles (selection) VPN Access Unix / NIS Account Windows / Active Directory Account Email Account Access to Intranet Access to shared workspaces Access to resource booking system (Microscopes, Rooms, etc.) SAP: can use online shopping module (SRM) SAP Modules X, Y, Z: can manage data Access to scientific application X,Y,Z Oracle DB user / access roles 17

IT Security domains EMBL s organization is distributed across 5 sites Individual organizations Responsible for local IT management (Site in Rome, managed from Heidelberg) Local IT security Inter site security as a joint effort Split user domains Blocks efficient collaboration 18

User Management Until 2007 HR Data EMBL Web Pages & Web Applications Other IT resources HR replace monthly export IT replace replace not linked replace Unix, Windows, Mail, VPN etc. HR System Payroll & Staff Oracle DBs EMBL Groups (Web), Visitors, PhD, EIPOD, Alumni, Consultants IT resources Applications & Operating Systems 19

User Management Short comings Many different identities in different systems Huge efforts to manage individual identities and access profiles To achieve a reasonable level of consistency No fine grained assignment of access patterns By default only access to IT infrastructure of users EMBL home site Many existing (self developed) systems cannot be integrated with others 20

Integrated User & Access Management 2008+ Master Data (one central resource) Payroll, Staff EMBL Groups (Web), EIPOD, PhD, Visitors, Alumni, Consultants User & Identity Management Access Management Template based Provisioning HR sync IT sync Unix, Windows, Mail, VPN Web CMS, SAP, Oracle, etc. SAP HR / OM LDAP / Oracle IM EMBL User Directory & Identity Management IT resources Applications & Operating Systems 21

Integrated User Management Benefits One central user directory (LDAP) for all people associated with EMBL from all sites not only staff Automation of access rights management and provisioning to IT resources Real time information displayed on the EMBL web LDAP is a standard component Easy Integration in future projects Can also be used by any application developer within EMBL Integration projects costs significantly lower 22

Integrated User Management Collaboration Benefits EMBL wide unified login (username & password) e.g. NIS, Windows, SAP, Storage systems, Ability to login while visiting another EMBL site Access to remote (expensive) analysis tools e.g. via Terminal Server Secure sharing of data with EMBL colleagues from remote sites Resource booking and checking peoples availability across the organization 23

Integrated User Management Technical Benefits Provisioning templates allow fine grained access management i.e. a user population could get access to many resources Others only could be assigned email only access Why a commercial solution Vendors like Oracle provide out of the box connectors to other access infrastructures, e.g. Active Directory LDAP (various vendors) UNIX, NIS SAP (various modules) Allows faster and cost effective integration of other infrastructures Federations: Supports Liberty alliance standard Federations across organizations also to industry partners 24

Summary Systems biology at EMBL requires a collaborative, scalable and secure IT environment to enable research and to protect IP The introduced an identity management and provisioning infrastructure is one of the key components to support this requirement It allows automated fine tuning of individual access scenarios Allows fast and cost effective integration of other infrastructures 25