TSD: a Secure and Scalable Service for Sensitive Data and ebiobanks



Similar documents
Veeam Backup and Replication Architecture and Deployment. Nelson Simao Systems Engineer

Veeam Cloud Connect. Version 8.0. Administrator Guide

UNINETT Sigma2 AS: architecture and functionality of the future national data infrastructure

How To Price Power In Norsk

TECHNICAL AND ORGANIZATIONAL DATA SECURITY MEASURES

Hypervisor Competitive Differences: Beyond the Data Sheet. Chris Wolf Senior Analyst, Burton Group

Cloud Optimize Your IT

VMware vcloud Air Security TECHNICAL WHITE PAPER

ActionPhoto International

QNAP NAS & Virtualization

Forklifting to AWS: An Option for Migration to AWS October Forklifting to AWS: An Option for Migration to AWS

Altaro Hyper-V Backup - Offsite Backups & Seeding Guide

Nordic Master in Didactics of Mathematics

Recommended ICT Security Architecture In the Higher Education Sector Best Practice Document

In addition to their professional experience, students who attend this training should have technical knowledge in the following areas.

C a r l G o e t h a l s T e r r e m a r k E u r o p e. C a r l. g o e t h a l t e r r e m a r k. c o m

Testing New Applications In The DMZ Using VMware ESX. Ivan Dell Era Software Engineer IBM

How to Backup XenServer VM with VirtualIQ

Steven Newhouse, Head of Technical Services

Running Agilent GeneSpring MPP on the Cloud

How To Use Arcgis For Free On A Gdb (For A Gis Server) For A Small Business

Introduction to ovirt

EMC Physical Security Enabled by RSA SecurID Two-Factor Authentication with Genetec Omnicast Client Applications

Hyper-V Enterprise Ready! Presented by Luther Allin

XenDesktop Workshop. Hva, Hvordan.? The best desktop virtualization solution is now even better

Private vs. Public Cloud Solutions

Citrix XenServer 7 Feature Matrix

Cloud on TEIN Part I: OpenStack Cloud Deployment. Vasinee Siripoonya Electronic Government Agency of Thailand Kasidit Chanchio Thammasat University

ovirt Introduction James Rankin Product Manager Red Hat Virtualization Management the ovirt way

Maximizing Your Desktop and Application Virtualization Implementation

SURFsara HPC Cloud Workshop

Enterprise Solution for Remote Desktop Services System Administration Server Management Server Management (Continued)...

Daly Computers Webinar for MEEC: P4000 SAN Solutions

YOUR STRATEGIC VIRTUALIZATION ALTERNATIVE. Greg Lissy Director, Red Hat Virtualization Business. James Rankin Senior Solutions Architect

Cloud Failover Appliance

RES PowerFuse Version Comparison Chart (1/9)

VMware Cloud Environment

A small selection of s we have chosen to include to show some of our communication with the open source community and how this has proceeded.

Securing sensitive data at Rest ProtectFile, ProtectDb and ProtectV. Nadav Elkabets Presale Consultant

What Cloud computing means in real life

Where are Organizations Today? The Cloud. The Current and Future State of IT When, Where, and How To Leverage the Cloud. The Cloud and the Players

Online Storage Replacement Strategy/Solution

Copyright 2014, Oracle and/or its affiliates. All rights reserved. 2

SURFsara HPC Cloud Workshop

Amazon Web Services Demo Tech Exchange. Slides:

IDA Call 6 for Cloud Computing. Presented by: Don Ng, CISSP don.sh.ng@starhub.com, Senior Manager SaaS Partner Program Date: 12th November, 2012

Citrix XenDesktop Backups with Xen & Now by SEP

Acronis Backup & Recovery 11.5

How to Backup and Restore a VM using Veeam

Table of Contents Introduction and System Requirements 9 Installing VMware Server 35

An Open Source Wide-Area Distributed File System. Jeffrey Eric Altman jaltman *at* secure-endpoints *dot* com

STREAM FRBC

If you do NOT use applications based on Amazon Web Services raise your hand.

Software services competence in research and development activities at PSNC. Cezary Mazurek PSNC, Poland

StorReduce Technical White Paper Cloud-based Data Deduplication

Microsoft Terminal Server and Citrix Presentation Server Deployment Environments

Cloud on TIEN Part I: OpenStack Cloud Deployment. Vasinee Siripoonya Electronic Government Agency of Thailand Kasidit Chanchio Thammasat

Experiences and challenges in the development of the JASMIN cloud service for the environmental science community

JOHNSON COUNTY COMMUNITY COLLEGE College Blvd., Overland Park, KS Ph Fax

The Virtualization Practice

Steelcape Product Overview and Functional Description

Intro to Virtualization

Content Distribution Management

Attachment D System Hardware & Software Overview & Recommendations For IRP System

Unitrends Virtual Backup Installation Guide Version 8.0

IOS110. Virtualization 5/27/2014 1

VMware vsphere Data Protection 6.0

An Analysis of Propalms TSE and Microsoft Remote Desktop Services

Transcription:

TSD: a Secure and Scalable Service for Sensitive Data and ebiobanks Gard Thomassen, PhD Head of Research Support Services Group University Center for Information Technology (USIT) University of Oslo

Outline Sensitive Data TSD setup, solutions, demo, status and future Q&A How to get on board

What is sensitive data? Norway : Personal Data Act 2, point 8 race/ethnic data, political opinion, philosophical and religious beliefs, the fact that a person has been suspected of, charged with, indicted for or convicted a criminal act, health, sex life and trade-union membership

Who has sensitive data Almost everyone

TSD launch in Computerworld 16/5-14

Norsk KreftGenom Konsortium Sammenliknet med den hardware vi benyttet fram til overgangen til TSD, som vel kan karakteriseres som en middels brukbar tjenermaskin, med 64 kjerner, kan vi med TSD oppnå en teoretisk hastighetsforbedring på 30X. I tillegg til dette kommer at vi har opitmalisert vår analysepipeline, ved at vi har parallellisert flere trinn. Tidligere ville en sekvenseringsanalyse på 48 svulst/normal-par resultert i kjøringstid på to-tre måneder minimun. Vi kjørte nå denne uka på TSD det samme på to dager og noen timer. Altså forsiktig sagt en dramatisk forbedring. Prof Eivind Hovig, NCGC

Teknisk ukeblad & e24, 5/5-14

Uniforum

TSD Pilot 2009-2012

System requirements Security, isolation and access control as given by law Large storage capacity Multi tenant (multiple users) High performance computing (HPC) resource High bandwidth Easy to maintain and operate Easy to use and practical (also for audio and video) Some freedom within confined user space Accessible from anywhere through proper mechanisms A variety of software and public data-sources must be available Windows and Linux support (server/host-side) Data collection services Data sharing services

Setup, solutions and status

System outline VM-server HPC - Colossus Internet Gateway n 1 Secure encrypted network to special high volume data production sites 1 (project) 1 (storage area) Storage

TSD Windows demo

Data import and export using TSD File lock server Virtual file lock server NFS mount 3 2 TSD File lock HD 1 Data copied here by sftp (2-factor authentication) encrypted data if sensitive Virtual projectserver 4 Project HD

Data collection using TSD minid Nettskjema-minID Nettskjema homepage Encrypted XML (PGP) File lock Project VM Project disk TSD

Homepage http://www.uio.no/tjenester/it/forskning/sensitiv/

Projects http://www.uio.no/tjenester/it/ forskning/sensitiv/mer-om/kunder/

TSD status > 80 research projects > 350 users Secure storage (> 1 PiB on disk) Secure data analysis Linux or windows hosts (> 250 VMs) Secure import and export Web-based data harvesting HPC cluster (>1500 cores) Postgres DBs Video and sound display

Capabilities enabled by TSD Large scale NGS research on human genomes Large scale medical imaging studies Large scale studies with web-based data collection Off-site analysis of sensitive data Secure storage for verification of published research Electronic consent

Nordic collaboration opportunities Laws are fairly similar (Norway very strict) Difficult to exchange sensitive data for research One should learn from each other as these systems demands very special IT-knowledge Services development and system-administration know-how is non-sensitive and may be shared Building TSD addressed many novel security questions in a University setting to be learnt from Large DBs/registeries of health data may enable very interesting research in the future TSD is involved in the NeIC-based Tryggve project We are happy to collaborate!

Future of TSD - main topics How to handle video and sound harvesting management metadata analysis Journal system for Psychologists (Univ of Umeå collaboration) Biobanks VMware and VDI infrastructure Galaxy inside TSD Elixir helpdesk connected to TSD Hosting docker containers Invariant storage of research data (connected with Cristin?) National einfrastructure investment in TSD??

Main collaborators on TSD Collaborators Norwegian Storage Infrastructure (NorStore) Norwegian Genetics Analysis Platform (GenAp) Norwegian Dietary Registry (Medical Faculty) Institute of Psychology (Faculty of Social Sciences) Norwegian Cancer Sequencing Consortium (NCGC) Reference group Oslo University Hospital, NorStore, Regional Ethical Committee, National Institute of Public Health, Norwegian Cancer Registry, Research Network at OUS, Elixir Norway, NCGC, GenAP, Institute of Psychology.

How to get on board tsd-contact@usit.uio.no tsd-drift@usit.uio.no NB Remember that NorStore (and StoreBioInfo) hands out TSD storage on a per application basis.

Thanks to Project group / developers tsd-core@usit virt-core@usit storage-core@usit postgres-core@usit network-core@usit hpc-core@usit windows-core@usit unix-core@usit IT-security@usit Administration / associated IT-dir Lars Oftedal Hans A. Eide Märtha Felton

Security details OATH TOTP 2-factor authentication Smart phones or programmable hardware tokens Import/export is under strict control No open connection to the internet All administration happens from the inside Strong separation between projects Hardened FreeBSD gateway and firewall Encrypted backup, one key per project Sys-admins are single users (traceability) Sys-admins have to use same authentication process