Title :
Globus Nexus: Research Identity, Profile, and Group Management as a Service
Author :
Chard, Kyle ; Lidman, Mattias ; Bryan, Josh ; Howe, Tom ; McCollam, Brendan ; Ananthakrishnan, Rachana ; Tuecke, Steven ; Foster, Ian
Author_Institution :
Ian Foster Comput. Inst., Univ. of Chicago, Chicago, IL, USA
Abstract :
Collaborative e-Science applications often need to manage large numbers of user identities, profiles, and groups. However, developing and maintaining such capabilities is often challenging given the plethora of security protocols available and requirements for scalable, robust, and highly available implementations. Globus Nexus is a professionally hosted Platform-as-a-Service that provides these capabilities for collaborative e-Science applications, with a particular focus on the needs of scientific communities. It provides features such as identity provisioning, identity federation, profile management, user-oriented group management, and branded web interfaces that are important to many e-Science applications. Globus Nexus implements best practices approaches for each of these features for example using delegated security protocols such as OAuth, provides sophisticated workflows for actions such as email validation, and implements complex user-defined policies regarding permissible actions. We present here Globus Nexus´ capabilities, motivate design choices, and present results that characterize the scalability, reliability, and availability of its implementation and deployment.
Keywords :
cloud computing; cryptographic protocols; natural sciences computing; user interfaces; Globus Nexus; OAuth; Web interfaces; collaborative e-science applications; email validation; identity federation; identity provisioning; platform-as-a-service; profile management; research identity; scientific communities; security protocols; sophisticated workflows; user identities; user profiles; user-defined policies; user-oriented group management; Authentication; Communities; Data models; Databases; Educational institutions; Electronic mail; Globus; group management; identity hub; identity management; platform-as-a-service;
Conference_Titel :
e-Science (e-Science), 2014 IEEE 10th International Conference on
Conference_Location :
Sao Paulo
Print_ISBN :
978-1-4799-4288-6
DOI :
10.1109/eScience.2014.25