A pathfinder project for a National AAAI
Lead Research Organisation:
University College London
Department Name: Physics and Astronomy
Abstract
The RCUK National e-Infrastructure projects wish to propose to undertake pilots to demonstrate the proposed access and resource management infrastructure works in several common research settings, especially in areas where data must be securely accessed, stored and transported.
The pilots will integrate 2 key existing Authentication, Authorisation and Accounting Infrastructure (AAAI) technologies, Assent and SAFE. The Authentication Service Assent is already in service at a number of institutions and Safe Share will be deployed, subject to successful pilots, at eMedLab (Crick/UCL), Farr Institute (London, HeRC, Wales and Scotland) and the Administrative Data Research Network. The Authorisation and Accounting service SAFE is currently used by Archer, DiRAC and the Hartree Centre.
The proposed pathfinder initiative will pilot the integration of these capabilities as a significant step towards implementing a coherent National Authentication, Authorisation and Accounting Infrastructure that serves the needs of UK and international research collaborations.
To deliver our vision of opening up access to the National E-Infrastructure we need to take these individual pieces and integrate them into a UK-wide service, which will also be compatible with EU and international projects' access and resource management services. This will allow us to then roll out a robust user management system across the National E-Infrastructure for both academic and industrial partners. The development of a final national solution is complex and by its nature cannot be quick. It must fit with European and global advances and requires international trust agreements. In order to move towards this, we propose this pathfinder project, which will utilise existing developments and provide a first working service on the National E-Infrastructure.
The pilots will integrate 2 key existing Authentication, Authorisation and Accounting Infrastructure (AAAI) technologies, Assent and SAFE. The Authentication Service Assent is already in service at a number of institutions and Safe Share will be deployed, subject to successful pilots, at eMedLab (Crick/UCL), Farr Institute (London, HeRC, Wales and Scotland) and the Administrative Data Research Network. The Authorisation and Accounting service SAFE is currently used by Archer, DiRAC and the Hartree Centre.
The proposed pathfinder initiative will pilot the integration of these capabilities as a significant step towards implementing a coherent National Authentication, Authorisation and Accounting Infrastructure that serves the needs of UK and international research collaborations.
To deliver our vision of opening up access to the National E-Infrastructure we need to take these individual pieces and integrate them into a UK-wide service, which will also be compatible with EU and international projects' access and resource management services. This will allow us to then roll out a robust user management system across the National E-Infrastructure for both academic and industrial partners. The development of a final national solution is complex and by its nature cannot be quick. It must fit with European and global advances and requires international trust agreements. In order to move towards this, we propose this pathfinder project, which will utilise existing developments and provide a first working service on the National E-Infrastructure.
Planned Impact
This pathfinder will build on and integrate the following existing capabilities:
Jisc's Assent service, to provide users with a common, single sign on mechanism that integrates with institutional identity management systems to confirm a researcher's identity; and its peer systems overseas.
Existing virtual organisation (VO) systems, such as the EPPC's SAFE management infrastructure.
A High Assurance Network and two-factor authentication, where appropriate, for secure data access and transport e.g. JISC's SafeShare service.
Four work packages are proposed to undertake this integration work and pilot the services in the field at sites across the RCUK domain.
The cost to RCUK will be £173932 over 10 months.
The outputs will be secure and very secure versions of a common AAAI application which integrates Assent and SAFE. This will also be able to federate with SAML and X.509 identity management systems which is a requirement for international collaborations.
A technical design and business case for a proposed National AAAI service will be produced.
Jisc's Assent service, to provide users with a common, single sign on mechanism that integrates with institutional identity management systems to confirm a researcher's identity; and its peer systems overseas.
Existing virtual organisation (VO) systems, such as the EPPC's SAFE management infrastructure.
A High Assurance Network and two-factor authentication, where appropriate, for secure data access and transport e.g. JISC's SafeShare service.
Four work packages are proposed to undertake this integration work and pilot the services in the field at sites across the RCUK domain.
The cost to RCUK will be £173932 over 10 months.
The outputs will be secure and very secure versions of a common AAAI application which integrates Assent and SAFE. This will also be able to federate with SAML and X.509 identity management systems which is a requirement for international collaborations.
A technical design and business case for a proposed National AAAI service will be produced.
Organisations
- University College London (Lead Research Organisation)
- Medical Research Council (Co-funder)
- Jisc (Co-funder, Collaboration)
- Economic and Social Research Council (Co-funder)
- Engineering and Physical Sciences Research Council (Co-funder)
- Arts and Humanities Research Council (Co-funder)
- Biotechnology and Biological Sciences Research Council (Co-funder)
- Natural Environment Research Council (Co-funder)
Publications
Robertson A
(2020)
Mapping dark matter and finding filaments: calibration of lensing analysis techniques on simulated data
in Monthly Notices of the Royal Astronomical Society
Owen J
(2020)
Massive discs around low-mass stars
in Monthly Notices of the Royal Astronomical Society
Trayford J
(2020)
Massive low-surface-brightness galaxies in the eagle simulation
in Monthly Notices of the Royal Astronomical Society
Pedersen C
(2020)
Massive neutrinos and degeneracies in Lyman-alpha forest simulations
in Journal of Cosmology and Astroparticle Physics
Li B
(2020)
Measuring the baryon acoustic oscillation peak position with different galaxy selections
in Monthly Notices of the Royal Astronomical Society
Srisawat C
(2020)
MEGA: Merger graphs of structure formation
in Monthly Notices of the Royal Astronomical Society
Nikolaev A
(2020)
Mesonic correlators at non-zero baryon chemical potential
Guo Y
(2020)
Metal Enrichment in the Circumgalactic Medium and Ly a Halos around Quasars at z ~ 3
in The Astrophysical Journal
Salvioni G
(2020)
Model nuclear energy density functionals derived from ab initio calculations
in Journal of Physics G: Nuclear and Particle Physics
Franci L
(2020)
Modeling MMS Observations at the Earth's Magnetopause with Hybrid Simulations of Alfvénic Turbulence
in The Astrophysical Journal
He J
(2020)
Modelling the tightest relation between galaxy properties and dark matter halo properties from hydrodynamical simulations of galaxy formation
in Monthly Notices of the Royal Astronomical Society
Ho S
(2020)
Morphological and Rotation Structures of Circumgalactic Mg ii Gas in the EAGLE Simulation and the Dependence on Galaxy Properties
in The Astrophysical Journal
Lofthouse E
(2020)
MUSE Analysis of Gas around Galaxies (MAGG) - I: Survey design and the environment of a near pristine gas cloud at z ˜ 3.5
in Monthly Notices of the Royal Astronomical Society
Dutta R
(2020)
MUSE Analysis of Gas around Galaxies (MAGG) - II: metal-enriched halo gas around z ~ 1 galaxies
in Monthly Notices of the Royal Astronomical Society
Katz H
(2020)
New methods for identifying Lyman continuum leakers and reionization-epoch analogues
in Monthly Notices of the Royal Astronomical Society
Kobayashi C
(2020)
New Type Ia Supernova Yields and the Manganese and Nickel Problems in the Milky Way and Dwarf Spheroidal Galaxies
in The Astrophysical Journal
Offler S
(2020)
News from bottomonium spectral functions in thermal QCD
Wurster J
(2020)
Non-ideal magnetohydrodynamics versus turbulence - I. Which is the dominant process in protostellar disc formation?
in Monthly Notices of the Royal Astronomical Society
Wurster J
(2020)
Non-ideal magnetohydrodynamics versus turbulence II: Which is the dominant process in stellar core formation?
in Monthly Notices of the Royal Astronomical Society
Almaraz E
(2020)
Nonlinear structure formation in Bound Dark Energy
in Journal of Cosmology and Astroparticle Physics
Bower R
(2020)
Numerical convergence of hydrodynamical simulations of galaxy formation: the abundance and internal structure of galaxies and their cold dark matter haloes
in Monthly Notices of the Royal Astronomical Society
Adamek J
(2020)
Numerical solutions to Einstein's equations in a shearing-dust universe: a code comparison
in Classical and Quantum Gravity
Campargue A
(2020)
Observation of electric-quadrupole infrared transitions in water vapor
in Physical Review Research
Ilee J
(2020)
Observing protoplanetary discs with the Square Kilometre Array - I. Characterizing pebble substructure caused by forming planets
in Monthly Notices of the Royal Astronomical Society
Heath R
(2020)
On the orbital evolution of binaries with circumbinary discs
in Astronomy & Astrophysics
Description | We demonstrated the practicality of having a central Authentication and Authorisation Service and linking it to a well used Accounting Service. This was tested in 3 common settings. We were able to demonstrate the successful use of a central Identity Provider for non academic users of academic eninfra structure |
Exploitation Route | This has been used to form the basis of the Proposed UKRI AAAI Framework |
Sectors | Aerospace, Defence and Marine,Agriculture, Food and Drink,Chemicals,Communities and Social Services/Policy,Construction,Creative Economy,Digital/Communication/Information Technologies (including Software),Education,Electronics,Energy,Environment,Financial Services, and Management Consultancy,Healthcare,Government, Democracy and Justice,Culture, Heritage, Museums and Collections,Pharmaceuticals and Medical Biotechnology,Retail,Security and Diplomacy,Transport |
Description | Used as the Basis for a UKRI White Paper on AAAI Approach will be used to open up the UKRI Einf to Public Sector, Industry and Commerce |
First Year Of Impact | 2018 |
Sector | Digital/Communication/Information Technologies (including Software),Healthcare |
Impact Types | Policy & public services |
Description | Fed into UKRI eInfrastructure policy |
Geographic Reach | Europe |
Policy Influence Type | Participation in a guidance/advisory committee |
Title | IMproved usability of JISC Assent Authentication Service and creation of Credential Conversion Service at RAL |
Description | The Assent Authentication Service was shown to work with an Authorisation and Accounting Service (SAFE). An API will be published. A credential conversion service was bulit at RAL to allow UK researchers to use home credentials to access international research projects |
Type Of Material | Improvements to research infrastructure |
Year Produced | 2018 |
Provided To Others? | Yes |
Impact | The construction of a plan to create a service to allow UK researchers single sign on to UK and World EInfrastrcutures |
Description | AAAI for the UK NeI |
Organisation | Jisc |
Country | United Kingdom |
Sector | Public |
PI Contribution | PI of RCUK pilot project for AAAI |
Collaborator Contribution | Software development and testing at 8 UK HEIs and ROs |
Impact | SAFE+ASSET AAAI service |
Start Year | 2016 |
Title | Collaboration with Atempo |
Description | Tape to Tape data transfter between DiRAC sites. |
Type Of Technology | Software |
Year Produced | 2019 |
Open Source License? | Yes |
Impact | Proof of COncept that data could be read from Tape stores remotely via a remote file system |
Title | Fast Network Links for Durham and Cambridge Univeristies |
Description | The Universeities and Cambridge are now linked by a highly performant Network |
Type Of Technology | Physical Model/Kit |
Year Produced | 2019 |
Impact | Both HEIs are able to ingest data at a faster rate |
Title | Improved usability of JISC Assent Authentication Service and creation of Credential Conversion Service at RAL |
Description | The Assent Authentication Service was shown to work with an Authorisation and Accounting Service (SAFE). An API will be published. A credential conversion service was bulit at RAL to allow UK researchers to use home credentials to access international research projects |
Type Of Technology | Software |
Year Produced | 2018 |
Open Source License? | Yes |
Impact | The construction of a plan to create a service to allow UK researchers single sign on to UK and World EInfrastrcutures |
Description | Member of UKRI E-Infrastructure Expert Panel 2017-2019 |
Form Of Engagement Activity | A formal working group, expert panel or dialogue |
Part Of Official Scheme? | No |
Geographic Reach | National |
Primary Audience | Policymakers/politicians |
Results and Impact | Created 7 white papers for UKRI which detailed a Roadmap for future e-Infrastructure funding in the UK |
Year(s) Of Engagement Activity | 2017,2018,2019 |
Description | NeI Project Directors Group |
Form Of Engagement Activity | A formal working group, expert panel or dialogue |
Part Of Official Scheme? | No |
Geographic Reach | National |
Primary Audience | Policymakers/politicians |
Results and Impact | Reports on AAAI, Data E-Infrastructure, Using Cloud for Research The National NeI Survey 2014, 2015, 2016 Report on Gender in HPC BEIS e-Infrastructure Business Case Integration activities of the NeI |
Year(s) Of Engagement Activity | 2014,2015,2016,2017 |
URL | https://neipdg.ac.uk/ |