| Literature DB >> 30254736 |
Mikael Linden1, Michal Prochazka2, Ilkka Lappalainen1, Dominik Bucik2, Pavel Vyskocil2, Martin Kuba2, Sami Silén1, Peter Belmann3, Alexander Sczyrba3, Steven Newhouse4, Ludek Matyska2, Tommi Nyrönen1.
Abstract
A common Authentication and Authorisation Infrastructure (AAI) that would allow single sign-on to services has been identified as a key enabler for European bioinformatics. ELIXIR AAI is an ELIXIR service portfolio for authenticating researchers to ELIXIR services and assisting these services on user privileges during research usage. It relieves the scientific service providers from managing the user identities and authorisation themselves, enables the researcher to have a single set of credentials to all ELIXIR services and supports meeting the requirements imposed by the data protection laws. ELIXIR AAI was launched in late 2016 and is part of the ELIXIR Compute platform portfolio. By the end of 2017 the number of users reached 1000, while the number of relying scientific services was 36. This paper presents the requirements and design of the ELIXIR AAI and the policies related to its use, and how it can be used for serving some example services, such as document management, social media, data discovery, human data access, cloud compute and training services.Entities:
Keywords: GA4GH; GDPR; IAM; authentication; authorisation; data access
Mesh:
Year: 2018 PMID: 30254736 PMCID: PMC6124379 DOI: 10.12688/f1000research.15161.1
Source DB: PubMed Journal: F1000Res ISSN: 2046-1402
Examples on ELIXIR identifier and username.
| ELIXIR identifier |
|
| ELIXIR username |
|
Home Organisation affiliation attribute’s types, their semantics and registration procedures.
| Affiliation type | Semantics | Procedure to register a value in ELIXIR authentication
|
|---|---|---|
| Faculty | The person is a researcher or teacher in their home
| • Perform login using the home organisation Identity
|
| Member | "Member" is intended to include faculty, staff, student,
| As above |
| Affiliate | The "affiliate" value indicates that the holder has some
| As above, or
|
Figure 1. ELIXIR authentication and authorisation infrastructure (AAI) design overview.