Custos Secrets: a Service for Managing User-Provided Resource Credential Secrets for Science Gateways

Custos Secrets: a Service for Managing User-Provided Resource Credential Secrets for Science Gateways
复制标题

DOI:
10.1145/3491418.3535177
复制
发表时间:
2022-07
期刊:
Practice and Experience in Advanced Research Computing
影响因子:
--
通讯作者:
Isuru Ranawaka;N. Goonasekera;E. Afgan;J. Basney;S. Marru;M. Pierce
Isuru Ranawaka;N. Goonasekera;E. Afgan;J. Basney;S. Marru;M. Pierce
中科院分区:
其他
文献类型:
--
作者:
Isuru Ranawaka;N. Goonasekera;E. Afgan;J. Basney;S. Marru;M. Pierce

文献摘要

相似文献

Custos 是一款开源软件,为科学网关提供用户、组和资源凭证管理服务。本文介绍了 Custos 中的资源凭证或秘密管理服务,该服务允许科学网关代表用户安全地管理安全令牌、SSH 密钥和密码。 Galaxy 等科学网关是研究人员访问网络基础设施的完善机制,并且越来越多地将其与其他在线服务(例如用户提供的存储或计算资源)结合起来。为了支持此用例,科学网关需要代表用户进行操作以连接、获取和释放这些资源,这些资源受到各种身份验证和访问机制的保护。必须使用“同类最佳”软件和既定的安全协议来存储和管理与这些访问机制相关的凭证。 Custos Secrets Service 允许科学网关使用安全协议和 API 存储和检索这些凭证,同时数据在静态时受到保护。在这里,我们提供该服务的实现细节,描述可用的 API 和 SDK,并讨论与 Galaxy 的集成作为用例。
Custos is open source software that provides user, group, and resource credential management services for science gateways. This paper describes the resource credential, or secrets, management service in Custos that allows science gateways to safely manage security tokens, SSH keys, and passwords on behalf of users. Science gateways such as Galaxy are well-established mechanisms for researchers to access cyberinfrastructure and, increasingly, couple it with other online services, such as user-provided storage or compute resources. To support this use case, science gateways need to operate on behalf of the users to connect, acquire, and release these resources, which are protected by a variety of authentication and access mechanisms. Storing and managing the credentials associated with these access mechanisms must be done using “best of breed” software and established security protocols. The Custos Secrets Service allows science gateways to store and retrieve these credentials using secure protocols and APIs while the data is protected at rest. Here, we provide implementation details for the service, describe the available APIs and SDKs, and discuss integration with Galaxy as a use case.