CICI: UCSS: SciAuth: Deploying Interoperable and Usable Authorization Tokens to Enable Scientific Collaborations
CICI:UCSS:SciAuth:部署可互操作和可用的授权令牌以实现科学协作
基本信息
- 批准号:2114989
- 负责人:
- 金额:$ 50万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2021
- 资助国家:美国
- 起止时间:2021-07-01 至 2025-06-30
- 项目状态:未结题
- 来源:
- 关键词:
项目摘要
The SciAuth project facilitates a cybersecurity transformation for NSF cyberinfrastructure, which is the scientific computing infrastructure across the nation that enables scientific productivity. The transformation at the heart of the project is a migration from cybersecurity technologies from 20 years ago to the cybersecurity standards of the modern Web. SciAuth provides needed leadership and coordination for this critical transformation through community engagement, coordinated adoption of community standards, integration with software cyberinfrastructure, security analysis and threat modeling, training, and workforce development. The project helps the community realize the benefits of an interoperable, modern cybersecurity ecosystem when transitioning between technologies, while maintaining the reliable and secure cyberinfrastructure upon which the scientific community depends. This transition to modern cybersecurity mechanisms is critical for enabling productive scientific collaborations across a diverse and distributed scientific cyberinfrastructure ecosystem. SciAuth builds on prior work by the NSF SciTokens project, in partnership with domain science projects and cyberinfrastructure providers, to realize this cybersecurity breakthrough across NSF cyberinfrastructure. SciAuth also supports the development of a diverse, globally competitive STEM workforce through a fellows program that pairs students across the country with mentors from the project to collaborate on student-led projects on the topic of cyberinfrastructure security.The migration from X.509 user certificates to JSON Web Tokens is in progress across NSF cyberinfrastructure. This migration has facilitated a re-thinking of authentication and authorization among cyberinfrastructure providers: enabling federated authentication as a core capability, improving support for attribute, role, and capability-based authorization, and reducing reliance on prior identity-based authorization methods that created security and usability problems. Achieving the benefits of a fundamentally new security credential ecosystem in NSF cyberinfrastructure, while avoiding the temptation to simply re-implement old X.509 methods, requires leadership and coordination. SciAuth provides the needed leadership and coordination to make these breakthrough technologies usable by scientists across disciplines, project sizes, and software ecosystems by enabling coordinated deployments across cyberinfrastructures in active use today.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
SciAuth项目促进了NSF网络基础设施的网络安全转型,这是全国范围内实现科学生产力的科学计算基础设施。该项目的核心转变是从20年前的网络安全技术向现代网络的网络安全标准的迁移。SciAuth通过社区参与、协调采用社区标准、与软件网络基础设施集成、安全分析和威胁建模、培训和劳动力发展,为这一关键转型提供必要的领导和协调。该项目帮助科学界在技术转换时实现可互操作的现代网络安全生态系统的好处,同时维护科学界所依赖的可靠和安全的网络基础设施。这种向现代网络安全机制的过渡对于在多样化和分布式的科学网络基础设施生态系统中实现富有成效的科学合作至关重要。SciAuth建立在NSF科学token项目之前的工作基础上,与领域科学项目和网络基础设施提供商合作,在NSF网络基础设施中实现这一网络安全突破。SciAuth还通过一项研究员计划,支持培养一支多元化的、具有全球竞争力的STEM劳动力队伍,该计划将全国各地的学生与该项目的导师配对,在以学生为主导的网络基础设施安全主题的项目上进行合作。从X.509用户证书到JSON Web令牌的迁移正在NSF网络基础设施中进行。这种迁移促进了网络基础设施提供商之间对身份验证和授权的重新思考:启用联合身份验证作为核心功能,改进对基于属性、角色和功能的授权的支持,并减少对先前基于身份的授权方法的依赖,这些方法会产生安全性和可用性问题。在NSF网络基础设施中实现全新安全凭证生态系统的好处,同时避免简单地重新实现旧X.509方法的诱惑,需要领导和协调。SciAuth提供了所需的领导和协调,使这些突破性技术能够被跨学科、项目规模和软件生态系统的科学家使用,从而实现跨网络基础设施的协调部署。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
项目成果
期刊论文数量(2)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
A Comparative Analysis Between SciTokens, Verifiable Credentials, and Smart Contracts: Novel Approaches for Authentication and Secure Access to Scientific Data
SciToken、可验证凭证和智能合约之间的比较分析:身份验证和安全访问科学数据的新方法
- DOI:10.1145/3569951.3597566
- 发表时间:2023
- 期刊:
- 影响因子:0
- 作者:Hossain Faruk, Md Jobair;Saha, Bilash;Basney, Jim
- 通讯作者:Basney, Jim
SciAuth: A Lightweight End-to-End Capability-Based Authorization Environment for Scientific Computing
SciAuth:用于科学计算的轻量级基于能力的授权环境
- DOI:10.1145/3491418.3535160
- 发表时间:2022
- 期刊:
- 影响因子:0
- 作者:Aydemir, Brian;Basney, Jim;Bockelman, Brian;Gaynor, Jeff;Weitzel
- 通讯作者:Weitzel
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
James Basney其他文献
James Basney的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('James Basney', 18)}}的其他基金
CICI: CCoE: Trusted CI: Advancing Trustworthy Science
CICI:CCoE:可信 CI:推进可信科学
- 批准号:
2241313 - 财政年份:2022
- 资助金额:
$ 50万 - 项目类别:
Cooperative Agreement
CICI: CE: SciTokens: Capability-Based Secure Access to Remote Scientific Data
CICI:CE:SciTokens:基于能力的远程科学数据安全访问
- 批准号:
1738962 - 财政年份:2017
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
CICI: Secure Data Architecture: CILogon 2.0 - An Integrated Identity and Access Management Platform for Science
CICI:安全数据架构:CILogon 2.0 - 科学的集成身份和访问管理平台
- 批准号:
1547268 - 财政年份:2016
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
SDCI Sec: Distributed Web Security for Science Gateways
SDCI Sec:科学网关的分布式网络安全
- 批准号:
1127210 - 财政年份:2011
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
CILogon: Secure Access to National-Scale CyberInfrastructure
CILogon:安全访问国家级网络基础设施
- 批准号:
0850557 - 财政年份:2009
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
A Cyber Identity Infrastructure for National Science
国家科学的网络身份基础设施
- 批准号:
0943633 - 财政年份:2009
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
Integration of the MyProxy Online Credential Repository into the NSF Middleware Initiative Software Infrastructure
将 MyProxy 在线凭证存储库集成到 NSF 中间件计划软件基础设施中
- 批准号:
0222571 - 财政年份:2002
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
相似海外基金
CICI: UCSS: Human-Centered Cybersecurity in Robotic Surgery (HCCRS) - Coordinating the Human and Cyber Infrastructure for Cybersecurity
CICI:UCCSS:机器人手术中以人为中心的网络安全 (HCCCS) - 协调网络安全的人力和网络基础设施
- 批准号:
2319891 - 财政年份:2023
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
CICI: UCSS: Trusted Resource Allocation in Volunteer Edge-Cloud Computing Workflows
CICI:UCSS:志愿者边缘云计算工作流程中的可信资源分配
- 批准号:
2232889 - 财政年份:2023
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
CICI: UCSS: Building a Community of Practice for Supporting Regulated Research
CICI:UCSS:建立支持监管研究的实践社区
- 批准号:
2409859 - 财政年份:2023
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
CICI: UCSS: Enhancing the Usability of Vulnerability Assessment Results for Open-Source Software Technologies in Scientific Cyberinfrastructure: A Deep Learning Perspective
CICI:UCSS:增强科学网络基础设施中开源软件技术漏洞评估结果的可用性:深度学习视角
- 批准号:
2319325 - 财政年份:2023
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
CICI: UCSS: Secure Containers in High-Performance Computing Infrastructure
CICI:UCSS:高性能计算基础设施中的安全容器
- 批准号:
2319975 - 财政年份:2023
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
CICI: UCSS: Maximizing Data Utility and Participant Privacy through Usable, Secure Data Workflows for Human-Centered AI Research
CICI:UCSS:通过可用、安全的数据工作流程实现以人为本的人工智能研究,最大限度地提高数据效用和参与者隐私
- 批准号:
2232690 - 财政年份:2023
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
CICI: UCSS: Confidential Computing in Reproducible Collaborative Workflows
CICI:UCSS:可重复协作工作流程中的机密计算
- 批准号:
2232824 - 财政年份:2023
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
CICI: UCSS: ScienceAccess: Enabling Zero-Trust Resource Access Management for Scientific Collaborations
CICI:UCSS:ScienceAccess:为科学合作实现零信任资源访问管理
- 批准号:
2232911 - 财政年份:2022
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
CICI: UCSS: Building a Community of Practice for Supporting Regulated Research
CICI:UCSS:建立支持监管研究的实践社区
- 批准号:
2201028 - 财政年份:2021
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
CICI: UCSS: Towards Secure and Usable Push Notification Authentication for Collaborative Scientific Infrastructures
CICI:UCSS:为协作科学基础设施实现安全可用的推送通知身份验证
- 批准号:
2115107 - 财政年份:2021
- 资助金额:
$ 50万 - 项目类别:
Standard Grant