Concepedia

Publication | Closed Access

Globus auth: A research identity and access management platform

88

Citations

12

References

2016

Year

TLDR

Globus Auth is a foundational identity and access management platform that brokers authentication and authorization between users, identity providers, resource servers, and diverse client applications, built on OAuth 2 and OpenID Connect to enable standards‑compliant integration for the science and engineering community. The paper describes the design and implementation of Globus Auth and reports on its integration with research resources such as JetStream, XSEDE, NCAR’s Research Data Archive, and FaceBase. Globus Auth implements identity federation and delegated access tokens, allowing client services to obtain short‑term tokens for accessing other services. Globus Auth simplifies researcher workflows by enabling single‑credential authentication, identity‑specific resource access, and data sharing, thereby eliminating friction from multiple accounts and streamlining the integration of advanced research applications.

Abstract

Globus Auth is a foundational identity and access management platform service designed to address unique needs of the science and engineering community. It serves to broker authentication and authorization interactions between end-users, identity providers, resource servers (services), and clients (including web, mobile, desktop, and command line applications, and other services). Globus Auth thus makes it easy, for example, for a researcher to authenticate with one credential, connect to a specific remote storage resource with another identity, and share data with colleagues based on another identity. By eliminating friction associated with the frequent need for multiple accounts, identities, credentials, and groups when using distributed cyberinfrastructure, Globus Auth streamlines the creation, integration, and use of advanced research applications and services. Globus Auth builds upon the OAuth 2 and OpenID Connect specifications to enable standards-compliant integration using existing client libraries. It supports identity federation models that enable diverse identities to be linked together, while also providing delegated access tokens via which client services can obtain short term delegated tokens to access other services. We describe the design and implementation of Globus Auth, and report on experiences integrating it with a range of research resources and services, including the JetStream cloud, XSEDE, NCAR's Research Data Archive, and FaceBase.

References

YearCitations

Page 1