Title
Globus auth: A research identity and access management platform
Abstract
Globus Auth is a foundational identity and access management platform service designed to address unique needs of the science and engineering community. It serves to broker authentication and authorization interactions between end-users, identity providers, resource servers (services), and clients (including web, mobile, desktop, and command line applications, and other services). Globus Auth thus makes it easy, for example, for a researcher to authenticate with one credential, connect to a specific remote storage resource with another identity, and share data with colleagues based on another identity. By eliminating friction associated with the frequent need for multiple accounts, identities, credentials, and groups when using distributed cyberinfrastructure, Globus Auth streamlines the creation, integration, and use of advanced research applications and services. Globus Auth builds upon the OAuth 2 and OpenID Connect specifications to enable standards-compliant integration using existing client libraries. It supports identity federation models that enable diverse identities to be linked together, while also providing delegated access tokens via which client services can obtain short term delegated tokens to access other services. We describe the design and implementation of Globus Auth, and report on experiences integrating it with a range of research resources and services, including the JetStream cloud, XSEDE, NCAR's Research Data Archive, and FaceBase.
Year
DOI
Venue
2016
10.1109/eScience.2016.7870901
2016 IEEE 12th International Conference on e-Science (e-Science)
Keywords
Field
DocType
Globus Auth,access management platform service,authentication,authorization,OAuth 2,OpenID Connect specifications,standards-compliant integration,client libraries,identity federation models,access tokens,JetStream cloud,XSEDE,NCAR Research Data Archive,FaceBase,research identity,foundational identity
Data mining,Authentication,Computer security,Computer science,Server,Cyberinfrastructure,Identity management,Credential,Distributed computing,World Wide Web,OpenID Connect,Authorization,Cloud computing
Conference
ISSN
ISBN
Citations 
2325-372X
978-1-5090-4274-6
5
PageRank 
References 
Authors
0.45
0
7
Name
Order
Citations
PageRank
Steven Tuecke14625708.07
R. Ananthakrishnan271.31
Kyle Chard351556.70
Mattias Lidman4282.10
Brendan McCollam5151.51
Stephen Rosen6150.94
Foster Ian7229382663.24