Cargando…
Bootstrapping a new LHC data transfer ecosystem
GridFTP transfers and the corresponding Grid Security Infrastructure (GSI)-based authentication and authorization system have been data transfer pillars of the Worldwide LHC Computing Grid (WLCG) for more than a decade. However, in 2017, the end of support for the Globus Toolkit - the reference plat...
Autores principales: | , , , , , , |
---|---|
Lenguaje: | eng |
Publicado: |
2019
|
Materias: | |
Acceso en línea: | https://dx.doi.org/10.1051/epjconf/201921404045 http://cds.cern.ch/record/2701407 |
_version_ | 1780964602079608832 |
---|---|
author | Bockelman, Brian Hanushevsky, Andrew Keeble, Oliver Lassnig, Mario Millar, Paul Weitzel, Derek Yang, Wei |
author_facet | Bockelman, Brian Hanushevsky, Andrew Keeble, Oliver Lassnig, Mario Millar, Paul Weitzel, Derek Yang, Wei |
author_sort | Bockelman, Brian |
collection | CERN |
description | GridFTP transfers and the corresponding Grid Security Infrastructure (GSI)-based authentication and authorization system have been data transfer pillars of the Worldwide LHC Computing Grid (WLCG) for more than a decade. However, in 2017, the end of support for the Globus Toolkit - the reference platform for these technologies - was announced. This has reinvigorated and expanded efforts to replace these pillars. We present an end-to-end alternate utilizing HTTP-based WebDAV as the transfer protocol, and bearer tokens for distributed authorization. This alternate ecosystem, integrating significant pre-existing work and ideas in the area, adheres to common industry standards to the fullest extent possible, with minimal agreed-upon extensions or common interpretations of the core protocols. The bearer token approach allows resource providers to delegate authorization decisions to the LHC experiments for experiment-dedicated storage areas. This demonstration touches the entirety of the stack - from multiple storage element implementations to FTS3 to the Rucio data management system. We show how the traditional production and user workflows can be reworked utilizing bearer tokens, eliminating the need for GSI proxy certificates for storage interactions. |
id | oai-inspirehep.net-1760997 |
institution | Organización Europea para la Investigación Nuclear |
language | eng |
publishDate | 2019 |
record_format | invenio |
spelling | oai-inspirehep.net-17609972022-08-10T12:22:27Zdoi:10.1051/epjconf/201921404045http://cds.cern.ch/record/2701407engBockelman, BrianHanushevsky, AndrewKeeble, OliverLassnig, MarioMillar, PaulWeitzel, DerekYang, WeiBootstrapping a new LHC data transfer ecosystemComputing and ComputersGridFTP transfers and the corresponding Grid Security Infrastructure (GSI)-based authentication and authorization system have been data transfer pillars of the Worldwide LHC Computing Grid (WLCG) for more than a decade. However, in 2017, the end of support for the Globus Toolkit - the reference platform for these technologies - was announced. This has reinvigorated and expanded efforts to replace these pillars. We present an end-to-end alternate utilizing HTTP-based WebDAV as the transfer protocol, and bearer tokens for distributed authorization. This alternate ecosystem, integrating significant pre-existing work and ideas in the area, adheres to common industry standards to the fullest extent possible, with minimal agreed-upon extensions or common interpretations of the core protocols. The bearer token approach allows resource providers to delegate authorization decisions to the LHC experiments for experiment-dedicated storage areas. This demonstration touches the entirety of the stack - from multiple storage element implementations to FTS3 to the Rucio data management system. We show how the traditional production and user workflows can be reworked utilizing bearer tokens, eliminating the need for GSI proxy certificates for storage interactions.oai:inspirehep.net:17609972019 |
spellingShingle | Computing and Computers Bockelman, Brian Hanushevsky, Andrew Keeble, Oliver Lassnig, Mario Millar, Paul Weitzel, Derek Yang, Wei Bootstrapping a new LHC data transfer ecosystem |
title | Bootstrapping a new LHC data transfer ecosystem |
title_full | Bootstrapping a new LHC data transfer ecosystem |
title_fullStr | Bootstrapping a new LHC data transfer ecosystem |
title_full_unstemmed | Bootstrapping a new LHC data transfer ecosystem |
title_short | Bootstrapping a new LHC data transfer ecosystem |
title_sort | bootstrapping a new lhc data transfer ecosystem |
topic | Computing and Computers |
url | https://dx.doi.org/10.1051/epjconf/201921404045 http://cds.cern.ch/record/2701407 |
work_keys_str_mv | AT bockelmanbrian bootstrappinganewlhcdatatransferecosystem AT hanushevskyandrew bootstrappinganewlhcdatatransferecosystem AT keebleoliver bootstrappinganewlhcdatatransferecosystem AT lassnigmario bootstrappinganewlhcdatatransferecosystem AT millarpaul bootstrappinganewlhcdatatransferecosystem AT weitzelderek bootstrappinganewlhcdatatransferecosystem AT yangwei bootstrappinganewlhcdatatransferecosystem |