Managing user identities across restricted access Beacons and within federated data-discovery networks
Tim Beck, Farid Yavari Dizjikan, Colin Veal, Tom Shorter, Greg Warren, Mehdi Mehtarizadeh, Anthony J. Brookes · 2020
Global Alliance for Genomics & Health (GA4GH) ‘Beacons’ enable the sharing of genomic and clinical data across federated networks. Data controllers can determine the access level granted to Beacon users depending on each user’s authentication and authorization status. The University of Leicester Beacon provides aggregated discovery across two public data sets and one controlled access sensitive data set. The open-access Beacon endpoint is https://beacon.cafevariome.org. In order to manage user identities, we have implemented the OpenID Connect authentication protocol for requesting, exchanging, and validating tokens between the Beacon and an OpenID Provider. Alongside our local Identity and Access Management (IAM) server we are currently introducing the ELIXIR AAI as a parallel OpenID Provider. We are extending this approach to manage user identities within Cafe Variome (https://www.cafevariome.org) data discovery private networks. Each user within a private network will have installation-specific permissions based on their own claims obtained from a single sign-on server and federated across the network using the OpenID Connect model.