11–15 Mar 2024
Charles B. Wang Center, Stony Brook University
US/Eastern timezone

Implementation of zero trust security strategy in HEPS scientific computing system

14 Mar 2024, 16:10
30m
Charles B. Wang Center, Stony Brook University

Charles B. Wang Center, Stony Brook University

100 Circle Rd, Stony Brook, NY 11794
Poster Track 2: Data Analysis - Algorithms and Tools Poster session with coffee break

Speaker

Qingbao Hu (IHEP)

Description

Traditionally, data centers provide computing services to the outside world, and their security policies are usually separated from the outside world based on firewalls and other security defense boundaries. Users access the data center intranet through VPN, and individuals or endpoints connected through remote methods receive a higher level of trust to use computing services than individuals or endpoints outside the perimeter. But this approach to security design is never ideal. Zero Trust security is based on de-peripheralization and least-privilege access, which protects intranet assets and services from vulnerabilities inherent in the network perimeter and implicit trust architecture. In order to meet the diverse data analysis needs of light source users, the HEPS scientific computing system provides an interactive computing service model for external network users. Users can directly access intranet computing resources through web pages. In this service model, how do we refer to the zero-trust security idea? It has become very urgent to realize the minimum permission access between various services of the computing system and improve the security level of the system environment. Based on the zero-trust security strategy, this paper designs an inter-service communication mechanism based on user identity tokens. During the function call process between different services, service permissions are allocated based on the token user identity to achieve fine-grained management of service permissions and ensure the Cybersecurity of HEPS scientific computing systems.

Primary authors

Mr Jiping Xu (IHEP) Qingbao Hu (IHEP) Yaosong Cheng (Institute of High Energy Physics Chinese Academy of Sciences, IHEP) qi luo (中科院高能物理所计算中心)

Presentation materials