KIT | KIT-Bibliothek | Impressum | Datenschutz

Extending an Open-Source Federated Identity Management System for Enhanced HPC Security

Buchmüller, Jennifer 1,2; Raffeiner, Simon 1,2; Simon, Michael ORCID iD icon 1,2; Obermaier, Holger 1,2; Weisbrod, Peter 1,2; Weiß, Ulrich ORCID iD icon 1,2; Nußbaumer, Martin ORCID iD icon 1,2
1 Karlsruher Institut für Technologie (KIT)
2 Scientific Computing Center (SCC), Karlsruher Institut für Technologie (KIT)

Abstract:

Strengthening the security infrastructure around HPC systems has become an urgent and important task, driven especially by the impact of a recent large-scale attack on the world-wide HPC community by a yet unknown party. Multiple European HPC systems had to be shut down for several weeks in mid-May of 2020 after backdoors were found on the systems. In the aftermath of the attack, two core security issues were identified: the absence of strong authentication, and a wide-spread practice of insecure handling of SSH key pairs.

We present our approach for extending an existing, open source, federated identity management system with user-friendly two-factor authentication (2FA) using Time-Based One-Time Password (TOTP) and centralized, secure SSH key management. A special focus will be put on how we integrated scientific workflows and automation with the new security measures by combining 2FA, SSH key management and security policies in an elegant, secure and user-friendly way.


Volltext §
DOI: 10.5445/IR/1000152866
Veröffentlicht am 18.11.2022
Cover der Publikation
Zugehörige Institution(en) am KIT Scientific Computing Center (SCC)
Publikationstyp Vortrag
Publikationsdatum 17.11.2020
Sprache Englisch
Identifikator KITopen-ID: 1000152866
Veranstaltung The International Conference for High Performance Computing, Networking, Storage, and Analysis (2020, SC20 2020), Online, 09.11.2020 – 19.11.2020
Schlagwörter IT Security, High-Performance Computing, HPC Security, Federated Identity Management, Identity Management
KIT – Die Forschungsuniversität in der Helmholtz-Gemeinschaft
KITopen Landing Page