One Login for FAIRagro
Abstract
FAIRagro establishes a central Authentication and Authorization Infrastructure (AAI) to provide secure and consistent access to its services and research data. Having a central AAI avoids the need for multiple accounts, simplifies user onboarding and supports compliance with legal and institutional requirements. The integration is realized collaboratively by M3.6, M4.1, and M4.2.
Full text
This work was created as part of the NFDI consortium FAIRagro (www.fairagro.net). We gratefully acknowledge the financial support of the German Research Foundation (DFG) – project number 501899475 Founded by Our paper Carmen Scheuner (Senckenberg Museum of Natural History Görlitz), David Arnold (Leibniz Centre for Agricultural Landscape Research, ZALF), Stephan Lesch (Senckenberg Museum of Natural History Görlitz), Daniel Arend (Leibniz Institute of Plant Genetics and Crop Plant Research, IPK), Xenia Specka (Leibniz Centre for Agricultural Landscape Research, ZALF) on behalf of the FAIRagro consortium One Login for FAIRagro FAIRagro establishes a central Authentication and Authorization Infrastructure (AAI) to provide secure and consistent access to its services and research data. Having a central AAI avoids the need for multiple accounts, simplifies user onboarding and supports compliance with legal and institutional requirements. The integration is realized collaboratively by M3.6, M4.1, and M4.2. Legal Workshop (Apr. 2024): current practices and challenges of Research Data Infrastructures (RDIs) with sensitive data → need for clear legal metadata on licensing and access conditions FAIRagro will support different levels of RDI integration. Access rights will be expressed using ODRL (Open Digital Rights Language) policies, which are then embedded in the metadata of a data set. •Variant 1 – Independent Access Control •Variant 2 – Hybrid Model •Variant 3 – Centralized Model Application: Restricted Data Sets IAM4NFDI Incubator (Sept. 2024 – Feb. 2025): evaluation of the four AAI solutions proposed by IAM4NFDI (AcademicID, didmos, Helmholtz AAI, RegApp). •Requirements: restricted data access, group management, account linking •Results: none of solutions fully met the FAIRagro needs due to various reasons •Decision: operate a dedicated FAIRagro Keycloak instance Background Final Report: https://doi.org/ 10.5281/ zenodo.17061022 Do you run a service that requires user management? → Contact us! carmen.scheuner@ senckenberg.de [email protected] Request / Trust User information + access rights Redirect User request RDI Data set Metadata (ODRL) Search Hub AAI User informationRedirect User request RDI Data set Metadata (ODRL) Search Hub AAI Redirect User request RDI Data set Metadata (ODRL) Search Hub AAI Direct Login via ORCID Service Service via DFN-AAI Future Integration no integration effort separate user accounts per RDI full autonomy streamlined processes not possible integration effort Single Sign-On via FAIRagro AAI autonomy in access control streamlined processes not possible integration effort uniform user experience less autonomy in access control, requires trust in central FAIRagro AAI streamlined processes possible Service Integration As an example service, Nextcloud is already integrated into FAIRagro AAI, and further services will follow step by step. In addition to direct login, ORCID is available as an Identity Provider, with DFN-AAI planned for future integration. RDI RDI RDI