Speaker
Description
Open Science does not necessarily mean that everything should be made openly available. Researchers should have the decision to openly share their research data and software or to publish their research output with restrictions due to privacy concerns for research participants, political sensitivities, or commercial reasons. Either way, robust research infrastructure should guard the services provided for researchers to be resilient against malicious use of data or attacks. Trust and security are the main drivers for this purpose.
For this reason, NFDIxCS has designed an architecture in which trust and security rank among the highest priorities for structuring its services. This requires building a controlled environment organized into security zones, where services and users must be authenticated, and only identified services can communicate freely within their zone or through controlled bridges to neighbouring zones. Zone-based access carries inherent risk: co-location within a zone may falsely imply trustworthiness, creating an attack surface. Authentication counters this by validating identity independent of zone placement. Together, these measures implement zero trust principles by combining structural containment with identity verification.
This architecture serves not only to secure internal communication but also to integrate external services, such as NFDI4Base services and other existing services in the research data and software management landscape. NFDIxCS services are primarily centred around the creation of Research Data Management Containers (RDMCs), for example the RDMC Creation Workflow, the RDMC Search Engine, and Metabase. The RDMC Creation Workflow guides users through the process of assembling research artefacts, creates a Reusable Execution Environment to test the artefact, adds metadata, and publishes the results into an archive. This connects with the RDMC Search Engine, which provides users easy access to search for created RDMCs. Metabase provides entry points for standardized metadata standards such as ontologies and offers a reasoning service based on given data and combined ontologies. These services already use NFDI4Base services. IAM4NFDI is connected to services for user identification. PID4NFDI is integrated into the publishing process of RDMCs for creating metadata-enriched ePIC PIDs. TS4NFDI is integrated into RDMC creation to add standardized metadata. In upcoming work, other base services such as DMP4NFDI and KGI4NFDI will be connected to internal services, but the use case needs to be worked out.
This contribution demonstrates how NFDI4Base services are technically used and integrated within NFDIxCS, and how services can be integrated into a secure environment. The development of infrastructure in NFDI is highly decentralized due to discipline-specific consortia and different research institutions. Reusing services is a central aspect. With similar security mechanisms, local resilience can be maintained without losing efficiency in cooperation. This contribution is one piece in this puzzle.
| background | NFDIxCS |
|---|