Analysis of data security from online data-taking to publication in ATLAS at CERN

Abstract

This thesis focuses on two main objectives. The first is remote access to online data taking systems at ATLAS experiment in CERN. The thesis, after assessment of current situation and recognising areas of possible improvements, suggests the improvements to the ATLAS environment in form of disabling direct access to online data taking systems from the internet and using VPN to access ATLAS network, suggesting different account management and access policies and proposing different authentication scheme where multi factor authentication is used. The second one is data rights management and data control of ATLAS measured and calculated data. System of downloading data to local stations makes really hard to enforce any restrictions. However, it is necessary to keep this option, and so development of data rights management solution is suggested, because no commercial or open source alternatives are available for this format of the data. This data rights management solutions encrypts data which leave ATLAS servers and so request for decryption key must be made towards ATLAS when those data are accessed. Assessment of current situation in both main objectives reveals that the greatest problem is in use of uncontrolled personal stations and so all security precautions must be taken on side of ATLAS

    Similar works