ResearchSoftwareInstitute / greendatatranslator

Green Team Data Translator Software Engineering and Development
BSD 3-Clause "New" or "Revised" License
2 stars 1 forks source link

Security #90

Closed stevencox closed 6 years ago

stevencox commented 6 years ago

Develop a technical architecture roadmap for securing Translator services. Working with Identity team at UNC on ways to secure clinical data via Shibboleth. First meeting held last week. We're doing independent research for a few days and will get back together soon. So far, we have not been able to identify a solution that gets us a working prototype in October.

stevencox commented 6 years ago

Notional initial prototype developed. This repository includes a Jupyter notebook that

Configuration involves:

Integration with the UNC test IdP includes registration of a test Onyen

@rayi113 is investigating getting a person who can interact with UNC Identity management folks to complete the steps to integrate with the UNC test IdP.

stevencox commented 6 years ago

At the hackathon, we moved on from the idea of protecting web services with SAML for real patient data. We concluded that real patient data is different and we'll use traditional, human in the loop approaches. So the shibboleth implementation is tabled.

In the mean time, we are moving ahead with a somewhat complex plan that includes:

stevencox commented 6 years ago

Tweetsie migration is handled in #96 . The broader security question for patient data is resolved.

stevencox commented 6 years ago

Getting legal attestation that RENCI is part of the same covered entity as UNC in response to Ken Langley's request late last week.

stevencox commented 6 years ago

Approach supplanted by clinical feature vectors and evidence based regrouping.