Hyppää sisältöön
    • Suomeksi
    • In English
Trepo
  • Suomeksi
  • In English
  • Kirjaudu
Näytä viite 
  •   Etusivu
  • Trepo
  • Opinnäytteet - ylempi korkeakoulututkinto
  • Näytä viite
  •   Etusivu
  • Trepo
  • Opinnäytteet - ylempi korkeakoulututkinto
  • Näytä viite
JavaScript is disabled for your browser. Some features of this site may not work without it.

A Federated Identity and Access Management Architecture for Roaming Researcher Access

Nauholz, Jaakko (2026)

 
Avaa tiedosto
NauholzJaakko.pdf (803.9Kt)
Lataukset: 



Nauholz, Jaakko
2026

Tietojenkäsittelyopin maisteriohjelma - Master's Programme in Computer Science
Informaatioteknologian ja viestinnän tiedekunta - Faculty of Information Technology and Communication Sciences
This publication is copyrighted. You may download, display and print it for Your own personal use. Commercial use is prohibited.
Hyväksymispäivämäärä
2026-06-09
Näytä kaikki kuvailutiedot
Julkaisun pysyvä osoite on
https://urn.fi/URN:NBN:fi:tuni-202606087118
Tiivistelmä
The secondary use of health data for research in the European Union remains limited despite the significant potential value of existing datasets. The key barriers to the secondary use of health data are a fragmented identity and access management landscape and complex cross-organisational authentication procedures that require the creation and management of new credentials for each organisation accessed.
The objective of this thesis is to design and evaluate an identity and access management architecture that enables a roaming access model for researchers to access health data across organisational and national boundaries. The focus of the work is on mitigating access-related architectural challenges rather than addressing operational or legal approval processes.
The theoretical background of the thesis covers identity and access management concepts, federated research infrastructures and the European regulatory context, including the European Health Data Space and the General Data Protection Regulation. This theoretical background is used to derive a set of functional and non-functional requirements that guide the development of the proposed solution.
The study follows the Design Science Research Methodology and implements a proof-of-concept artefact of the proposed architecture based on federated identity brokering, cluster-based federations and multi-layered access control. The proof-of-concept simulates a federated research environment consisting of multiple organisations grouped into two federation clusters, where each organisation operates a secure processing environment. Researchers authenticate using the credentials of their home organisation and can roam to secure processing environments in other organisations both within and across clusters. This approach enables access to federated learning environments without the need to create new credentials for each new organisation.
The artefact is evaluated to assess how well it meets the objectives set for it, using scenario-based evaluation, architecture-level analysis, and an evaluation of requirements and regulatory alignment.
The results of the evaluation process indicate that the proposed architecture enables seamless cross-organisational and cross-cluster authentication while reducing credential proliferation and preserving organisational autonomy. The findings suggest that at a technical level federated identity and access management can support a roaming access model that aligns with the goals of the European Health Data Space without the need to develop new authentication technologies.
Kokoelmat
  • Opinnäytteet - ylempi korkeakoulututkinto [43034]
Kalevantie 5
PL 617
33014 Tampereen yliopisto
oa[@]tuni.fi | Tietosuoja | Saavutettavuusseloste
 

 

Selaa kokoelmaa

TekijätNimekkeetTiedekunta (2019 -)Tiedekunta (- 2018)Tutkinto-ohjelmat ja opintosuunnatAvainsanatJulkaisuajatKokoelmat

Omat tiedot

Kirjaudu sisäänRekisteröidy
Kalevantie 5
PL 617
33014 Tampereen yliopisto
oa[@]tuni.fi | Tietosuoja | Saavutettavuusseloste