Research use of sensitive information -- personally identifiable information (PII), protected health information (PHI), commercial or proprietary data, and the like -- is increasing as researchers' skill with "big data" matures. Duke University's Protected Network is an environment with technical controls in place that provide research groups with essential pieces of security measures needed for studies using sensitive information. The environment uses virtualization and authorization groups extensively to isolate data, provide elasticity of resources, and flexibly meet a range of computational requirements within tightly controlled network boundaries. Since its beginning in 2011, the environment has supported about 200 research projects and groups and has served as a foundation for specialized and protected IT infrastructures in the social sciences, population studies, and medical research. This article lays out key features of the development of the Protected Network and outlines the IT infrastructure design and organizational features that Duke has used in establishing this resource for researchers. It consists of four sections: 1. Context, 2. Infrastructure, 3. Authentication and identity management, and 4. The infrastructure as a "platform."
翻译:研究敏感信息 -- -- 个人识别信息(PII)、保护健康信息(PHI)、商业或专利数据等 -- -- 随着研究人员掌握“大数据”技能的成熟,研究使用敏感信息(PII)、保护健康信息(PHI)、商业或专有数据等 -- -- 随着研究人员使用“大数据”技能的成熟,研究使用敏感信息(PHI)、商业或专有数据(PHI)、商业或专有数据等 -- -- 正在增加。杜克大学的保护网络是一个具有技术控制的环境,为研究小组提供使用敏感信息所需的基本安全措施。环境使用虚拟化和授权小组广泛隔离数据,提供资源的弹性,灵活满足严格控制网络边界内的一系列计算要求。自2011年开始以来,环境支持了大约200个研究项目和团体,并成为社会科学、人口研究和医学研究中专门和受保护的信息技术基础设施的基础。该文章阐述了保护网络发展的关键特征,概述了杜克在为研究人员建立这一资源时使用的信息技术基础设施设计和组织特点。它由四个部分组成:1. 背景、2.基础设施、3.验证和身份管理,以及4.基础设施作为“平台”的基础设施。