Skip to main content
Graphic demonstrating the federated id layer between genesis users and DOE resource providers.

Map to Federation

Understanding the role of federated access in Genesis workflows
Text Area

What is Federated Identity?

The American Science Cloud (AmSC) is one of the cornerstone infrastructure efforts supporting DOE’s Genesis Mission, providing capabilities for the DOE Office of Science and Applied Energy complex. NNSA is developing a complementary capability through the AI National Security Platform (ANSP). Together, AmSC and ANSP are working toward the integrated digital infrastructure needed to connect the people, computing, AI models, data, and other scientific resources that make up the broader Genesis ecosystem. A foundational element of that infrastructure is Federated Identity (FederatedID).

FederatedID is intended to provide researchers with a secure and more seamless way to access resources distributed across participating organizations. Rather than requiring users to establish and maintain a separate identity for every facility or service, users authenticate through a trusted Identity Provider (IdP)—such as their DOE national laboratory—and that trusted identity can be recognized across the federation. The architecture is also designed to accommodate additional trusted identity providers as Genesis expands to include industry, academic, and other partners.

 

Text Area

Centralized access layer, not centralized control

Importantly, AmSC is not a single computing system or centrally operated cloud. It is a federation of independently owned and operated resources. The goal of FederatedID is therefore not to centralize control, but to establish a common trust and access layer across those resources. Authentication can be federated while authorization remains with the resource owner. 

Each participating facility or provider determines:

  1.  Who may use a given resource

  2.  What they may access

  3. The conditions of that access and use.

AmSC provides trusted information about

  1. The user

  2. The project

  3. The access context

to support these decisions. 

Understanding the Design

The technical design follows Zero Trust principles and uses standards-based technologies, including OAuth 2.0 and OpenID Connect (OIDC). After authentication, AmSC can issue short-lived, dynamically scoped access tokens—referred to as AmSC Keycards—that securely convey the user's identity and active project context to AmSC services and participating resource providers. Project context is particularly important because it connects the authenticated individual with the scientific project, resource entitlements, allocations, and other authorization information associated with the work being performed.

Agent and machine identities

This same trust model extends beyond individual researchers to agents and machine identities needed for increasingly automated scientific workflows. Machine identities can act as delegates on behalf of an authorized researcher, with their actions tied to the originating user and authorized project context. Combined with AmSC's API Gateway, policy enforcement, and Resource Integration Gateway (RIG), this provides a path for securely routing both human- and machine-initiated requests to distributed resources while maintaining appropriate authorization and policy controls.

Beyond SSO

FederatedID is therefore more than a Single Sign-On (SSO) capability. It is a foundational layer for the larger AmSC architecture and ultimately for Genesis: establishing the trusted identity, project, and authorization context needed for users and automated workflows to move across computing systems, AI models, data resources, scientific facilities, and other services without requiring every provider to recreate the complete identity and access-management process independently. The AmSC Core Services Architecture builds on this foundation to provide the broader set of federated services required for scientific discovery across the Genesis ecosystem.

 

Text Area

Why this matters

Today, gaining access to multiple scientific resources can require researchers to establish separate accounts, repeat identity and vetting processes, and manage different credentials and access mechanisms at each facility or provider. That model becomes increasingly difficult to scale as Genesis workflows begin to span multiple computing facilities, data sources, AI models, instruments, and organizations. FederatedID provides the trust foundation needed to make those resources operate more like a connected scientific ecosystem—allowing researchers, applications, and AI agents to securely move across resources while preserving each provider’s control over its own infrastructure. Without this capability, the vision of seamless, cross-facility and increasingly autonomous Genesis workflows would be extremely difficult to achieve at scale.

 

Text Area

Submit a support ticket for any of the following:

  • Connect your team with services like data management planning, supercharging your scientific workflows with AI best practices, and cross-cutting AI capabilities.

  • Have an issue, suggestion, or addition to this content.

Click to Submit a Support Ticket