Achieve Secure Cloud-Based Research with the Research Gateway on Azure

November 27, 2024

Overview

The Secure Enclave for Research (also known as the Secure Research Enclave) from Microsoft is a reference architecture designed for a remotely accessible environment that researchers can use securely while working with restricted data sets. This solution features robust mechanisms for controlling user access to the environment and managing the movement of data in or out of its scope for analysis, making it ideal for handling sensitive information.

Data within the environment can be analyzed using traditional virtual machines (VMs) that run on either Windows or Linux, utilizing well-known tools such as R Studio. Additionally, it supports the use of advanced analytical tools like Azure Machine Learning.

The solution is built using multiple Azure services, including Azure Virtual Desktop, Azure Key Vault, and Azure Data Factory, to provide strong control over data movement into and out of the environment and to prevent unauthorized access to data sets.

Key ask from the customer

A large university focused on Health Sciences Research wanted to make it easy for researchers to concentrate on science rather than on servers. With the need to protect data and comply with HIPAA standards, there was a need for a secure, compliant, and simple solution for scaling up research in the cloud.

The AI & Machine Learning Architecture of Microsoft provides a prescriptive model for a secure research environment for regulated data. This architecture shows a secure environment that allows researchers to access sensitive data with a higher degree of control and protection. It is applicable to organizations that are bound by regulatory compliance or strict security requirements.

While evaluating the proposed solution, the university sought a UI-based portal to facilitate the adoption of the architecture in a frictionless manner, with the following key enhancements using the Research Gateway platform:

  1. Implement Research Gateway to support Microsoft Azure Cloud workloads, with enhancements for multi-cloud orchestration.
  2. Provide a Key Orchestration Layer through Research Gateway that integrates multiple Azure workloads, underlying products, and services, simplifying access for researchers.
  3. Offer a Standard Pre-Built Catalog of products for researchers on Azure, which includes Azure VMs (Linux and Windows) and Azure Blob Storage.
  4. Establish Default Project Storage based on Azure Blob Storage, allowing this storage to be mounted on both Linux and Windows workloads.
  5. Implement Azure Cost and Budget Controls to enable effective cost tracking.
  6. Create an Azure Multi-Account Management Structure for research projects that ensures isolation, control, and secure access.
  7. Support Secure Research Environments with capabilities for data management and Ingress & Egress controls.

Our Solution

Our Research Gateway platform is a self-service portal for research computing in the cloud, supporting a common orchestration layer for workloads along with cost management, collaboration, and secure data management.

Navigating the complexities of IT operations can be daunting, especially in a research setting where time is of the essence. The Research Gateway platform simplifies this process with its plug-and-play solution, enabling teams to operate efficiently and focus on essential tasks. This ease of use reduces the workload on IT staff, allowing them to dedicate more time to support innovative research initiatives.

Effective budget management is crucial for the success of any research project. The Research Gateway platform offers customized budget management tools that enable teams to track, control, and manage their research budgets with precision. By allocating funds precisely where needed, research organizations can avoid the pitfalls of overspending while ensuring that all necessary resources are available to their teams.

The following figure illustrates the Research Gateway architecture deployed on Azure, utilizing Azure Well-Architected Frameworks and landing zone setup.

Take the next step toward Secure Research excellence

Whether it's enabling secure collaborations or optimizing costs, the platform is a game-changer for organizations navigating the challenges of cloud-based research. To learn how the Research Gateway can elevate your research initiatives, contact us at marketing@relevancelab.com

Tags
Research Gateway
Microsoft Azure