FRIDGE

Harnessing the power of AIRR supercomputers for trusted research

Jim Madge

Alan Turing Institute

Why sensitive data?

Data Ecosystem by Scriberia. Used under CC-BY 4.0 10.5281/zenodo.13882307

Why trusted research environments?

Sensitive Data by Scriberia. Used under CC-BY 4.0 10.5281/zenodo.13882307

Why HPC?

Machine Learning Reusable Pipelineby Scriberia, modified. Used under CC-BY 4.0 10.5281/zenodo.13882307

TREs are not HPC

  • Security is top priority
  • Lack HPC hardware
  • Scaling is expensive
  • Often designed for a single domain

HPC is not a TRE

  • Designed for performance or throughput
  • Shared systems
  • Public
  • Few controls for data ingress and egress

FRIDGE

A ready-to-use SATRE compliant TRE that can be deployed to AIRR

Shared responsibility

Need agreement between TRE operator and infrastructure provider

Extend TRE governance to a secure enclave on HPC (the TRE tenancy)

Delegate information governance to the TRE operator

TRE operator 🧑‍⚖️

  • User management
  • Data processing
  • Data ingress and merging
  • Release of results

Infrastructure provider 🧑‍🔧

  • Securing TRE tenancy
  • Providing FRIDGE-compatible K8s
    • GPU passthrough
    • Compatible CNI

FRIDGE architecture

FRIDGE implementation

Security

Inside K8s 🚢

  • RBAC
  • Pod security standards
  • Network policy
  • Automatic encryption of volumes

On the host 🏢

  • Site-to-site VPN
  • TRE tenancy isolation

Progress

Project

  • Shared responsibility model ✅
  • TRE tenancy ✅
  • MVP implementation on Azure ✅
  • Job submission API 🚧

on Dawn

  • On-demand K8s cluster ✅
  • GPU passthrough ✅
  • Fridge development deployment ✅
  • S2S VPN 🚧
  • PVC encryption 🚧

Lessons

  • Multi-party governance is difficult
  • Self-service HPC has arrived
  • K8s implementations differ
  • Don't reinvent the wheel

Future

Cardiac digital twin

🫀

Scaling to many nodes

🚀

Confidential computing

🔐

Acknowledgements

Banner Thanks by Scriberia. Used under CC-BY 4.0 10.5281/zenodo.13882307

Development Team


DARE UK

Funding this work through the DARE UK Early Adopters programme

Scriberia and The Turing Way

Who we work with to make the excellent, openly licensed, illustrations

Try it out and contribute

alan-turing-institute/fridge

Explore other DARE UK activities

Early Adopters
TREvolution

Get involved

uktre.org
satre-specification.readthedocs.io