Authors: Kristyna Kvizdova
Document classification: public
| version | date | changes made | |
| 0.1 | 2025-03-11 | Document creation | Kristyna Kvizdova |
| 0.2 | 2026-02-27 | Review phase before publishing | Kristyna Kvizdova |
| 1.0 | 2026-05-20 | Document published 1.0 | Kristyna Kvizdova |
Contents of the document
1. Life Science AAI Introduction
1.1. Life Science AAI definition
1.5.1. Level of Users of LS AAI
1.6. Technical Conditions for the LS AAI Operations
2. Processing of Personal Data
2.1. Providing Personal data to Services
3.1. Lifecycle of User Accounts and Membership in Virtual Organizations 8
3.1.1. Registration (Application) to a Virtual Organization
3.1.4. Termination of Membership
3.1.5. Lifecycle in Hierarchical Virtual Organizations
3.1.6. Termination of User Account
3.2. Lifecycle of Virtual Organization
3.2.1. Creation of Virtual Organization
3.2.2. Management of Virtual Organization
3.2.3. Termination of Virtual Organization
3.4. Lifecycle of a Group Membership
3.4.1. Creation of a Group Membership
3.4.1.1. Creation of Direct Group Membership
3.4.1.2. Creation of Indirect Group Membership
3.4.2. Active Group Membership
3.4.3. Inactive Group Membership
3.4.4. Termination of Group Membership
3.5. Lifecycle of Service Account
3.5.1. Creation of Service Account
3.5.2. Management of Service Account
3.5.3. Termination of Service Account
3.6.3. Termination of Facility
4.3. Users with higher privileges
4.3.1. Administrator of Virtual Organization
4.3.3. Owner of Service Account
5. Conditions for Connecting Services
6. Creation of Virtual Organization
Life Science AAI Introduction
1.1. Life Science AAI definition
The Authentication and Authorization Infrastructure of the Life Science e-infrastructure (hereinafter referred to as “LS AAI”) is designed for managing user accounts and securely verifying (authentication) and approving (authorization) access to services connected to Life Science AAI.
Thanks to LS AAI, users can access Life Science services without needing to create new accounts for each individual service. LS AAI enables services to delegate authentication and authorization use cases to it enhancing security and user convenience. This ensures the secure and seamless sharing and use of scientific resources across various institutions at both national and international levels.
Services can decide whether to use LS AAI or whether to handle authentication and authorization through another suitable method instead. In case a service decides to use LS AAI, they must follow Terms of Use of LS AAI for Service providers and instructions to connect a service to LS AAI.
LS AAI is built according to the international AARC Blueprint Architecture recommendations and provides the following functions:
- User registration
- Service registration
- Management of user information
- Management of service information
- User access control to services
- Management of user information provided to services
- Translation between different authentication protocols (SAML2, OIDC, OAuth 2.0)
- Merging multiple authentication methods of a single user into one account
LS AAI is intended for users defined in section 1.5. and organizations operating services as defined in section 1.4..
1.2. Basic Terminology
The terms LS AAI and Operators of LS AAI are defined in the document Terms of Use for Service Providers.
A Virtual Organization (hereinafter referred to as “VO”) is a group of users with established rules for membership and lifecycle.
In the hierarchy of VOs, a parent VO refers to a superior VO, while a member VO refers to a subordinate VO.
A Service is an instance of a software system that users can access and use over a network. A service may have a web-based user interface but can also be accessible via other protocols, such as SSH, NFS, or S3.
A User is defined in section 1.5..
A User Account is either a representation of a natural person (LS AAI User) or a representation of non-personal (typically machine-based) access, known as a service account.
1.3. Operator of LS AAI
The Operator of LS AAI is Masaryk University (Žerotínovo nám. 617/9, 601 77 Brno).
1.4. Operator of Services
The operator of each service connected to LS AAI must always be an organization with legal personality (a legal entity). The Service Operator is responsible for its operation.
User access to services is governed by access conditions, which are set by the operator of each service. The operator must publish the access conditions for a given service on their website or the service’s website.
The following services can be connected to LS AAI:
- services endorsed by any of the Lifescience RI are automatically approved
- any other services are reviewed and evaluated individually by the LS AAI operator
1.5. LS AAI Users
A User is a natural person who registers to LS AAI.
1.5.1. Level of Users of LS AAI
LS AAI distinguishes between two levels of users, which services can use to manage user access:
An eligible user of LS AAI can be:
- any natural person authenticated by an identity provider in eduGAIN
- any natural person manually approved by LS AAI operator
There is no legal entitlement to the eligibility for user account in LS AAI; in disputed cases, its assignment is decided by the operator of LS AAI.
Authorized User: Anyone who can authenticate using one of the supported authentication methods and register a user account.
Supported authentication methods include:
- Institutional Login: account at an organization participating in the international interfederation eduGAIN.
- Social Identity Providers that do not guarantee the actual identity of the person, such as ORCID, Apple, Google, LinkedIn, GitHub.
- LifeScience Hostel (a local LS AAI account) that does not guarantee the actual identity of the person.
1.6. Technical Conditions for the LS AAI Operations
- LS AAI is provided on a “best effort” basis, without a guarantee of specific availability. The expected availability is 99% of the time.
- The operator of LS AAI makes every possible effort to ensure that LS AAI remains available with minimal downtime and implements backup and recovery measures for this purpose.
- The operator of LS AAI has an Information Security Management System (ISMS) in place and holds an ISO/IEC 27001 certification.
- All time-related data in LS AAI is presented in Central European Time (CET).
2. Processing of Personal Data
The collection and processing of personal data in LS AAI is governed by the Policy on the Processing of Personal Data of the LS AAI Service. Furthermore, the following rules apply:
- Upon registration and subsequent authentication in LS AAI, the user provides their personal data to the operator of LS AAI.
- The processing of personal data in LS AAI is governed by the rules of the virtual organizations (VOs) in which the user is a member.
- When registering with the ’Life Science Community’ virtual organization, which represents all users of the LifeScience e-infrastructure, personal data is shared with the Operators of the LS AAI, who act as controllers of personal data.
- When registering with other virtual organizations, the user is informed in the registration form about which organization (legal entity) acts as the data controller for that particular VO.
- The personal data of virtual organization members is accessible to the VO administrators and group administrators within the same VO. A VO or group administrator can be any user, even if they are not a member of the respective VO or group.
- Personal data is processed for the duration of the user account’s existence, unless explicitly stated otherwise (after which the data is deleted or anonymized).
- Personal data of LS AAI users is processed exclusively within the territory of the European Union.
2.1. Providing Personal data to Services
The service provider is always responsible for processing of personal data within each service, as defined in section 1.4. Service Providers
Personal data is transferred from LS AAI to a service in two cases:
- At the user’s request during user authentication to the service via LS AAI (using the OIDC or SAML protocol).
- Automatically when creating or updating the user’s account in the service (using a protocol agreed upon between the service provider and the LS AAI operator).
If personal data is transferred between different data controllers during authentication (i.e., with the user’s involvement), the user is explicitly informed of the transfer.
The first automatic transfer of personal data (i.e., without the user’s involvement) to the service occurs when the user becomes an active member of a group for which the service is available. Further automatic transfers occur when previously transferred personal data is updated. This follows the principle of IAM (Identity and Access Management), where LS AAI actively propagates user data to the service via the agreed protocol.
The user is informed about the automatic transfer of personal data during registration to the group that grants access to the service.
3. Life cycles
3.1. Lifecycle of User Accounts and Membership in Virtual Organizations
A user’s natural person in LS AAI is represented by a user account. The user account is linked to one or more memberships in virtual organizations.
A user account is created during the registration to the first virtual organization.
Each membership in a virtual organization has its own lifecycle, defined by the administrator of the respective virtual organization. The lifecycle of membership in a virtual organization can be divided into several phases, reflecting the process of registration, gaining access to services, using them, membership verification, and eventual termination of use. This cycle is described in the following steps:
3.1.1. Registration (Application) to a Virtual Organization
- The user submits an application to a virtual organization by filling out and submitting the registration form (application).
- The application may be automatically approved or require administrator intervention, depending on the settings of the virtual organization.
- Once the application is approved, the user gains active membership in the respective virtual organization.
3.1.2. Active Membership
- During the period of active membership, the user can access the services made available by the respective virtual organization.
- The validity period of active membership is set individually for each virtual organization (e.g. one year, two years from the last use, or manually managed by the administrator).
- Before the active membership expires, the user may receive a notification with a link to the renewal request (depending on the settings of the virtual organization).
3.1.3. Inactive Membership
- Inactive membership may be caused by:
- Expiration of the active membership validity period
- Blocking of membership in the virtual organization for security reasons
- During the period of inactive membership, the user may have limited access to the services made available by the respective virtual organization. However, personal data and settings related to that virtual organization remain preserved.
3.1.4. Termination of Membership
- A user’s membership in a virtual organization is terminated by removing the user account from the virtual organization, which can occur either automatically or through administrator intervention.
- Upon the termination of membership, personal data and settings related to the respective virtual organization are deleted.
3.1.5. Lifecycle in Hierarchical Virtual Organizations
- Virtual organizations can form a hierarchy
- By registering in a member virtual organization (VO), the user automatically becomes a member of the parent virtual organization.
- The user’s membership in the member VO is governed by its own life cycle. The life cycle of members in the parent VO is based on the life cycles of the subordinate member VOs as follows:
- If the user is an active member of at least one of the subordinate member VOs, they are considered an active member of the parent VO.
- If the user does not have an active membership in any of the subordinate member VOs in the hierarchy, their lifecycle in the parent VO will follow the lifecycle of the parent VO itself.
3.1.6. Termination of User Account
If the user is not an active member of any virtual organization, their user account will be deleted after a period of six months.
3.2. Lifecycle of Virtual Organization
3.2.1. Creation of Virtual Organization
A Virtual Organization (VO) is a structure created within the LS AAI that allows the aggregation and management of users, services, and resources for a specific purpose. It primarily serves organizations and communities from the academic, research, or educational environments that need to securely share and utilize data, tools, and computational capacities. The VO facilitates easy coordination of resources, management of user accounts, and setting access permissions, supporting effective collaboration on research initiatives.
- The conditions for creating a VO are outlined in section 6. Creation of Virtual Organization
- A VO is created by the LS AAI operator upon request from the applicant.
- The applicant must specify the duration for the need of the VO, or it will be set for an indefinite period with regular reviews.
- A VO can only be created after fulfilling related obligations, such as adhering to internal rules for the service life cycle, signing a data processing agreement with the LS AAI operator, and so on.
3.2.2. Management of Virtual Organization
- As part of the operation of a Virtual Organization (VO), the administrator manages memberships and settings according to their needs and the capabilities of the system.
- The VO administrator coordinates with the relevant service administrators to make services available to the members of their virtual organization that are part of Life Science.
- The VO administrator can restrict access to a service for specific groups of users defined within the VO. This allows for granular control over who can access certain services, ensuring that only authorized members or groups within the VO have access to particular resources.
3.2.3. Termination of Virtual Organization
- If the VO administrator does not specify a fixed duration for the need of the VO, the necessity of the VO will be reviewed annually. If the administrator does not respond to a request from the LS AAI operator, the VO will be terminated after a period of two months.
- The VO administrator can request the termination of the VO at any time.
- The LS AAI operator will terminate the VO upon the request of the administrator.
- The VO can only be terminated after fulfilling related obligations, such as adhering to internal rules for the service lifecycle, ending the data processing agreement with the LS AAI operator, and other required procedures.
3.3. Lifecycle of Group
3.3.1. Creation of Group
A group is a set of members within the same Virtual Organization (VO) who share access to specific resources and services. Each group belongs to a particular VO. Groups can form a hierarchical structure, where members of all subgroups are automatically members of their parent groups. Additionally, it is possible to establish membership inclusion relations between groups outside of the hierarchy.
The VO administrator is responsible for creating, managing, and deleting groups. They can also designate another user as a delegated group administrator.
- Group creation is the responsibility of the VO administrator.
- Delegated group administrators have the right to create subgroups within the hierarchy.
- The right to create groups directly under a VO can be independently delegated.
- Each group can have a registration form, notifications, and a membership lifecycle, which is subject to the lifecycle rules of both the VO and the VO membership lifecycle.
3.3.2. Management of Group
- The VO administrator manages group membership and settings according to their needs and system capabilities or delegates this responsibility to a delegated group administrator.
- The VO administrator determines the assignment of groups to specific services that the VO has access to.
- The VO administrator is responsible for assessing the necessity of the group.
3.3.3. Termination of Group
- The termination of a group is decided by the VO administrator or, if applicable, the delegated group administrator
- If a VO is terminated, all its groups are also terminated.
3.4. Lifecycle of a Group Membership
3.4.1. Creation of a Group Membership
Membership in a group can be either direct or indirect.
- Direct membership occurs when a VO member is explicitly added to a group.
- Indirect membership arises based on relationships between groups (group hierarchy or set inclusion of groups).
3.4.1.1. Creation of Direct Group Membership
Direct membership in a group can be established through:
- Manual addition by the VO administrator or group administrator
- Self-registration via an application form
- Synchronization from an external system
3.4.1.2. Creation of Indirect Group Membership
- In a tree hierarchy of groups, members of subgroups are indirect members of parent groups.
- In set inclusion, members of the included group are indirect members of the target group.
3.4.2. Active Group Membership
- Direct and indirect membership can exist simultaneously.
- During the period of active direct or indirect membership, a user can access the services available to the respective group.
- The duration of active direct membership can be set indefinitely or have a specified expiration date.
- Before direct membership expires, the user may receive a notification with a link to request an extension.
- Indirect membership remains active as long as the user is an active member of at least one subordinate group in the hierarchy or an included group.
3.4.3. Inactive Group Membership
- During the period of inactive membership, the user may have limited access to the services available to the respective group. Personal data and settings related to the group remain preserved.
- Inactive membership may be caused by:
- Membership expiration in the respective group
- Suspension due to security reasons
3.4.4. Termination of Group Membership
- A user who ceases to be a member of the VO will automatically lose membership in all its groups.
- Direct membership can be manually revoked by the VO administrator or a delegated group administrator.
- Direct membership can also be revoked through synchronization with an external system.
- Indirect membership is revoked if the links between groups are removed or if the user ceases to be a member of all linked groups.
- Both direct and indirect membership are revoked when a group is deleted.
3.5. Lifecycle of Service Account
3.5.1. Creation of Service Account
A service account does not represent a natural person; it is created for machine-to-machine access, such as process automation. Each service account always has a clearly defined owner. While it is created for a specific purpose, this purpose is not recorded in the LS AAI system. The owner bears full responsibility for the proper use and security of the service account.
When creating a service account, the following applies:
- It is created by an administrator of a VO.
- It always has one or more owners.
- It is subject to standard VO and group membership rules (except for expiration policies) and must have all required attributes filled in.
3.5.2. Management of Service Account
The following operations can be performed with the service account:
- Changes to the owners of the service account
- Changes to membership in VO and groups
- Configuration of login and password
The rules for the expiration of the service account membership in VO are as follows:
- The service account membership in VO is valid if at least one of the owners has valid membership in the same VO and the service account is not in Disabled status
- Expiration checks and adjustments are done on a regular basis (daily)
- If all owners’ memberships have expired, the service account will expire immediately
- When an owner is added or removed, the expiration will be recalculated
- When the service account expires, a notification will be sent to the account owners.
3.5.3. Termination of Service Account
- Termination of a service account proceeds in the same way as the termination of a regular user account, see section 3.1.6. Termination of User account
- The termination of the service account membership in VO is governed by the VO’s established rules
- If the service account is not a member of any VO, it will then be deleted from the system.
3.6. Lifecycle of Facility
3.6.1. Creation of Facility
The Facility object within the AAI system represents a device, a group of devices, or a software system (e.g., a computing cluster, data storage, web or mail server) to which access is controlled. A Facility represents a service and is the basic unit of access control; if it is a group of devices, they have a unified configuration.
Access to the Facility is granted to members of virtual organizations through so-called resources (Resources). The Facility administrator is responsible for allocating resources to individual virtual organizations. The VO administrator is responsible for assigning member groups of the VO to these resources.
- Conditions for creating a Facility representing a service are listed in section 5. Conditions for Connecting Services
- Facility can be created in two ways:
- By submitting and approving a request from any user through the registration application (SPadmin). The applicant becomes the Facility administrator.
- By manual creation by the operator of LS AAI. The Facility administrator can designate additional Facility administrators.
3.6.2. Operation of Facility
- Within the operation, the Facility administrator manages the Facility settings according to their needs and the capabilities of the system.
- The Facility administrator coordinates the access for members of virtual organizations with the respective VO administrators.
- The Facility administrator is responsible for creating and deleting resources (Resources) for individual VOs.
- LS AAI provides the service represented by the Facility with user data, as described in the section 2.1. Providing Personal data to Services
3.6.3. Termination of Facility
- The necessity of the Facility is regularly checked every year. If the Facility administrator does not confirm its necessity, the Facility will be canceled after two months from the submission of the confirmation request.
- The Facility administrator can cancel it themselves in the administrative interface of the Perun system or in the SPadmin application.
4 Rights and Obligations
4.1. User
The user is entitled to:
- Manage their user account (change contact details and other settings)
- Use LS AAI to access services
The user is obligated for:
- Secure their user account against misuse, loss, or theft
- Cooperate with the operator of LS AAI
- Keep all their user information up to date
- Not misuse system errors to gain higher privileges, but report them to the operator of LS AAI
- Report the loss or misuse of their access data to the contacts listed on the website https://csirt.muni.cz/en
4.2. Operator of LS AAI
The operator is entitled to:
- Manage and monitor LS AAI
- Suspend user access in case of rule violations or security risks
- Decide on connecting and disconnecting services
- Change the technical parameters of LS AAI
The operator is obligated to:
- Respond quickly and effectively to outages and security incidents, report them to relevant parties, and ensure corrective actions
- Inform users about relevant changes in LS AAI
4.3. Users with higher privileges
A user with higher privileges is a user who has been assigned administrative rights within LS AAI. They must fulfill all user obligations as outlined in section 4.1. and, in addition, use personal data of users only for the purposes for which it was collected.
The following sections specify the rights and responsibilities for special cases of users with higher privileges.
4.3.1. Administrator of Virtual Organization
The VO administrator is authorized to:
- Use the VO in accordance with the purpose for which it was created
- Create service accounts, see section 4.3.3.
The VO administrator is obligated to:
- Comply with the VO management rules in accordance with the Terms of Use and Policy on Processing Personal Data
- Ensure necessary cooperation with the administrators of LS AAI for the smooth functioning of systems and services
- Set up and maintain rules for membership creation and its lifecycle
- Set up and maintain the registration form and notification templates for users
- Include a link to information on personal data processing in the registration form
- Train users to whom they have delegated some of their privileges
- Collect only personal data defined in section 2. Processing of Personal Data or defined in the contract with the operator of LS AAI
- Notify the operator of LS AAI about any changes affecting the VO lifecycle (e.g., transferring the VO to another administrator, discontinuing the VO’s activities)
- Ensure users who are members of the VO are informed of changes in the purpose, scope, and processing of their personal data
- Ensure that at least one VO administrator is an authorized user of LS AAI (according to section 1.5.1. Level of Users of LS AAI of these terms)
4.3.2. Service Administrator
The service administrator is entitled to:
- Deny the user access to the service if the user has violated the service’s terms of operation or poses a security risk.
- Modify the service configuration in LS AAI.
The service administrator is obliged to:
- Train other service administrators to whom they have delegated part of their authority.
- Ensure notification to the operator of LS AAI about the initiation of the service termination process.
- Maintain an up-to-date document with the service’s terms of operation and information on personal data processing and notify users of any changes.
- Keep the service information recorded in LS AAI up to date.
- Report security incidents related to LS users per the published Security Response Procedures
4.3.3. Owner of Service Account
When higher privileges are assigned to a service account, the corresponding rights and responsibilities are transferred to its owners.
The service account is entitled to:
- Add and remove other owners of the service account.
- Manage the service account similarly to a user account, including authentication mechanisms.
The service account owner is obliged to:
- Ensure that the service account always has at least one owner.
- Request the Operator of LS AAI to delete the service account if it is no longer needed.
- Train new service account owners.
- Not misuse the service account for personal access.
5. Conditions for Connecting Services
- The following services can be connected to LS AAI:
- services endorsed by any of the Lifescience RI are automatically approved
- any other services are reviewed and evaluated individually by the LS AAI operator
- A request to connect a service must be submitted by a representative of an organization. For each registered service, an administrator contact is mandatory and it has to be a physical person. Such administrator is the main contact for service setup and AAI notices. Optional contacts in the registration process are the following: technical, support and security.
- An organization eligible to request the connection of a service to LS AAI must appoint a guarantor who confirms the accuracy of the provided data and the legitimacy of each request submitted by the applicant on behalf of their organization. This typically applies when moving a service into the production environment. The guarantor also acts as the administrator for all services connected by their organization.
- For each service, the applicant must provide mandatory details describing the service being connected, particularly information about its operator, the personal data it collects and for what purpose, and other necessary details for the technical integration of the service with LS AAI.
- The LS AAI operator will assess the technical and formal compliance of the service with these conditions and either approve or reject the request.
- Once approved, each service is placed in a testing environment, and the applicant becomes the service administrator. User access to the service in the testing environment is typically restricted, and users are informed of this when accessing the service.
- After successfully testing the service in the testing environment, the administrator can request its transition to the production environment. This transition requires approval from the LS AAI operator.
- The service administrator is responsible for keeping the information provided during service registration up to date.
- The service administrator has the right to add and remove other individuals from the role of service administrator.
- Any changes to the technical or registration details of a connected service require further approval from the LS AAI operator.
- The service administrator may request the deactivation or disconnection of the service from LS AAI. This request is subject to approval by the LS AAI operator.
- The LS AAI operator reserves the right to disconnect or restrict access to a connected service at any time, particularly for the following reasons:
- Termination or violation of the contractual relationship with the LS AAI operator.
- Long-term technical malfunction of the service.
- Inactivity of the service administrator or administrative contact.
6. Creation of Virtual Organization
A virtual organization may be established for:
- an authorized user of LS AAI for the purposes of self-governing management of their team or scientific community, in order to manage access to services connected to the LS AAI;
- an organization that operates services connected to the LS AAI, in order to manage access to its services.
To establish a virtual organization, the following conditions must be met:
- appointment of VO administrators;
- a defined membership lifecycle within the VO and conditions for membership in the VO;
- a defined purpose and the necessary duration of the VO’s existence;
- if the VO is established for an organization, and the organization requires the collection of personal data beyond what is specified in these terms under the section Processing of Personal Data, the organization becomes the controller of such personal data and is required to enter into a written data processing agreement with the operator of LS AAI as the processor;
- if the VO is established for an individual, the collection or use of personal data for purposes beyond those specified in these terms is not permitted.
There is no legal entitlement to the establishment of a VO; its creation is decided by the operator of LS AAI. The decision is made based on the overall strategy and structure of the Life Science Community VO.
7. Final Provisions
These LS AAI Terms and Conditions come into effect on the date of their publication.
The operator of LS AAI reserves the right to modify or supplement these terms at any time. Any changes will be communicated to users through appropriate communication channels.
Documentation for LS AAI is available at https://www.lifescience-ri.eu/life-science-login/ and https://perunaai.atlassian.net/wiki/x/AQAI; users are required to review it before contacting support.
User support is available at support@aai.lifescience-ri.eu, all correspondence is recorded in the Request Tracker system.
Requests are handled on working days from 9:00 AM to 5:00 PM, typically with a response time by the end of the following business day.
These Terms & Conditions shall be governed by the legal order of the Czech Republic. Any dispute arising out of or in connection with these Terms and Conditions shall first be settled amicably through mutual negotiation. If a resolution is not reached within 30 days, the dispute shall be subject to the exclusive jurisdiction of the courts of the Czech Republic.