This session provides implementation-driven updates from the GIF TRE Open Suite on emerging trust architectures for federated research environments. It focuses on authentication, authorisation, identity, and workload trust across control-plane and data-plane interactions, in close alignment with the GA4GH Cloud and Data Security Work Streams.
We examine how Trusted Execution Environments (TEEs) and the IETF-defined Attested TLS protocol can integrate with existing GA4GH standards to enable fine-grained, secure flows in Trusted Research Environments (TREs). The discussion clarifies architectural boundaries between transport-level security guarantees, middleware signalling, and application-level trust and policy enforcement.
Grounded in open source reference implementations, the session highlights where current standards scale well and where practical gaps remain, particularly around workload identity, integrity, and reproducibility. Alternative trust models, including blockchain-based approaches, are briefly discussed as complementary mechanisms for auditability and accountability.