Secure Data Enclave
What is a SDE?
The Research Computing Center (RCC) provides certified, trusted research environments within the Secure Data Enclave (SDE) for storing, processing, analyzing, and transmitting restricted research data, reducing the burden of meeting security, privacy, and compliance requirements and streamlining research projects involving such data. RCC manages the environments and configures the required security and privacy controls, while researchers manage their datasets and meet applicable deadlines and compliance obligations, with RCC assistance available upon request.
Two systems, SDE2 and SDE3, are available within SDE. They are Linux-based high-performance computing systems operating independently of RCC’s Midway ecosystem and are specifically configured with enhanced security and privacy controls. Access is granted by project and requires authorization from the data steward (typically PI), whose responsibilities are defined in the Research Data Protection Policy.
Is SDE a Good Fit to My Research Project?
UChicago Principal Investigators are eligible to claim project workspaces on the appropriate SDE systems upon execution of Data Use Agreement (DUA), Institutional Review Board (IRB) approval, or execution of Procurement Contract (PC).
UChicago’s Secure Research Data Strategy (SRDS) classifies restricted research data into three impact levels, depending on the liability terms and compliance requirements: high, moderate, and low. SDE3 system is designed to host high-impact restricted data, while SDE2 system supports restricted data up to the moderate-impact level.
What Resources Are Available in SDE?
Each PI is granted 500GB of high-performance storage per system for all their projects. The shared research software is maintained and configured by RCC experts to facilitate distributed simulations and optimize high-intense computing tasks. Additional storage and private compute nodes can be provisioned through the Cluster Partnership Program (CPP). RCC staff can assist PIs with various tasks throughout the data management cycle, including assisting with restricted data applications, transferring restricted data, configuring software, migrating research workflows, securely deleting data, and other related activities. A pull of computational experts is also available through the Consultant Partnership Program to contribute to research projects.
How to Plan My Research in SDE?
Researchers propose a trusted research environment where the data will be stored, processed, and analyzed when applying for restricted research data, when drafting protocols for collecting such data, or when migrating acquired restricted data to a new environment. Given that data security and privacy obligations vary across different agreements, protocols, and contracts, an ancillary review of data-specific obligations is conducted by the University Research Administration (URA) and/or IRB to classify the data according to impact level. The security team reviews data security and privacy obligations and either approves the data for hosting in the SDE or recommends an alternative environment that meets the applicable compliance requirements.
How to Request an Account in SDE?
PI requests a project workspace in the SDE2 or SDE3 system. Once the request is processed, a researcher applies for a general user account on a given system to join the project. After the PI verifies the researcher’s eligibility and approves the request, RCC staff create the user account and grant access to the authorized workspace.
SDE2 and SDE3 operate independently of RCC’s general-purpose Midway HPC systems; therefore, a Midway account cannot be used to access the SDE systems. For authorized collaborators who are not affiliated with UChicago, assistance will be provided to create CNetIDs once they have signed a Data Collaborator Agreement (DCA).
How to Transfer Restricted Research Data to SDE?
The data transfer may be subject to restrictions outlined in the DUAs, IRBs, and/or PCs. Additionally, the transfer method may depend on the size of your data. Please reach out to midwayr-help@rcc.uchicago.edu to consult with the RCC team.
Can One Host a Shared Data Set in SDE?
Yes, when the restricted research data is expected to be used by multiple research groups, the data can be hosted in read-only mode and shared with authorized SDE users.
Can One Reduce Data Sensitivity within SDE and Continue Research in a Different Environment?
Yes, in some cases, it is possible to de-identify data, such as personally identifiable information (PII), to reduce the impact level and continue research on de-identified data in a less stringent research environment, provided that data security obligations do not restrict such migration. Please reach out to midwayr-help@rcc.uchicago.edu to learn more about available options.