Trust and Identity Infrastructure Services Above the Network Ann Harding, SWITCH/GÉANT UbuntuNetConnect 2014.

Slides:



Advertisements
Similar presentations
Key Multi-domain GÉANT Network Services June 2011.
Advertisements

Innovation through participation eduGAIN federation operator training eduGAIN interfederation service /18 Valter Nordh, NORDUnet / GU 1.
Federated Identity Management for Researchers – A quick overview from GÉANT BoF TNC May 2014 Dublin.
EduGAIN – Are we there yet? Lukas Hämmerle (ghost writer, Brook Schofield) FIM4R, Helsinki – 2 October 2013.
Europe Latin America Collaborative e ‑ Infrastructure for Research Activities A Model for Federated Services Brook Schofield, TERENA ● Sofia, Bulgaria.
Interfederation subgroup of InCommon Technical Advisory Committee (TAC) spaces.internet2.edu/display/incinterfed.
Teula Morgan The Adaptable Repository: Swinburne Online Journals.
Component 4: Introduction to Information and Computer Science Unit 10: Future of Computing Lecture 2 This material was developed by Oregon Health & Science.
SWITCHaai Team Federated Identity Management.
To identity federation and beyond! Josh Howlett JANET(UK) HEAnet 2008.
Federated Identity Management in New Zealand Sat Mandri Service Manager TNC15 REFEDs Meeting, 14 th June 2015.
EuroPKI 2008 Manuel Sánchez Óscar Cánovas Gabriel López Antonio F. Gómez Skarmeta University of Murcia Levels of Assurance and Reauthentication in Federated.
Eduroam Louis Twomey HEAnet Library Services Day 20 th November 2014.
AARC Overview Licia Florio, David Groep 21 Jan 2015 presented by David Groep, Nikhef.
Copyright JNT Association 2005Copyright JNT Association An Introduction to Access Management and the UK Federation Simon Cooper.
Component 4: Introduction to Information and Computer Science Unit 10b: Future of Computing.
NSLA Members ACT Library and Information Service National Library of Australia National Library of New Zealand Northern Territory Library State Library.
Federated Identity Management for HEP David Kelsey WLCG GDB 9 May 2012.
Updates Licia Florio, TERENA REFEDS Meeting 5 Sept 2012.
Belnet Federation Belnet – Loriau Nicolas Brussels – 12 th of June 2014.
School 2.0 ORT Argentina High School’s Pedagogical Model Our students were born into an age of dramatical change in communication, entertainment and learning.
EResearchers Requirements the IGTF model of interoperable global trust and with a view towards FIM4R AAI Workshop Presenter: David Groep, Nikhef.
INTRODUCTION: THE FIRST TRY InCommon eduGAIN Policy and Community Working Group.
Test your IdP
Connect. Communicate. Collaborate The MetaData Service Distributing trust in AAI confederations Manuela Stanica, DFN.
Federation as a Service Marina Vermezović, AMRES Federated Identity Technology Workshop Sofia, Bulgaria, 20. Jun 2014.
Authentication and Authorisation for Research and Collaboration Licia Florio AARC Workshop The AARC Project Brussels, 26 October.
University of Washington Identity and Access Management IEEAF – RENU Network Design Workshop Seattle - 29 Nov 2007 Lori Stevens, Director, Distributed.
Jini Architectural Overview Li Ping
Connect. Communicate. Collaborate Universität Stuttgart A Client Middleware for Token- Based Unified Single Sign On to eduGAIN Sascha Neinert, University.
Diego R. Lopez, RedIRIS JRES2005, Marseille On eduGAIN and the Coming GÉANT Middleware Infrastructure.
Federated Identity Management for HEP David Kelsey HEPiX, IHEP Beijing 18 Oct 2012.
Connect. Communicate. Collaborate Deploying Authorization Mechanisms for Federated Services in the eduroam architecture (DAMe)* Antonio F. Gómez-Skarmeta.
University of Washington Collaboration: Identity and Access Management Lori Stevens University of Washington October 2007.
Federations: The New Infrastructure Speaker Name Here Date Here Speaker Name Here Date Here.
Evolving Security in WLCG Ian Collier, STFC Rutherford Appleton Laboratory Group info (if required) 1 st February 2016, WLCG Workshop Lisbon.
Growth. Interfederation PKI is globally scalable Unfortunately, its not locally deployable… Federation is locally deployable Can it.
INTRODUCTION: THE FIRST TRY InCommon eduGAIN Policy and Community Working Group.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
NREN Trust and Identity Strategy Ann Harding, SWITCH Cambridge July 2014.
AAI/Federated Identity Training Ann Harding, SWITCH Cambridge July 2014.
Networks ∙ Services ∙ People Thomas Bärecke Journée Fédération, Paris Collaboration européenne GÉANT SA5 03/07/2015 SA5 T5 team
Connect communicate collaborate Trust & Identity EC meets GÉANT 19 June 2014 Brussels Valter Nordh, NORDUnet Federation as a Service Task Leader Trust.
b2access.eudat.eu B2ACCESS The simple and secure authorisation and authentication platform of EUDAT This work is licensed under the Creative.
Connect communicate collaborate Internet2 Global Summit 27 April 2015 Washington DCs User Community Driven Development in Trust and Identity Services Ann.
Networks ∙ Services ∙ People Marina Adomeit FIM4R meeting Virtual Organisation Platform as a Service VOPaaS Nov 30, 2015, Austria Task Leader,
1 Identities and Federation: The Next IT Wave (The Canadian Access Federation) Rick Bunt President The Canadian University Council of CIOs (CUCCIO)
Federated Identity Fundamentals Ann Harding, SWITCH Cambridge July 2014.
Connect communicate collaborate GÉANT Making the Difference Dai Davies, DANTE 8 th eConcertation Meeting CERN, Geneva 4-5 November 2010.
Networks ∙ Services ∙ People Ann Harding GÉANT Symposium, Vienna Users Session A3 Trust and Identity March GÉANT Activity Leader Trust.
INTRODUCTION TO IDENTITY FEDERATIONS Heather Flanagan, NSRC.
RoEduNet 11th International Conference, Sinaia, Romania, January Implementation of national IdP Management Systems for Access.
Networks ∙ Services ∙ People Licia Florio TNC, Lisbon Consuming identities across e- Infrastructures 16 June 2015 PDO GÈANT.
Authentication and Authorisation for Research and Collaboration Licia Florio AARC CORBEL Workshop The AARC Project Paris, 31 May.
Designing Identity Federation Policy, the right way Marina Vermezović, Academic Network of Serbia TNC2013 conference 4 May 2013.
1 Enabling Smart Cities/Campuses to Serve the Internet of People Florence Hudson Senior Vice President & Chief Innovation Officer Internet2 TNC16 June.
THE VALUE PROPOSITION FOR IDENTITY FEDERATIONS APAN 41 – TF-IAM 27 January 2016.
Networks ∙ Services ∙ People Marina Adomeit TNC16 Conference, Prague Towards a platform for supporting collaboration GÉANT VOPaaS
Networks ∙ Services ∙ People TNC 2016, Prague Alice Through the Looking Glass Science DMZ goes above the network 13 June
Networks ∙ Services ∙ People Ann Harding Networkshop 44, Manchester Thinking globally, acting locally Trust and Identity in the GÉANT project.
THE CAMPUS IDENTITY SYSTEM Lucy Lynch, NSRC. Learning Objectives Discovering the key role campus networks play in trusted identities for R&E Authoritative.
Networks ∙ Services ∙ People Di4R Network. Services. People. GÉANT 28 th September, Krakow.
WACREN EduID Fostering Identity Federations in West and Central Africa 3rd Sci-GaIA Workshop Dar es Salaam, Tanzania – 5 th September Omo Oaiya.
“Connectivity Around the World”
Cross-sector and user-centric AAI
eduTEAMS platform for collaboration Niels Van Dijk
Innovative Solutions from Internet2
InCommon Steward Program: Community Review
ELIXIR Safeguarding the results of life science research in Europe
Federations: Introduction Justin Knight, Jisc
Presentation transcript:

Trust and Identity Infrastructure Services Above the Network Ann Harding, SWITCH/GÉANT UbuntuNetConnect 2014

2 Connect | Communicate | Collaborate e-Research in the 21 st Century Source: Professor David De Roure, Professor of e-Research at University of Oxford

3 Connect | Communicate | Collaborate e-Research in the 21 st Century CC BY-NC-ND 4.0, Distributed Data Distributed Users Distributed Data Distributed Users

4 Connect | Communicate | Collaborate Are we ready?

5 Connect | Communicate | Collaborate The Flow of Trust User Service Service Provider Home Organisation Federation

6 Connect | Communicate | Collaborate eduroam Open your laptop and be online

7 Connect | Communicate | Collaborate eduroam Operating safe wireless access, scalably

8 Connect | Communicate | Collaborate eduroam Open your laptop and be online …anywhere? oam+along+with+commercial+hotspot+system

9 Connect | Communicate | Collaborate eduroam Open your laptop and be online …anywhere! H2eduroam/How+to+deploy +and+promote+eduroam+for +events

10 Connect | Communicate | Collaborate Building out eduroam – the basics In ternational International strategy & business case Offer Top Level Roaming Service (not essential) 1-2 VMs, open source radius Supporting services – e.g. cat.eduroam.org In ternational International strategy & business case Offer Top Level Roaming Service (not essential) 1-2 VMs, open source radius Supporting services – e.g. cat.eduroam.org National National strategy & business case National roaming infrastructure 1-2 VMs, free software Support and training Cookbooks available duroam/How+to+deploy+eduroa m+at+national+level National National strategy & business case National roaming infrastructure 1-2 VMs, free software Support and training Cookbooks available duroam/How+to+deploy+eduroa m+at+national+level Campus WIFI deployments Service Provider deployment User management Identity Provider deployment Cookbooks available duroam/How+to+deploy+eduroa m+on-site+or+on+campus Campus WIFI deployments Service Provider deployment User management Identity Provider deployment Cookbooks available duroam/How+to+deploy+eduroa m+on-site+or+on+campus People and Skills

11 Connect | Communicate | Collaborate eduGAIN Trust Across Borders eduGAIN Members Joining eduGAIN Other federations

12 Connect | Communicate | Collaborate eduGAIN – a global interfederation service MDS fetches, aggregates and republishes metadata eduGAIN provides policy framework to build trust MDS fetches, aggregates and republishes metadata eduGAIN provides policy framework to build trust

13 Connect | Communicate | Collaborate How do federations build trust? Register Member Sign Policy Register ‘Entities’ Verify Data Publish ‘Entities’ Sign Metadata PROCESS TRUST THAT’S IT.

14 Connect | Communicate | Collaborate Federated Identity Benefits The world of eduGAIN Reduces Work Provides Current Data Insulation from service atromises Minimize attack surface area Minimize attack surface area User Friendly Simplifies Adding Services

15 Connect | Communicate | Collaborate Federations The Power of Collective Trust Infrastructure to support collective service delivery E-Learning platforms Journals Cloud providers Infrastructure to maintain the privacy and integrity of users and citizens Users are not the product Infrastructure to reach out globally Bring users to global services Bring services to global users Infrastructure to support collective service delivery E-Learning platforms Journals Cloud providers Infrastructure to maintain the privacy and integrity of users and citizens Users are not the product Infrastructure to reach out globally Bring users to global services Bring services to global users Federation development eduGAIN & GÉANT Federation development eduGAIN & GÉANT

16 Connect | Communicate | Collaborate Building out eduGAIN/Identity Federation – the basics National/International Develop & operate a federation policy 2/slides/Identity%20Federation%20Policy%20Te mplate%20v0.4.pdf Operate infrastructure 1-2 VMs, free software GÉANT FaaS model Support and training Campus & Service providers Join eduGAIN klist.php National/International Develop & operate a federation policy 2/slides/Identity%20Federation%20Policy%20Te mplate%20v0.4.pdf Operate infrastructure 1-2 VMs, free software GÉANT FaaS model Support and training Campus & Service providers Join eduGAIN klist.php Campus User management Identity Provider deployment Free software, shibboleth, simpleSAMLphp Support/require enabling services Library Services Campus services Health Journal providers Campus User management Identity Provider deployment Free software, shibboleth, simpleSAMLphp Support/require enabling services Library Services Campus services Health Journal providers Strategy, People and Skills

17 Connect | Communicate | Collaborate Trust and Identity Voice of one and the voice of many I am because we are....Ubuntu is not just a philosophy – it is a way of life that defines the relationship of the individual to the community and vice versa … - F F Tusubira I am because we are....Ubuntu is not just a philosophy – it is a way of life that defines the relationship of the individual to the community and vice versa … - F F Tusubira