AAI needs of the Distributed Computing Infrastructures - CLARIN Dieter Van Uytvanck Max Planck Institute for Psycholinguistics

Slides:



Advertisements
Similar presentations
Lousy Introduction into SWITCHaai
Advertisements

Building metadata components Dieter Van Uytvanck Max Planck Institute for Psycholinguistics CLARIN-NL Info Session Nijmegen
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
CLARIN AAI, Web Services Security Requirements
Interoperability aspects in the The Virtual Language Observatory Dieter Van Uytvanck Max Planck Institute for Psycholinguistics
User Attributes; who, where, how many? Daan Broeder TLA – MPI for Psycholinguistics.
Contrail and Federated Identity Management
Advanced Metadata Usage Daan Broeder TLA - MPI for Psycholinguistics / CLARIN Metadata in Context, APA/CLARIN Workshop, September 2010 Nijmegen.
CLARIN and the DSA Paul Trilsbeek The Language Archive Max Planck Institute for Psycholinguistics.
Steven KrauwerLREC20081 CLARIN: Common Language Resources and Technology Infrastructure for the Humanities and Social Sciences Kimmo Koskenniemi (University.
1 Issues in federated identity management Sandy Shaw EDINA IASSIST May 2005, Edinburgh.
EMI INFSO-RI Session Summary AAI Needs for DCIs John White, HIP Christoph Witzig, SWITCH
Copyright JNT Association 20051OptionalCopyright JNT Association 2007 Overview of the UK Access Management Federation Josh Howlett.
SAML-based Delegation in Shibboleth Scott Cantor Internet2/The Ohio State University.
FIM-ig Federated Identity Management Interest Group.
SWITCHaai Team Federated Identity Management.
EduGAIN Code of Conduct Workshop, , Brussels GEANT eduGAIN Data Protection "Code of Conduct" Workshop Dieter Van Uytvanck
CLARIN Common Language Resources and Technology Infrastructure Daan Broeder & Dieter van Uytvanck Max-Planck Institute for Psycholinguistics TF-EMC2 Meeting,
CLARIN-NL Second Open Call Jan Odijk CLARIN-NL Call 2 Info-session Amsterdam, 26 Aug 2010.
Authentication and Authorization in a federated environment Jules Wolfrat (SARA)
CLARIN and the Humanities Daan Broeder The Language Archive – MPI for Psycholinguistics CLARIN EU/NL Workshop on Federated Identity Management CERN, June.
The role of Parthenos for CLARIN ERIC Steven Krauwer CLARIN ERIC Executive Director 1.
The Language Archive – Max Planck Institute for Psycholinguistics Nijmegen, The Netherlands Why should we invest in DWF? Peter Wittenburg CLARIN Research.
Federated Identity Management for HEP David Kelsey WLCG GDB 9 May 2012.
CLARIN Infrastructure Vision (and some real needs) Daan Broeder CLARIN EU/NL Max-Planck Institute for Psycholinguistics.
CLARIN Metadata Infrastructure Component Metadata and intermediate solutions Daan Broeder Claus Zinn Dieter van Uytvanck - Max-Planck Institute for Psycholinguistics.
AAI-enabled VO Platform “VO without Tears” Christoph Witzig EGI TF, Amsterdam, Sept 15, 2010.
EMI AAI Strategy & Plans John White / Helsinki Institute of Physics Federated Identity Systems for Scientific Collaborations Workshop , CERN,
FIM, , Nijmegen CLARIN: status of FIM Dieter Van Uytvanck 1.
Authentication and Authorization Overview Kimmo Koskenniemi, Antti Arppe, Mikael Lindén University of Helsinki, CSC – IT Centre for Science Consortium.
Authentication and Authorisation for Research and Collaboration Licia Florio (GÉANT) Christos Kanellopoulos (GRNET) Service orientation.
10/25/2015 AEB/Yleisesittely Organising Federated Identity in Finnish Higher Education TNC2005 Mikael Linden June 8th, 2005.
CLARIN work packages. Conference Place yyyy-mm-dd
Shibboleth Akylbek Zhumabayev September Agenda Introduction Related Standards: SAML, WS-Trust, WS-Federation Overview: Shibboleth, GSI, GridShib.
AAI WG EMI Christoph Witzig on behalf of EMI AAI WG.
CLARIN Issues Peter Wittenburg MPI for Psycholinguistics Nijmegen, NL.
A Data Category Registry- and Component- based Metadata Framework Daan Broeder et al. Max-Planck Institute for Psycholinguistics LREC 2010.
Recent Developments in CLARIN-NL Jan Odijk P11 LREC, Istanbul, May 23,
Community Sign-On and BEN. Table of Contents  What is community sign-on?  Benefits  How it works (Shibboleth)  Shibboleth components  CSO workflow.
Authentication and Authorisation for Research and Collaboration Licia Florio REFEDS Meeting The AARC Project I2 Technology Exchange.
Authentication and Authorisation for Research and Collaboration Licia Florio AARC Workshop The AARC Project Brussels, 26 October.
Authorization and Authentication Infrastructure Daan Broeder & Dieter Van Uytvanck Max Planck Institute for Psycholinguistics
JRA1.4 Models for implementing Attribute Providers and Token Translation Services Andrea Biancini.
Clain update TF-EMC Mikael Linden, CSC.
Connect. Communicate. Collaborate Deploying Authorization Mechanisms for Federated Services in the eduroam architecture (DAMe)* Antonio F. Gómez-Skarmeta.
EMI is partially funded by the European Commission under Grant Agreement RI Federated Grid Access Using EMI STS Henri Mikkonen Helsinki Institute.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
Networks ∙ Services ∙ People Thomas Bärecke Journée Fédération, Paris Collaboration européenne GÉANT SA5 03/07/2015 SA5 T5 team
A Data Category Registry- and Component- based Metadata Framework Daan Broeder et al. Max-Planck Institute for Psycholinguistics LREC 2010.
b2access.eudat.eu B2ACCESS The simple and secure authorisation and authentication platform of EUDAT This work is licensed under the Creative.
Networks ∙ Services ∙ People Marina Adomeit FIM4R meeting Virtual Organisation Platform as a Service VOPaaS Nov 30, 2015, Austria Task Leader,
Tutorial on Science Gateways, Roma, Riccardo Rotondo Introduction on Science Gateway Understanding access and functionalities.
European Grid Initiative AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
EMI is partially funded by the European Commission under Grant Agreement RI Security Token Service (STS) Simplified Credential Management Henri.
CLARIN EUDAT2020 uptake plan Dieter Van Uytvanck CLARIN ERIC EUDAT User Forum, Rome.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Enabling SSO capabilities in the EGI Cloud services Peter Solagna – EGI.eu.
Networks ∙ Services ∙ People Marina Adomeit TNC16 Conference, Prague Towards a platform for supporting collaboration GÉANT VOPaaS
Authentication and Authorisation for Research and Collaboration Peter Solagna, Nicolas EGI AAI integration experiences AARC Project.
Authentication and Authorisation for Research and Collaboration AARC/CORBEL Workshop for Life Sciences AAI AARC Draft Blueprint.
DARIAH EU AAI consideration K. Skala, D. Davidović, Z. Šojat Lisbon, 22 May 2015.
Authentication and Authorisation for Research and Collaboration Taipei - Taiwan Mechanisms of Interfederation 13th March 2016 Alessandra.
Innovation through participation Data Protection Code of Conduct (DP CoC) TNC2013 conference, 4 June 2013 Mikael Linden, CSC – IT Center for Science
Accessing the VI-SEEM infrastructure
AAI for a Collaborative Data Infrastructure
eduTEAMS platform for collaboration Niels Van Dijk
Identity Federations - Overview
CLARIN Federated Identity Vision
Krister Lindén and Ville Oksanen FINCLARIN / University of Helsinki
AAI Architectures – current and future
Check-in Identity and Access Management solution that makes it easy to secure access to services and resources.
Presentation transcript:

AAI needs of the Distributed Computing Infrastructures - CLARIN Dieter Van Uytvanck Max Planck Institute for Psycholinguistics EGI Technical Forum 2010 Amsterdam

2 Overview  Introduction: what is CLARIN?  Long-term AAI objectives:  Cross-border federation  License consent service  Relayed trust for web services  Issues

3 What is CLARIN?  “Common Language Resources and Technology Infrastructure”  The CLARIN (FP7) project:  a distributed pan-European research infrastructure  aim: providing language resources and technology in a user- friendly way  target group: Humanities and Social Sciences researchers  Resources: Lexica, text corpora, multi-media/multi-modal recordings, …  Software: parsers, speech/video recognizers, editors, …

4  an EU Infrastructure project  with 4.2 mio euro funding for a  3 year preparatory phase (2008 – 2011)  Additional funding from national governments, currently at least 16 ME  The CLARIN consortium has now 32 partners from 26 EU countries and 178 member organisations  CLARIN EU continuation after the preparatory phase as an ERIC  This is important if only to provide a legal entity that is able to establish contracts with outside parties on behalf of the CLARIN community. CLARIN Organization

5 CLARIN and the Holy Grail (1)  A researcher authenticates at his own organization and creates a virtual collection of resources from different repositories.

6 CLARIN and the Holy Grail (2)  On the basis of:  browsing a catalogue  searching through  metadata  resource content  Afterwards:  use a workflow specification tool and  process this virtual collection using web services  (Intermediate) results and provenance data are stored in a user specific workspace that can also keep a user profile  After evaluation resulting data (including metadata) can be added to a repository and the “virtual” collection specification can be stored for future reference

7 Infrastructure components  CLARIN centers with reliable repository systems  Stable pillars of the infrastructure  Main function is taking care of data preservation and access with depositor/owner specified restrictions  Persistent identification of resources  Metadata catalog: harvesting, browsing and searching  Registries for centers and services  E.g. which centers offer metadata, where can I store my virtual collection?  Specification tool for workflow chains of web services  EU-wide federated authentication

8 Long term AAI objectives (1)  Rely on user’s home organization membership of national IDFs for establishing trust relations with the SPs  A CLARIN SP organization as a legal entity able to sign contracts with the national Identity Federations SP2 SP3 SP1 IDF a IDF b homeless users? IDF c

9 Service Provider Federation  Some numbers:  270k (FI) + 511k (NL) + ? (DE) (DK)  = more than 4 million potential users MPI BBAW IDS INL CSC SURFfederatie (~ 50 IdPs) HAKA (~ 40 IdPs) DFN-AAI (~ 60 IdPs) CLARIN SP federation prototype

10 Long term AAI objectives (2)  The CLARIN SPs become members of their national IDFs  Rely on the eduGAIN confederation to provide the trust between the national IdFs SP2 SP3 SP1 IDF a IDF b homeless users? IDF c

11 License Acceptance (1) IdP SPa SPb user SP requires license to be signed and takes care of this but only for its own domain This can break the SSO if the user is required to sign the same license several times browser license DB CLARIN will harmonize the licenses to a limited number

12 License Acceptance (2) IdP SPa SPb user browser Store the license info in the user attributes at the IdP But how does it get there? Special application? Not every IdP will/can run this license DB

13 License Acceptance (3) IdP SPa SPb user browser VO Platform license DB Create special license service. This is part of the CLARIN SPF CLARIN independent of the IDFs External User Attribute Authority

14 WS Security / delegation tokenizer parser semantic tagger WF engine authentication dataflow parserA parserB delegation Composite Web service }

15 Web Services – solutions?  “always trust the web service” rule. Any registered web service should be trusted if it claims to act on behalf of a specific user.  web services identify each other by means of server certificates, user identity itself is not proven  solution for a relatively limited number of web services, not a scalable solution.  Embody the identity (and thus the authority) of the user in a user certificate (upload, SLCS, …)  certificate is then propagated from web service to web service.  Use SAML assertions especially the Relayed-Trust SAML assertion.  the workflow engine will use the original authentication assertion it obtained from and build a RT SAML assertion that is specific for itself and the web service it needs to access

16 Issues encountered  AAI should make access to Services easier, but  Multi-level WAYF screens (confusing for users!)  Attribute release consent dialog (confusing for users!)  Opt-in policy to give IdPs access to SP (SurfFederatie eg.)  Sometimes even an additional contract to be signed per SP Service Provider

17 Further information 

Thank you for your attention CLARIN has received funding from the European Community's Seventh Framework Programme under grant agreement n°