Networks ∙ Services ∙ People www.geant.org Licia Florio TNC, Lisbon Consuming identities across e- Infrastructures 16 June 2015 PDO GÈANT.

Slides:



Advertisements
Similar presentations
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
Advertisements

Federated Identity Management for Researchers – A quick overview from GÉANT BoF TNC May 2014 Dublin.
EduGAIN – Are we there yet? Lukas Hämmerle (ghost writer, Brook Schofield) FIM4R, Helsinki – 2 October 2013.
Federated Identity Management for Research Communities (FIM4R) David Kelsey (STFC-RAL) EGI TF, AAI workshop 19 Sep 2012.
2006 © SWITCH Authentication and Authorization Infrastructures in e-Science (and the role of NRENs) Christoph Witzig SWITCH e-IRG, Helsinki, Oct 4, 2006.
Federated Identity Management for the context of storage Bart Kerver - TERENA Storage-meeting, Amsterdam,
1 eAuthentication in Higher Education Tim Bornholtz Session #47.
Agenda Project beginnings and funding. Purpose of the federation. Federation members. Federation protocols. Special features in our federation. Pilot.
Use case: Federated Identity for Education (Feide) Identity collaboration and federation in Norwegian education Internet2 International Workshop, Chicago,
To identity federation and beyond! Josh Howlett JANET(UK) HEAnet 2008.
BoF: Federated Identity Management for Researchers David Kelsey (STFC-RAL) TNC2014, Dublin 20 May 2014.
Innovation through participation Interfederation through eduGAIN - steps and challenges eduGAIN interfederation service Federated Identity Systems.
AARC Overview Licia Florio, David Groep 21 Jan 2015 presented by David Groep, Nikhef.
Federated Identity Management for HEP David Kelsey WLCG GDB 9 May 2012.
Updates Licia Florio, TERENA REFEDS Meeting 5 Sept 2012.
Connect communicate collaborate GÉANT3plus Enabling Users Pilots Lukas Hämmerle Task Leader "Enabling Users"
John Dyer Business & Technology Strategist TERENA Business & Technology Strategist 4 October 2013 European NRENs Evolution.
Authentication and Authorisation for Research and Collaboration Licia Florio (GÉANT) Christos Kanellopoulos (GRNET) Service orientation.
European Life Sciences Infrastructure for Biological Information Life science community update for the 7 th Federated Identity Management.
MAT U M A T U Middleware Assisted Take-Up Service For JISC Funded Early Adopters.
Authentication and Authorisation for Research and Collaboration Pilots on the Integrated R&E AAI Paul van Dijk, Activity Lead Pilots.
7 th FIM 4 R meeting April 2014 ESRIN Frascati.
EResearchers Requirements the IGTF model of interoperable global trust and with a view towards FIM4R AAI Workshop Presenter: David Groep, Nikhef.
INTRODUCTION: THE FIRST TRY InCommon eduGAIN Policy and Community Working Group.
Community Sign-On and BEN. Table of Contents  What is community sign-on?  Benefits  How it works (Shibboleth)  Shibboleth components  CSO workflow.
Test your IdP
Authentication and Authorisation for Research and Collaboration Licia Florio REFEDS Meeting The AARC Project I2 Technology Exchange.
Authentication and Authorisation for Research and Collaboration Licia Florio AARC Workshop The AARC Project Brussels, 26 October.
Authentication and Authorisation for Research and Collaboration Peter Solagna Milano, AARC General meeting Current status and plans.
Federated Identity Management for HEP David Kelsey HEPiX, IHEP Beijing 18 Oct 2012.
Connect. Communicate. Collaborate Deploying Authorization Mechanisms for Federated Services in the eduroam architecture (DAMe)* Antonio F. Gómez-Skarmeta.
Authentication and Authorisation for Research and Collaboration Christos Kanellopoulos Open Day Event: Towards the European Open.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
NREN Trust and Identity Strategy Ann Harding, SWITCH Cambridge July 2014.
Networks ∙ Services ∙ People Thomas Bärecke Journée Fédération, Paris Collaboration européenne GÉANT SA5 03/07/2015 SA5 T5 team
Connect communicate collaborate Trust & Identity EC meets GÉANT 19 June 2014 Brussels Valter Nordh, NORDUnet Federation as a Service Task Leader Trust.
Connect communicate collaborate Internet2 Global Summit 27 April 2015 Washington DCs User Community Driven Development in Trust and Identity Services Ann.
Networks ∙ Services ∙ People Nicole Harris UK federation meeting eduGAIN, REFEDS and the UK 23 June 2015 Project Development Officer GÉANT.
Networks ∙ Services ∙ People Marina Adomeit FIM4R meeting Virtual Organisation Platform as a Service VOPaaS Nov 30, 2015, Austria Task Leader,
Federated Identity Fundamentals Ann Harding, SWITCH Cambridge July 2014.
Networks ∙ Services ∙ People Ann Harding GÉANT Symposium, Vienna Users Session A3 Trust and Identity March GÉANT Activity Leader Trust.
Authentication and Authorisation for Research and Collaboration Taipei Taiwan Authentication and Authorisation for Research and.
Authentication and Authorisation for Research and Collaboration Licia Florio REFEDS Meeting AARC and AARC2 Vienna, 1 st December.
David Groep Nikhef Amsterdam PDP programme Authentication and Authorization for Research and Collaboration David Groep, Nikhef with materials gratefully.
David Groep Nikhef Amsterdam PDP & Grid AARC Authentication and Authorisation for Research and Collaboration an impression of the road ahead.
Federated Identity Management for Research Communities: FIM4R PSI workshop objectives Bob Jones, CERN.
Authentication and Authorisation for Research and Collaboration Licia Florio AARC CORBEL Workshop The AARC Project Paris, 31 May.
Authentication and Authorisation for Research and Collaboration Christos Kanellopoulos David Groep 9 th FIM4R Meeting The AARC Project.
Networks ∙ Services ∙ People Marina Adomeit TNC16 Conference, Prague Towards a platform for supporting collaboration GÉANT VOPaaS
Authentication and Authorisation for Research and Collaboration Peter Solagna, Nicolas EGI AAI integration experiences AARC Project.
Authentication and Authorisation for Research and Collaboration AARC/CORBEL Workshop for Life Sciences AAI AARC Draft Blueprint.
Authentication and Authorisation for Research and Collaboration Taipei - Taiwan Mechanisms of Interfederation 13th March 2016 Alessandra.
Networks ∙ Services ∙ People Mandeep Saini AARC/CORBEL Workshop Collaborative Organisation Platform as a Service June 1, 2016, Paris Product.
Authentication and Authorisation for Research and Collaboration Licia Florio IGTF Meeting The AARC Project Amsterdam, 8 September.
Introduction to AAI Services
Boosting AAI for research and collaboration
Cross-sector and user-centric AAI
Authentication and Authorisation for Research and Collaboration
AARC Update What’s been happening in AARC which matters for GÉANT
User Community Driven Development in Trust and Identity
eduTEAMS platform for collaboration Niels Van Dijk
Federated Identity Management for Researchers (FIM4R)
An AAI solution for collaborations at scale
Boosting AAI for research and collaboration
ELIXIR Safeguarding the results of life science research in Europe
The AARC Project Licia Florio (GÉANT) Christos Kanellopoulos (GRNET)
The AARC Project Licia Florio AARC Coordinator GÉANT
AAI For Researchers Licia Florio AARC Project Coordinator GÉANT DI4R
AARC Blueprint Architecture and Pilots
AAI Architectures – current and future
Presentation transcript:

Networks ∙ Services ∙ People Licia Florio TNC, Lisbon Consuming identities across e- Infrastructures 16 June 2015 PDO GÈANT

Networks ∙ Services ∙ People When and how it all started Where we are now Where we want/should be 2 Overview

Networks ∙ Services ∙ People years of 1 st March 2005: SAML2.0 was approved Now used by 50 R&E federations! REFEDS – 10 years of discussion on how federations can interoperate. And of course federated access

Networks ∙ Services ∙ People 4 A look at the past

Networks ∙ Services ∙ People Our community realised very soon that username and password would not scale in a world: Where on-line access was becoming more and more common Where students mobility was growing and it was expected to grow more Where remote access to resources was becoming a main requirement 5 Importance of Federated Access

Networks ∙ Services ∙ People 6 From the Internet Archives Tuesday 29 Oct 2002 I2 News Item: “After two months of using Shibboleth to manage web course material at North Carolina State University, we saw an 80- to 85-percent drop in our help desk call” Dec Oct 2002 SWITCH AAI Info Day: “Demo on Shibboleth demo (v 0.7!) And an overview on other AAIs in Europe ”

Networks ∙ Services ∙ People 7 How it all started A-Select PAPI FEIDE Shibboleth Athens PermisSPOCP

Networks ∙ Services ∙ People 8 The good year! Source: Ton Verschuuren 14_Confederation_-_JISC_Workshop.pdf SAML becomes the de-facto lingua franca with multiple implementations (i.e. simpleSAMLphp and commercial products)

Networks ∙ Services ∙ People 9 Federations in 2005 Source: TERENA CompendiumTERENA Compendium 6 Federations Many NRENs planning

Networks ∙ Services ∙ People 10 Challenges back then Scalability Inter-federation Business Models Schema harmonization Support for VOs Authorization

Networks ∙ Services ∙ People 11 Please meet eduGAIN grandpa

Networks ∙ Services ∙ People 12 Federations in the past 5 years

Networks ∙ Services ∙ People April 2011: Official start of eduGAIN Nov 2013: 21 Federations are members (50%), 5 joining Apr 2014: 24 Federations are members (51%), 6 joining April 2015: 32 Federations are members (57%), 9 joining Whole (academic) SAML landscape: 56 Federations, 3007 IdPs, 6514 SPs (gathered from metadata) Not all of them need to be interfederated, e.g. many internal SPs 13 The Rise of Federations

Networks ∙ Services ∙ People 14 eduGAIN and Federations 32 eduGAIN Members 9 Joining eduGAIN 3 Candidate Federation 12 Other Federations April 2015

Networks ∙ Services ∙ People 15 Identity is QUEEN Demand for Federated Access Identity as important as the network Users want to access services across various e- Infrastructures Industry recognises the importance of identity and federated access

Networks ∙ Services ∙ People 16 Scalability Business Models Support for VOs Authorization Non-Web Browser federated access Assurance Security Incident Response in Federations Support for Guest Users Data Protection Technology translators Attribute release Schema harmonisation Schema harmonization Business Models Scalability The Challenges Inter-federation

Networks ∙ Services ∙ People 17 Work in progress

Networks ∙ Services ∙ People 18 The Project Two-year EC-funded project 20 partners NRENs, e-Infrastructure providers and Libraries as equal partners About 3M euro budget Starting date 1st May, Authentication and Authorisation for Research and Collaboration

Networks ∙ Services ∙ People 19 AARC - Objectives Build on federated access, improve its up- take and address current challenges Harmonise policies among e-Infrastructures to ease service delivery Avoid the creation of project-specific AAIs by enabling researchers to use their existing credentials to access different resources Avoid the creation of project-specific AAIs by enabling researchers to use their existing credentials to access different resources Define a training package for institutions and services to support federated access Integrate existing R&E AAIs to create an highway for identities

Networks ∙ Services ∙ People 20 The landscape 20 AARC Requirements Anchored in real use cases Pilots AARC technical and policy findings Training REFEDS/FIM4R REFEDS: Feedback and validation from Fed Operators on best practices FIM4R: Feedback on pilots from AAI user communities Requirements/feedback for training and architecture e-Infrastructures i.e. GEANT Develop business case Costing Supply chain Pilot the deployments eduGAIN Incorporate

Networks ∙ Services ∙ People 21 Where do we want to be

Networks ∙ Services ∙ People 22 Challenges in 5 years The role of the IdPs will change: To become only authentication? A national single authentication point for the R&E ? Or a hub? eduID.se to create user accounts to access courses (and more) in all Swedish universities Federations will change More hubs and mesh as needed And to cope with privacy laws Engagement with other sectors: eGov – different approaches per countries/federations Industry – OIDC, social identities and cloud services Account linking

Networks ∙ Services ∙ People 23 What will be solved Non-Web federated access Incident response in federated access Attribute release for some use- cases Many issues related to Support for VOs

Networks ∙ Services ∙ People 24 Conclusions Plenty of work ahead Environment is right to collaborate rather than reinventing the wheel

Networks ∙ Services ∙ People Thank you and any questions Networks ∙ Services ∙ People 25