Networks ∙ Services ∙ People Marina Adomeit TNC16 Conference, Prague Towards a platform for supporting collaboration GÉANT VOPaaS 14.06.2016.


Similar presentations
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager

Federated Identity Management for Researchers – A quick overview from GÉANT BoF TNC May 2014 Dublin.
EduGAIN – Are we there yet? Lukas Hämmerle (ghost writer, Brook Schofield) FIM4R, Helsinki – 2 October 2013.
Step-up Authentication as-a Service Pieter van der Meulen Technical Product Manager.
Networks ∙ Services ∙ People John DYER TF-MSP Video Conference Community Procurement Support Building on the SPOT-ON Proposal Smart Procurement,
FIM-ig Federated Identity Management Interest Group.
Developments and challenges in authentication and authorisation Klaas Wierenga Berlin, 23 May 2006.
AARC Overview Licia Florio, David Groep 21 Jan 2015 presented by David Groep, Nikhef.
CLARIN Infrastructure Vision (and some real needs) Daan Broeder CLARIN EU/NL Max-Planck Institute for Psycholinguistics.
Supporting Are we ready? REFEDS, Oct 2013 Ann Harding
European Life Sciences Infrastructure for Biological Information Life science community update for the 7 th Federated Identity Management.
Collaborative Platforms. Collaborations and Virtual Organizations IdM is a critical dimension of collaboration, crossing many applications.
EResearchers Requirements the IGTF model of interoperable global trust and with a view towards FIM4R AAI Workshop Presenter: David Groep, Nikhef.
Federation as a Service Marina Vermezović, AMRES Federated Identity Technology Workshop Sofia, Bulgaria, 20. Jun 2014.
Authentication and Authorisation for Research and Collaboration Peter Solagna Milano, AARC General meeting Current status and plans.
Authentication and Authorisation for Research and Collaboration Peter Solagna Milano, AARC General meeting Report and plans Attribute.
Authentication and Authorisation for Research and Collaboration Peter Solagna Milano, AARC General meeting Current status and plans.
Authentication and Authorisation for Research and Collaboration Christos Kanellopoulos GRNET Proposed Pilots for Libraries and eGov.
Authentication and Authorisation for Research and Collaboration Michał Jankowski, Maciej Brzeźniak AARC General Meeting, Milan.
JRA1.4 Models for implementing Attribute Providers and Token Translation Services Andrea Biancini.
Federated Identity Management for HEP David Kelsey HEPiX, IHEP Beijing 18 Oct 2012.
Connect. Communicate. Collaborate Deploying Authorization Mechanisms for Federated Services in the eduroam architecture (DAMe)* Antonio F. Gómez-Skarmeta.
HEXAA e-Science gateways with external attribute authority István Tétényi, MTA SZTAKI 21-May-2014 Co-Authors: Mr. Héder, Mihály (MTA SZTAKI); Mr. BAJNOK,
Authentication and Authorisation for Research and Collaboration Christos Kanellopoulos Open Day Event: Towards the European Open.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
NREN Trust and Identity Strategy Ann Harding, SWITCH Cambridge July 2014.
Networks ∙ Services ∙ People Thomas Bärecke Journée Fédération, Paris Collaboration européenne GÉANT SA5 03/07/2015 SA5 T5 team
Connect communicate collaborate Trust & Identity EC meets GÉANT 19 June 2014 Brussels Valter Nordh, NORDUnet Federation as a Service Task Leader Trust. B2ACCESS The simple and secure authorisation and authentication platform of EUDAT This work is licensed under the Creative.
Networks ∙ Services ∙ People Nicole Harris UK federation meeting eduGAIN, REFEDS and the UK 23 June 2015 Project Development Officer GÉANT.
Trust and Identity Infrastructure Services Above the Network Ann Harding, SWITCH/GÉANT UbuntuNetConnect 2014.
Networks ∙ Services ∙ People Marina Adomeit FIM4R meeting Virtual Organisation Platform as a Service VOPaaS Nov 30, 2015, Austria Task Leader,
Federated Identity Fundamentals Ann Harding, SWITCH Cambridge July 2014.
Networks ∙ Services ∙ People Ann Harding eduGAIN Town Hall eduGAIN in the GÉANT Project Activity Leader GÉANT Trust and Identity.
Authentication and Authorisation for Research and Collaboration Licia Florio REFEDS Meeting AARC and AARC2 Vienna, 1 st December.
Networks ∙ Services ∙ People Mandeep Saini TNC15, Porto, Portugal Virtual organisation Authorisation Management Practices in Research and.
AAI needs of the Distributed Computing Infrastructures - CLARIN Dieter Van Uytvanck Max Planck Institute for Psycholinguistics
Case Studies in Federated Identity Management for Research Communities Ann Harding, SWITCH/GN3plus Peter Gietz, DAASI International GmbH/DARIAH Tommi Nyro.
Connect communicate collaborate Case Studies in Federated Identity Management for Research Communities Ann Harding, SWITCH/GN3plus Peter Gietz, DAASI International.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI-InSPIRE PY5 new activities Peter Solagna –
Open Collaboration Exchange Alexander Blanc, Niels van Dijk, Jocelyn Manderveld, Remco Poortinga - van Wijnen VAMP 2013, Espoo.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Enabling SSO capabilities in the EGI Cloud services Peter Solagna –
Networks ∙ Services ∙ People Licia Florio TNC, Lisbon Consuming identities across e- Infrastructures 16 June 2015 PDO GÈANT.
European Life Sciences Infrastructure for Biological Information European Life Sciences Infrastructure for Biological Information.
Networks ∙ Services ∙ People TNC 2016, Prague Alice Through the Looking Glass Science DMZ goes above the network 13 June
Authentication and Authorisation for Research and Collaboration Peter Solagna, Nicolas EGI AAI integration experiences AARC Project.
Authentication and Authorisation for Research and Collaboration AARC/CORBEL Workshop for Life Sciences AAI AARC Draft Blueprint.
Networks ∙ Services ∙ People Ann Harding Networkshop 44, Manchester Thinking globally, acting locally Trust and Identity in the GÉANT project.
Authentication and Authorisation for Research and Collaboration Taipei - Taiwan Mechanisms of Interfederation 13th March 2016 Alessandra.
Networks ∙ Services ∙ People Mandeep Saini AARC/CORBEL Workshop Collaborative Organisation Platform as a Service June 1, 2016, Paris Product.
Authentication and Authorisation for Research and Collaboration Licia Florio IGTF Meeting The AARC Project Amsterdam, 8 September.
Networks ∙ Services ∙ People Di4R Network. Services. People. GÉANT 28 th September, Krakow.
Introduction to AAI Services
Cross-sector and user-centric AAI
EGI Updates Check-in Matthew Viljoen – EGI Foundation
User Community Driven Development in Trust and Identity
eduTEAMS platform for collaboration Niels Van Dijk
eduTEAMS – Current status & Future Plans
CheckIn: the AAI platform for EGI
Federated Identity Management for Researchers (FIM4R)
An AAI solution for collaborations at scale
ELIXIR Safeguarding the results of life science research in Europe
GÉANT project update eduTEAMS - AAI as a Service for Collaborative organisations Introduction Status Pilots New Features – input requested InAcademia –
EduTEAMS at a Glance Mandeep Saini Linz, Austria 30 May 2017.
Multi-Domain User Applications Research (JRA3)
AARC Blueprint Architecture and Pilots
Community AAI with Check-In
eIDAS-enabled Student Mobility
Check-in Identity and Access Management solution that makes it easy to secure access to services and resources.
Presentation transcript:

Networks ∙ Services ∙ People Marina Adomeit TNC16 Conference, Prague Towards a platform for supporting collaboration GÉANT VOPaaS SA2 Activity Leader, GÉANT Head of department for user services, AMRES

Networks ∙ Services ∙ People GÉANT project is Europe’s leading collaboration on network and related infrastructure and services for the benefit of research and education. Majority of GÉANT members operate Identity Federations and GÉANT operates the eduGAIN interfederation. GÉANT members also collaborate to design and deliver services. In order to support the uptake of federated technologies and enable more communities to use eduGAIN, GÉANT initated a task offering hosted federation services. Federation as a Service - FaaS is service aimed to federation operators. Service offering is hosted federation metadata registry connected to eduGAIN MDS. VO Platform as a Service – VOPaaS offering is a simple, consistent way of offering and using federated services for virtual organisations, including group management, attribute authorities. 2 About VOPaaS in GÉANT

Networks ∙ Services ∙ People Goal: Investigate the conditions that would allow GÉANT to provide services to support Virtual Organisations Focus on delivery of Technical services Out of scope: Technical development Policy & LOA development Activities: Gather requirements and priorities with/from communities Look at existing tools and technologies Look into delivery model Investigate business case & sustainability Operations and Market 3 VO Platform as a Service

Networks ∙ Services ∙ People Access to resources (or Services) often needs to be managed, and therefore requires authentication and authorization. When using Federated Authentication in R&E, the identity is managed at the Home Institution. The Identity provider (IdP), operated by the Home Institution, allows the authentication towards a Service Provider (SP). Identity Federations provide trust frameworks between Service Providers and Institutions. Interfederation, such as eduGAIN, emerged because of the need to interconnect National identity federations. For international collaborations, federated AAI based on eduGAIN looks like an extremely useful infrastructure to build on. 4 Virtual Organisations and AAI

Networks ∙ Services ∙ People Authorization is about specifying access rights to a Service To be able to grant access, a Service needs information beyond Authentication In Identity Federations this information is often conveyed using attributes Often attributes from the Home Organisation alone are not enough: VO related Services need attribute information in the context of the VO VOs therefore need to be able to manage and provide attribute and group information towards Services, independently from the Home Organisation 5 Virtual Organisations and AAI

Networks ∙ Services ∙ People The FIM4R paper (April 2012) was one of the first to articulate collective requirements for using Federated AAI for VOs. Many VOs have chosen to build the AAI infrastructure using the national and eduGAIN infrastructures. Identity Federations and Identity providers are however traditionally focused on Campus use cases, which introduces a number of challenges for VOs in leveraging Federated AAI. The VOPaaS has performed a survey among several small and large Pan- European VOs to (re-)validate the FIM4R requirements. From the results of this Survey, functional requirements were analyzed. A number of services were proposed to be put in place to support VOs on a Pan-European level. 6 Requirements for building on Federated AAI as a VO

Networks ∙ Services ∙ People Interviews and desk study conducted with: Umbrella(Large neutron and photon facilities) CLASSe(Shared IaaS) DARIAH(Humanities) CERN(High Energy Physics) CLARIN(Humanities and social sciences) Virtual Campus Hub (eLearning, Renewable Energy) ELIXIR(Life Sciences, Bioinformatics) GÉANT VAPIRE (NREN collaboration). Broad NREN/federation participation: AMRES, CESNET, DFN/LRZ, GARR, IUCC, NIIF, RENATER, SUNET, SURFnet, SWITCH Market Analysis 2_Market-Analysis-for-Virtual-Organisation-Platform-as-a-Service.pdf 7 VOPaaS Market Analysis

Networks ∙ Services ∙ People 8 VOpaas Market Analysis Results

Networks ∙ Services ∙ People Functional requirements identified Persistent Identifier - Allow the VO to identify the user even if (s)he changes IdP VO Membership Registry - To become members of the VO a certain workflow must be followed ‘External’ Identities - Many VO users will not be in eduGAIN Attribute Management - Attributes beyond the IdP are needed for VO roles and rights, or to provide extra context (e.g. ORCID, Grant number) Group Management - groups may also be used to define roles and rights (de)Provisioning – Identity, attributes and groups need to be provided to Services Service Proxy and Attribute Aggregation – A centralised infrastructure to operate on behalf of the VO Service Providers 9 Function requirements for VOPaaS

Networks ∙ Services ∙ People Basic Services Operated by GÉANT Multi tenant service Also for VOs that are not legal entities Operated as a (set of) Services Advanced Services Operated by GÉANT on behalf of a VO Single tenant service Somebody – a legal entity - must take responsibility for that data Operates as per VO applications on VM ‘boxes’ 10 Deployment model

Networks ∙ Services ∙ People VO Membership service registry for VO persistent Identifier VO specific Workflows for onboarding Limited set of attributes Accessible through eduGAIN & TEIP Transparent External Identity proxy (TEIP) One persistent (SAML) IdP for many ‘Guest’ Identity Providers, including: Social (Google, Twitter, Linkedin, Facebook) NREN operated & Commercial Guest IdPs (OpenIDP,, eGOV (STORK) BankID Provides LOA: eIDAS by default, others upon request from SP Available and accessible through eduGAIN 11 Basic Services

Networks ∙ Services ∙ People (advanced) Attribute Management - Whatever you can come up with (advanced) Group Management - Groups in groups, etc. Provisioning - For web and non-web resources, ‘application specific connectors’ Service Proxy and Attribute Aggregation – To have a central point for technology and policy Accessible through eduGAIN & extIDp May be delivered as a paid service 12 Advanced Services

Networks ∙ Services ∙ People Basic Services VO Membership service: COmanage Transparent External Identity Proxy (TEIP): SaToSa Advanced Services Attributes and Groups: HEXAA, PERUN and COmanage SP Proxy: OpenConext 13 Tools

Networks ∙ Services ∙ People 14 VOPaaS membership registration functional design

Networks ∙ Services ∙ People 15 VOPaaS TEIP functional design

Networks ∙ Services ∙ People Thank you Networks ∙ Services ∙ People 16