Networks ∙ Services ∙ People www.geant.org Ann Harding Networkshop 44, Manchester Thinking globally, acting locally Trust and Identity in the GÉANT project.

Slides:



Advertisements
Similar presentations
Agenda Project beginnings and funding. Purpose of the federation. Federation members. Federation protocols. Special features in our federation. Pilot.
Advertisements

Federated Identity Management in New Zealand Sat Mandri Service Manager TNC15 REFEDs Meeting, 14 th June 2015.
Innovation through participation Interfederation through eduGAIN - steps and challenges eduGAIN interfederation service Federated Identity Systems.
AARC Overview Licia Florio, David Groep 21 Jan 2015 presented by David Groep, Nikhef.
Authentication and Authorisation for Research and Collaboration Licia Florio (GÉANT) Christos Kanellopoulos (GRNET) Service orientation.
Géant-TrustBroker project overview Slides assembled by the Géant-TrustBroker team at Leibniz Supercomputing Centre, Germany for a short presentation by.
EResearchers Requirements the IGTF model of interoperable global trust and with a view towards FIM4R AAI Workshop Presenter: David Groep, Nikhef.
INTRODUCTION: THE FIRST TRY InCommon eduGAIN Policy and Community Working Group.
Authentication and Authorisation for Research and Collaboration Licia Florio REFEDS Meeting The AARC Project I2 Technology Exchange.
Authentication and Authorisation for Research and Collaboration Licia Florio AARC Workshop The AARC Project Brussels, 26 October.
Authentication and Authorisation for Research and Collaboration David Kelsey AARC AHM Milan And mechanisms NA3 Task 4 – Scalable.
Authentication and Authorisation for Research and Collaboration Niels van Dijk AARC General Meeting Authentication and Authorisation.
Authentication and Authorisation for Research and Collaboration Christos Kanellopoulos GRNET Proposed Pilots for Libraries and eGov.
Networks ∙ Services ∙ People Nicole Harris, GÉANT GN4 Project Update “SA5”, or Identity Stuff Internet2 Technology Exchange 2015.
Authentication and Authorisation for Research and Collaboration Michał Jankowski, Maciej Brzeźniak AARC General Meeting, Milan.
Géant-TrustBroker Project Overview Daniela Pöhn 7 th FIM4R meeting Frascati, Italy April 24 th, 2014.
JRA1.4 Models for implementing Attribute Providers and Token Translation Services Andrea Biancini.
Connect. Communicate. Collaborate Deploying Authorization Mechanisms for Federated Services in the eduroam architecture (DAMe)* Antonio F. Gómez-Skarmeta.
Authentication and Authorisation for Research and Collaboration David Groep AARC All Hands meeting Milano Policy and Best Practice.
Identity Federations: Here and Now David L. Wasley Thomas Lenggenhager Peter Alterman John Krienke.
Authentication and Authorisation for Research and Collaboration Christos Kanellopoulos Open Day Event: Towards the European Open.
Networks ∙ Services ∙ People Daniela Pöhn REFEDS EWTI, Vienna IdPs and Federations Service Aspects of Assurance SA5T1.
Understanding deployment issues on the Supply Chain Ann Harding, SWITCH, Nicole Harris, TERENA Cambridge July 2014.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
NREN Trust and Identity Strategy Ann Harding, SWITCH Cambridge July 2014.
Networks ∙ Services ∙ People Thomas Bärecke Journée Fédération, Paris Collaboration européenne GÉANT SA5 03/07/2015 SA5 T5 team
Networks ∙ Services ∙ People eduGAIN Townhall Meeting Nicole Harris (or updating the eduGAIN policy suite) “Unicorns can be sued in Wales”
Connect communicate collaborate Trust & Identity EC meets GÉANT 19 June 2014 Brussels Valter Nordh, NORDUnet Federation as a Service Task Leader Trust.
b2access.eudat.eu B2ACCESS The simple and secure authorisation and authentication platform of EUDAT This work is licensed under the Creative.
Connect communicate collaborate Internet2 Global Summit 27 April 2015 Washington DCs User Community Driven Development in Trust and Identity Services Ann.
Networks ∙ Services ∙ People Nicole Harris UK federation meeting eduGAIN, REFEDS and the UK 23 June 2015 Project Development Officer GÉANT.
Trust and Identity Infrastructure Services Above the Network Ann Harding, SWITCH/GÉANT UbuntuNetConnect 2014.
Networks ∙ Services ∙ People Marina Adomeit FIM4R meeting Virtual Organisation Platform as a Service VOPaaS Nov 30, 2015, Austria Task Leader,
Federated Identity Fundamentals Ann Harding, SWITCH Cambridge July 2014.
Networks ∙ Services ∙ People Ann Harding eduGAIN Town Hall eduGAIN in the GÉANT Project Activity Leader GÉANT Trust and Identity.
Networks ∙ Services ∙ People Ann Harding GÉANT Symposium, Vienna Users Session A3 Trust and Identity March GÉANT Activity Leader Trust.
Networks ∙ Services ∙ People Ann Harding + Marina Adomeit GÉANT Symposium 2016 What’s changed, what stays the same? Project future - services.
European Grid Initiative AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
Networks ∙ Services ∙ People Mandeep Saini TNC15, Porto, Portugal Virtual organisation Authorisation Management Practices in Research and.
AAI needs of the Distributed Computing Infrastructures - CLARIN Dieter Van Uytvanck Max Planck Institute for Psycholinguistics
INTRODUCTION TO IDENTITY FEDERATIONS Heather Flanagan, NSRC.
Networks ∙ Services ∙ People Andrea Biancini #TNC15, Porto, Portugal Implementing Grouper to federate user authorization Federated Authorization.
Networks ∙ Services ∙ People Licia Florio TNC, Lisbon Consuming identities across e- Infrastructures 16 June 2015 PDO GÈANT.
Authentication and Authorisation for Research and Collaboration Heiko Hütter, Martin Haase, Peter Gietz, David Groep AARC 3 rd.
Authentication and Authorisation for Research and Collaboration Peter Solagna, Davide Vaghetti, et al. Topics for PY2 activities.
Authentication and Authorisation for Research and Collaboration Licia Florio AARC CORBEL Workshop The AARC Project Paris, 31 May.
Connected Identity & the role of the Identity Bus Prabath Siriwardena Director of Security Architecture WSO2.
Networks ∙ Services ∙ People Marina Adomeit TNC16 Conference, Prague Towards a platform for supporting collaboration GÉANT VOPaaS
Networks ∙ Services ∙ People TNC 2016, Prague Alice Through the Looking Glass Science DMZ goes above the network 13 June
Authentication and Authorisation for Research and Collaboration Peter Solagna, Nicolas EGI AAI integration experiences AARC Project.
Authentication and Authorisation for Research and Collaboration David Kelsey AARC AHM Utrecht NA3 Task 4 – Scalable Policy Negotiation.
Authentication and Authorisation for Research and Collaboration AARC/CORBEL Workshop for Life Sciences AAI AARC Draft Blueprint.
Authentication and Authorisation for Research and Collaboration Taipei - Taiwan Mechanisms of Interfederation 13th March 2016 Alessandra.
Networks ∙ Services ∙ People Mandeep Saini AARC/CORBEL Workshop Collaborative Organisation Platform as a Service June 1, 2016, Paris Product.
Networks ∙ Services ∙ People Di4R Network. Services. People. GÉANT 28 th September, Krakow.
Boosting AAI for research and collaboration
Cross-sector and user-centric AAI
User Community Driven Development in Trust and Identity
eduTEAMS platform for collaboration Niels Van Dijk
eduTEAMS – Current status & Future Plans
Identity Federations - Overview
GÉANT International Networking and Collaboration
An AAI solution for collaborations at scale
Boosting AAI for research and collaboration
GÉANT project update eduTEAMS - AAI as a Service for Collaborative organisations Introduction Status Pilots New Features – input requested InAcademia –
AAI For Researchers Licia Florio AARC Project Coordinator GÉANT DI4R
AARC Blueprint Architecture and Pilots
AAI Architectures – current and future
Community AAI with Check-In
Check-in Identity and Access Management solution that makes it easy to secure access to services and resources.
Presentation transcript:

Networks ∙ Services ∙ People Ann Harding Networkshop 44, Manchester Thinking globally, acting locally Trust and Identity in the GÉANT project GÉANT Activity Leader, Trust and Identity Development SWITCH Project Manager

Networks ∙ Services ∙ People Trust and Identity today Classic Identity Federations interoperating via eduGAIN 2 Identity Provider (IdP) asserts authentication and information about users. Service Providers (SP) check and consume this information for authorization and make it available to an application A group of organizations running IdPs and SPs that agree on a common set of rules and standards that build trust

Networks ∙ Services ∙ People 3 From local to global 3

Networks ∙ Services ∙ People Crowd Intelligence Digital Research Open Innovation Collaborative Design e-infrastructure Technology Conventional Computing Flexible Communication More People More Machines e-Science (Scholars, citizens) HPC Big Compute Big Data Adapted from: Professor David De Roure, Professor of e-Research at University of Oxford More complex trust A changing research environment

Networks ∙ Services ∙ People No researcher works in isolation 5 Source: LIGO/Caltech

Networks ∙ Services ∙ People Campus Hundreds of thousands of users Federation Tens of thousands of services eduGAIN Thousands of services General and Specific e- Research Infrastructures Hundreds of services Individual Experiments Tens to hundreds of individuals * e-Research Trust and Identity Infrastructures 6

Networks ∙ Services ∙ People Entity Categories for Attribute Release Moonshot Production Next Generation Architectures and Protocols e-Research Support AARC Collaboration Virtual Organisation Platform InAcademia Simple Validation Service Assurance Selected Roadmap Developments until 2016 Campus IdP Services

Networks ∙ Services ∙ People To be able to grant access, a Service needs information beyond Authentication In Identity Federations this information is often conveyed using attributes Often attributes from the Home Organisation alone are not enough: VO related Services need attribute information in the context of the VO VOs therefore need to be able to manage and provide attribute and group information towards Services, independently from the Home Organisation 8 In Focus - VO Platform Enable flexible collaboration

Networks ∙ Services ∙ People Persistent Identifier - Allow the VO to identify the user even if (s)he changes IdP VO Membership Registry - To become members of the VO a certain workflow must be followed ‘External’ Identities – Not all VO users will be in eduGAIN Attributes beyond the IdP are needed for VO roles and rights, or to provide extra context (e.g. ORCID, Grant number) Group Management - groups may also be used to define roles and rights (de)Provisioning – Identity, attributes and groups need to be provided to Services Service Proxy and Attribute Aggregation 9 In Focus – VO Platform functional requirements

Networks ∙ Services ∙ People VO Membership service registry for VO persistent Identifier VO specific Workflows for onboarding Limited set of attributes External Identity Provider (extIDp) One persistent (SAML) IdP for many ‘Guest’ Identity Providers, including: Social (Google, Twitter, Linkedin, Facebook) NREN operated & Commercial Guest IdPs (OpenIDP, UnitedID.org, eduID.se) eGOV (STORK) Provides LOA: eIDAS by default once available, others upon request from SP Available and accessible through eduGAIN 10 VO Platform Basic Service Requirements Pilot in preparation

Networks ∙ Services ∙ People Most of eduGAIN is under EU Data protection directive or equivalent The objective of the directive is to protect a person’s fundamental rights while guaranteeing the free flow of personal data between member states Member States shall provide that the controller must implement appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction or accidental loss, alteration, unauthorized disclosure or access, in particular where the processing involves the transmission of data over a network, and against all other unlawful forms of processing. 11 Unlocking Attributes I am not a lawyer…

Networks ∙ Services ∙ People 12 Balancing Risk

Networks ∙ Services ∙ People Entity Categories group federation entities that share common criteria. Facilitate IdP decisions to release a defined set of attributes to SPs without the need for detailed local review for each SP Check with JISC for advice on which best suits your needs Research and Scholarship Entity Category relies on the legitimate interest approach Safeguards of data minimisation, privacy enhancing tech Limits the types of services that are allowed to claim this category and focusing on low-risk, high benefit services that have a clearly identifiable need for personal information Each SP is considered on a case-by-case basis by the federation in question and reviewed annually. GÉANT Code of Conduct approach aims to minimise the risk that arises from depending on each other. Legitimate interest is also fundamental Signals that the Home Organisation and Service Provider are aware of the legal requirements Based on Directive 95/46/EC In Focus - Attribute Release Tools to automate risk-analysis-based support of e-Research

Networks ∙ Services ∙ People Now can LIGO have some attributes please? We have many more years of gravitational-wave astronomy discoveries to come and realizing the full science potential will require close collaboration with astronomers and astrophysicists from around the world. eduGAIN and your national federations can help make that happen. - Scott Koranda, lead architect for the Laser Interferometer Gravitational-Wave Observatory Identity and Access Management Read more about releasing attributes for Science 14 What we can do

Networks ∙ Services ∙ People Thank you Networks ∙ Services ∙ People This work is part of a project that has received funding from the European Union’s Horizon 2020 research and innovation programme under Grant Agreement No (GN4-1).