ELIXIR AAI Michal Procházka, Mikael Linden, EGI VC 15 March 2016.

Slides:



Advertisements
Similar presentations
Federated Identity Management for HEP David Kelsey WLCG GDB 9 May 2012.
Advertisements

AAI-enabled VO Platform “VO without Tears” Christoph Witzig EGI TF, Amsterdam, Sept 15, 2010.
Authentication and Authorisation for Research and Collaboration Licia Florio (GÉANT) Christos Kanellopoulos (GRNET) Service orientation.
European Life Sciences Infrastructure for Biological Information Life science community update for the 7 th Federated Identity Management.
Authentication and Authorisation for Research and Collaboration Licia Florio REFEDS Meeting The AARC Project I2 Technology Exchange.
Authentication and Authorisation for Research and Collaboration Licia Florio AARC Workshop The AARC Project Brussels, 26 October.
Authentication and Authorisation for Research and Collaboration Peter Solagna Milano, AARC General meeting Current status and plans.
Authentication and Authorisation for Research and Collaboration Peter Solagna Milano, AARC General meeting Report and plans Attribute.
Authentication and Authorisation for Research and Collaboration Peter Solagna Milano, AARC General meeting Current status and plans.
Authentication and Authorisation for Research and Collaboration Mikael Linden AARC all hands Milan Authentication and Authorisation.
Authentication and Authorisation for Research and Collaboration Milan, Italy Training and Outreach Authentication and Authorisation.
JRA1.4 Models for implementing Attribute Providers and Token Translation Services Andrea Biancini.
Federated Identity Management for HEP David Kelsey HEPiX, IHEP Beijing 18 Oct 2012.
AAI Developments AAI for e-infrastructures UK T0 workshop, Milton Hill Park October 2015
University of Washington Collaboration: Identity and Access Management Lori Stevens University of Washington October 2007.
Authentication and Authorisation for Research and Collaboration Christos Kanellopoulos Open Day Event: Towards the European Open.
EUDAT receives funding from the European Union's Horizon 2020 programme - DG CONNECT e-Infrastructures. Contract No B2ACCESS LSDMA.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
A uthentication & A uthorization for R esearch & C ollaboration Pilots in SA1 Paul van Dijk, SURFnet AARC.
Networks ∙ Services ∙ People Marina Adomeit FIM4R meeting Virtual Organisation Platform as a Service VOPaaS Nov 30, 2015, Austria Task Leader,
Authentication and Authorisation for Research and Collaboration Taipei Taiwan Authentication and Authorisation for Research and.
European Grid Initiative AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI-InSPIRE PY5 new activities Peter Solagna – EGI.eu.
Project Moonshot Daniel Kouřil EGI Technical Forum
Networks ∙ Services ∙ People Licia Florio TNC, Lisbon Consuming identities across e- Infrastructures 16 June 2015 PDO GÈANT.
Authentication and Authorisation for Research and Collaboration Peter Solagna, Davide Vaghetti, et al. Topics for PY2 activities.
European Life Sciences Infrastructure for Biological Information European Life Sciences Infrastructure for Biological Information.
Networks ∙ Services ∙ People Marina Adomeit TNC16 Conference, Prague Towards a platform for supporting collaboration GÉANT VOPaaS
Authentication and Authorisation for Research and Collaboration Peter Solagna, Nicolas EGI AAI integration experiences AARC Project.
Authentication and Authorisation for Research and Collaboration AARC/CORBEL Workshop for Life Sciences AAI AARC Draft Blueprint.
European Life Sciences Infrastructure for Biological Information European Life Sciences Infrastructure for Biological Information.
Security in the wider world David Kelsey (STFC-RAL) GridPP37 – Ambleside 2 Sep 2016.
Introduction to AAI Services
The EGI AAI “CheckIn” Service
Boosting AAI for research and collaboration
RCauth.eu CILogon-like service in EGI and the EOSC
Authentication and Authorisation for Research and Collaboration
EGI Updates Check-in Matthew Viljoen – EGI Foundation
AAI for a Collaborative Data Infrastructure
User Community Driven Development in Trust and Identity
eduTEAMS platform for collaboration Niels Van Dijk
eduTEAMS – Current status & Future Plans
Identity Management and Authorization
Christos Kanellopoulos
CheckIn: the AAI platform for EGI
AAI Alignment Nicolas Liampotis (based on the work of Mikael Linden)
Check-in Nicolas Liampotis
An AAI solution for collaborations at scale
Boosting AAI for research and collaboration
Updates on Training Andrea Biancini (AARC2.AHM)2 NA2 WP leader
ELIXIR Safeguarding the results of life science research in Europe
The AARC Project Licia Florio (GÉANT) Christos Kanellopoulos (GRNET)
The AARC Project Licia Florio AARC Coordinator GÉANT
Minimal Level of Assurance (LoA)
Identity Management and Authorization
Identity Management and Authorization
GÉANT project update eduTEAMS - AAI as a Service for Collaborative organisations Introduction Status Pilots New Features – input requested InAcademia –
Leveraging the IGTF authentication fabric for research
Leveraging the IGTF authentication fabric for research
Thursday pilot session: 7-minutes
Pilots in AARC Arnout Terpstra (AARC2) / Paul van Dijk (AARC1)
Pilots in AARC Arnout Terpstra (AARC2) / Paul van Dijk (AARC1)
AARC Blueprint Architecture and Pilots
Common Authentication and Authorisation Service for Life Science Research Mikael Linden, ELIXIR Finland.
AAI Architectures – current and future
RCauth.eu CILogon-like service in EGI and the EOSC
Community AAI with Check-In
AAI in EGI Status and Evolution
Check-in Identity and Access Management solution that makes it easy to secure access to services and resources.
Common Authentication and Authorisation Service for Life Science Research Mikael Linden, ELIXIR Finland.
Presentation transcript:

ELIXIR AAI Michal Procházka, Mikael Linden, EGI VC 15 March 2016

Goals of this meeting How we harmonize development and deployment of the AAI infrastructure? What will be benefits for ELIXIR to interconnect with EGI AAI? What AAI components can be shared?

ELIXIR AAI history – where we are now Use case gathering -- Autumn Requirements and design – Spring 2015 Based on existing s/w and experience in the NREN community Deployment starts – Autumn 2015 – EXCELERATE WP4.3.1 Part of ELIXIR Compute platform First release -- August 2016 Until that ELIXIR AAI in pilot status Key components up and running already

High level stuff: ELIXIR AAI strategy (DRAFT) Covers ELIXIR AAI under the responsibility of the hub Delegation of common AAI components to other e-infrastructures Relations to e-infrastructures (collaborate, make use of) Relations to other BMS research infrastructure (common AAI, share gained knowledge) ELIXIR AAI policies for end users, relying parties and AAI operators Under community consultation right now

Design of ELIXIR AAI

ELIXIR AAI design 6 ELIXIR AAI External authentication (e-infrastructures) Relying services eduGAIN IdPsCommon IdPs ELIXIR Proxy IdP ELIXIR Directory Bona fide management Dataset authorisation management (REMS) Group/role mgmt (PERUN) Credential translation EGAeLearning CloudIntranet wiki Data archive …… Attribute self-management Step-up AuthN

ELIXIR identity 7 ELIXIR AAI External authentication Relying services EGAwiki CloudIntranet … Data archive …… (Google ID) (eduGAIN) (ORCID) (ELIXIR ID)

The dimensions of authentication and authorisation

The planned assurance levels for authentication Basic (in place now) Raised Strong Self-registrated accounts, password authN Google, LinkedIn, ORCID authentication Organisation-registed accounts, password authN Log in with Home Organisation IdPs (eduGAIN) Requires Home Organisation complying to a minimal assurance level Face-to-face proof of identity and two factor authN Step-up authentication Possibly rely on external sources (e.g. eID)

ELIXIR AAI position It is used by to community already Users’ enrolment Group and authorization management Community is quite large BBMRI would like to use the same approach as is used in ELIXIR Uses validated and maintained components Perun, REMS, OpenConext, CILogon, Kerberos, Shibboleth, VOMS There is no own development, just deployment

Common BMS AAI AARC2 project proposal has a pilot: BMS AAI Gather use cases Draw requirements and design Have a pilot Study implementation alternatives For a Common AAI for the 11 BMS research infrastructures (in collaboration with the CORBEL project) We can expect all those BMS to require the same AAI components

Perceived differences and gaps ELIXIR AAI architecture is finalized with all the components required to do the AAI within the e-Infrastructure Core components of ELIXIR AAI is operational Design of EGI architecture is is not complete and list of used components is not fixed

User/group/VO management ELIXIR has its own VO/group/user management system connected to the Proxy IdP directly EGI relies on attribute authorities, it is not clear how the users will be registered to the attribute authorities and how the attribute authorities will manage additional user’s attributes

Authorization ELIXIR has central component where authZ rules are defined Services receive only relevant data, no data breach Bona fide researcher defined Connection with REMS for additional authZ management In EGI AAI there isn’t clear who and where the authZ will be defined: globally? on VO level? Proxy IdP doesn’t know the attribute values in advance, thus cannot filter them. AAs doesn’t know the target service so they cannot do filtering as well

Identity verification ELIXIR can raise user’s LoA by Managers/board approval (Perun and REMS) Connection with ORCID and publications Identity consolidation EGI uses only external identities as is

Identity consolidation ELIXIR consolidates users’ identities at system which do the VO/group/authZ management Identity consolidation is done on Proxy IdP It is not clear how this information will be published to the attribute authorities which are doing registration/manageme nt of the users

Common components Perun system At EGI works as an Attribute Authority At ELIXIR does the whole user/group/vo management, including account linking, provisioning/deprovisioning Can be outsourced CILogon and other token translation components (can be outsourced) VOMS (can be outsourced) REMS (can be outsourced) Proxy IdP ELIXIR uses OpenConext components (maintained by SurfNet, used by SurfConext and delivers additional components on top of SimpleSAMLphp like OIC, step-up authN) EGI uses OpenConext as well?

How to interconnect AAI infrastructures? ELIXIR AAI should be one of many AAIs to connect to the EGI AAI, do not do proprietary interconnection EUDAT, UNICORE, PRACE, … BBMRI, CLARIN, DARIAH,... Keep it simple (avoid multiple WAYFs), but secure Use shared components Strong trust between AAI infrastructures and shared components – technical and political E.g. Trusted CA at CILogon, accepted privacy policy for REMS or Perun

How we can harmonize work on AAI? Share our design documents ELIXIR AAI Requirements and Design Document (mostly align with the AARC Blue Print) Share components ELIXIR needs to know clear vision what the EGI AAI will deliver and what will be the quality of service ELIXIR can then adopt technologies used in EGI, but cannot be alpha tester Need to harmonize also policies ELIXIR is currently developing policy documents for each of the AAI component Privacy policy should be harmonized as well