Case Studies in Federated Identity Management for Research Communities

Slides:



Advertisements
Similar presentations
Innovation through participation Data Protection Code of Conduct (DP CoC) REFEDS Helsinki Mikael Linden, CSC – IT Center for Science
Advertisements

Federated Identity Management for Researchers – A quick overview from GÉANT BoF TNC May 2014 Dublin.
Federated Identity Management for Research Communities (FIM4R) David Kelsey (STFC-RAL) EGI TF, AAI workshop 19 Sep 2012.
FIM-ig Federated Identity Management Interest Group.
EUROPEAN IDENTITY STRATEGY 1 NICOLE HARRIS e-Infrastructure Summer Workshops, Federated Identity Technology.
Federated Identity Management in New Zealand Sat Mandri Service Manager TNC15 REFEDs Meeting, 14 th June 2015.
BoF: Federated Identity Management for Researchers David Kelsey (STFC-RAL) TNC2014, Dublin 20 May 2014.
Authentication and Authorization in a federated environment Jules Wolfrat (SARA)
AARC Overview Licia Florio, David Groep 21 Jan 2015 presented by David Groep, Nikhef.
Federated Identity Management for HEP David Kelsey WLCG GDB 9 May 2012.
Connect communicate collaborate GÉANT3plus Enabling Users Pilots Lukas Hämmerle Task Leader "Enabling Users"
Authentication and Authorisation for Research and Collaboration Licia Florio (GÉANT) Christos Kanellopoulos (GRNET) Service orientation.
European Life Sciences Infrastructure for Biological Information Life science community update for the 7 th Federated Identity Management.
7 th FIM 4 R meeting April 2014 ESRIN Frascati.
Jamie Hall (ILL). SciencePAD Persistent Identifiers Workshop PANData Software Catalogue January 30th 2013 Jamie Hall Developer IT Services, Institut Laue-Langevin.
EResearchers Requirements the IGTF model of interoperable global trust and with a view towards FIM4R AAI Workshop Presenter: David Groep, Nikhef.
Authentication and Authorisation for Research and Collaboration Licia Florio REFEDS Meeting The AARC Project I2 Technology Exchange.
Authentication and Authorisation for Research and Collaboration Licia Florio AARC Workshop The AARC Project Brussels, 26 October.
Authentication and Authorisation for Research and Collaboration David Kelsey AARC AHM Milan And mechanisms NA3 Task 4 – Scalable.
Authentication and Authorisation for Research and Collaboration Peter Solagna Milano, AARC General meeting Current status and plans.
Federated Identity Management for HEP David Kelsey HEPiX, IHEP Beijing 18 Oct 2012.
Authentication and Authorisation for Research and Collaboration Christos Kanellopoulos Open Day Event: Towards the European Open.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
NREN Trust and Identity Strategy Ann Harding, SWITCH Cambridge July 2014.
Networks ∙ Services ∙ People Thomas Bärecke Journée Fédération, Paris Collaboration européenne GÉANT SA5 03/07/2015 SA5 T5 team
Connect communicate collaborate Trust & Identity EC meets GÉANT 19 June 2014 Brussels Valter Nordh, NORDUnet Federation as a Service Task Leader Trust.
b2access.eudat.eu B2ACCESS The simple and secure authorisation and authentication platform of EUDAT This work is licensed under the Creative.
Connect communicate collaborate Internet2 Global Summit 27 April 2015 Washington DCs User Community Driven Development in Trust and Identity Services Ann.
Networks ∙ Services ∙ People Nicole Harris UK federation meeting eduGAIN, REFEDS and the UK 23 June 2015 Project Development Officer GÉANT.
Research Community Requirements Ann Harding, SWITCH Cambridge July 2014.
Networks ∙ Services ∙ People Marina Adomeit FIM4R meeting Virtual Organisation Platform as a Service VOPaaS Nov 30, 2015, Austria Task Leader,
European Grid Initiative AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
Authentication and Authorisation for Research and Collaboration Licia Florio REFEDS Meeting AARC and AARC2 Vienna, 1 st December.
Case Studies in Federated Identity Management for Research Communities Ann Harding, SWITCH/GN3plus Peter Gietz, DAASI International GmbH/DARIAH Tommi Nyro.
Connect communicate collaborate Case Studies in Federated Identity Management for Research Communities Ann Harding, SWITCH/GN3plus Peter Gietz, DAASI International.
David Groep Nikhef Amsterdam PDP & Grid AARC Authentication and Authorisation for Research and Collaboration an impression of the road ahead.
Federated Identity Management for Research Communities: FIM4R PSI workshop objectives Bob Jones, CERN.
Networks ∙ Services ∙ People Licia Florio TNC, Lisbon Consuming identities across e- Infrastructures 16 June 2015 PDO GÈANT.
Networks ∙ Services ∙ People Marina Adomeit TNC16 Conference, Prague Towards a platform for supporting collaboration GÉANT VOPaaS
Networks ∙ Services ∙ People TNC 2016, Prague Alice Through the Looking Glass Science DMZ goes above the network 13 June
Authentication and Authorisation for Research and Collaboration AARC/CORBEL Workshop for Life Sciences AAI AARC Draft Blueprint.
Authentication and Authorisation for Research and Collaboration Taipei - Taiwan Mechanisms of Interfederation 13th March 2016 Alessandra.
Authentication and Authorisation for Research and Collaboration Licia Florio IGTF Meeting The AARC Project Amsterdam, 8 September.
Introduction to AAI Services
WLCG Update Hannah Short, CERN Computer Security.
Cross-sector and user-centric AAI
The Policy Puzzle Many groups and (proposed) policies, but leaving many open issues AARC “NA3” is tackling a sub-set of these “Levels of Assurance” –
EGI Updates Check-in Matthew Viljoen – EGI Foundation
User Community Driven Development in Trust and Identity
eduTEAMS platform for collaboration Niels Van Dijk
Federated Identity Management for Researchers (FIM4R)
CLARIN Federated Identity Vision
Mirjam van Daalen:: Paul Scherrer Institut
GÉANT International Networking and Collaboration
Federated Identity Management for Scientific Collaborations
ELIXIR Safeguarding the results of life science research in Europe
The AARC Project Licia Florio (GÉANT) Christos Kanellopoulos (GRNET)
The AARC Project Licia Florio AARC Coordinator GÉANT
ESA Single Sign On (SSO) and Federated Identity Management
Pilots in AARC Arnout Terpstra (AARC2) / Paul van Dijk (AARC1)
AAI For Researchers Licia Florio AARC Project Coordinator GÉANT DI4R
AARC Blueprint Architecture and Pilots
WP 5 Shared Data Access & Enrichment
AAI Architectures – current and future
Common Solutions to Common Problems
Community AAI with Check-In
AAI in EGI Status and Evolution
FIM4R Requirements where GN3+ (SA5) is Active and Involved (9/2013)
Check-in Identity and Access Management solution that makes it easy to secure access to services and resources.
Umbrella ID Federated Identity for PaN facilities
Presentation transcript:

Case Studies in Federated Identity Management for Research Communities Ann Harding, SWITCH/GN3plus Peter Gietz, DAASI International GmbH/DARIAH Tommi Nyrönen, CSC - IT Center for Science/ELIXIR Mirjam van Daalen, Paul Scherrer Institute/Umbrella TNC 2014 20 May 2014 Dublin

Federated Identity Management for Research The Wizard Gap 30+ Research Infrastructures in Europe

Shared Challenges – FIM4R and TERENA AAA Study Attribute aggregation User friendliness Credential translation Scalable, flexible attribute release Levels of Assurance Homeless users Also Authorisation under community control, open standards, well defined, harmonised attributes Bridging Communities Non-web-browser

Collaborative pilots between user communities and GÉANT “A connected network of people, information, tools, and methodologies for investigating, exploring and supporting work across the broad spectrum of the digital humanities.” “Basic life science information constitutes a testament of human and natural evolution and advancement. As such, this wealth of knowledge should be freely available for all to access, study and process” “Umbrella is the Federated Identity Solution of the Photon and Neutron Community, enabling user initiated trans-facility access.” Goal – use these pilots to address issues from FIM4R for the benefit both of the individual communities and the wider community. Both geant and the communities invest significant time and effort.

DARIAH Goals Make DARIAH services available via eduGAIN Support digital humanities researchers Find and use a wide range of research data Work across domains and disciplines Experiment and innovate in collaboration with other scholars Make DARIAH services available via eduGAIN Encourage attribute release based on GÉANT Code of Conduct Group and attribute management integration with DARIAH-DE Textgrid Lab tools for scholarly digital editions

DARIAH Progress Distributing group and attribute management 5 DARIAH services in DFN AAI: Portals, search, wiki, collections, research tools Architecture based on standards interoperable with eduGAIN Support GÉANT Code of Conduct

DARIAH Experience eduGAIN is the best approach to pan European AAI for DARIAH Some time needed to fulfil all requirements DARIAH would like to see more entities available in eduGAIN And reasonable attributes available DARIAH has been able to meet many requirements Distributed user and privilege administration Policies that allow for integration into DFN-AAI and eduGAIN Combination of eduGAIN and community specific DARIAH homeless-IdP and attribute authority

ELIXIR distributed infrastructure ELIXIR Goals Research requiring AAI – Matching the treatment to the cancer One in 10 women in the EU-27 will develop breast cancer before the age of 80. If they can identify patterns of genes that are active in different tumours, we can diagnose and treat cancers earlier Pilot Goals: Requirements for Levels of Assurance Make EGA and REMS available on a pan-European basis via eduGAIN Part of a wider portfolio of ELIXIR AAI work ELIXIR distributed infrastructure

ELIXIR Progress Level of Assurance capabilities for European Identity Federations/IdPs vs. EGA’s security needs Use of GÉANT Data Protection Code of Conduct EGA SP registered to Haka (the Finnish Identity Federation). EGA SP exported to eduGAIN

ELIXIR Experience Next phase of AAI in ELIXIR – blueprint for discussion External IdPs via eduGAIN ELIXIR specific services for authorisation (REMS), non web, homeless users and community management Federated identity cross sector collaboration: REMS to be used by FI-CLARIN & FI-CESSDA A pan-European approach to LoA would be appreciated/necessary in the future Minimise ELIXIR-specific customisation

Swiss Light Source at Paul Scherrer Institute in Villigen Switzerland, Umbrella Goals Umbrella platform - a collaborative effort by leading European Photon and Neutron facilities as part of several EU projects Unique and persistent user identification for interdisciplinary user community from biology, physics to earth sciences Optimisation of the process from experimental data acquisition to data publication Bridging Home Institution Accounts with Umbrella persistent identities Enable Home Org identities to be used in Umbrella Enable Umbrella identities to access resources available via eduGAIN Non-web-browser based access Swiss Light Source at Paul Scherrer Institute in Villigen Switzerland, Six such facilities use Umbrella and serve over 30’000 users - 40% of these researchers use multiple facilities.

Umbrella Progress Next step – considerations for interfederation testing of Moonshot Moonshot pilot infrastructure for SSH Umbrella-eduGAIN Bridging prototype Considerations for usability in a production Umbrella context

Umbrella Experience More opportunities for NREN/Research Infrastructure Collaboration Security analysis discussion at FIM4R Piloting with a wider community has benefits JANET/Diamond Light in UK Moonshot Pilot Confidentiality aspects critical for Umbrella - high competition, especially structural biology Authorisation is delegated to the systems participating in Umbrella

GÉANT Goals Better Understanding = Better Services Collaborate with the wider GÉANT project and with international user communities to increase usage of AAI infrastructure. Act as an expert partner for large pan-European projects with AAI requirements. White paper “Options for Joining eduGAIN” Improved public documentation & knowledgebase Custom support for finding the best option Help you reach the right federation contacts In development – test IdP, plans for other services beyond basic eduGAIN

GÉANT Experience - What still needs work? Attributes - Release, consistency, community specific and harmonisation Levels of Assurance A long term issue to be broken down Understanding security and incident response Progress can be slow as we learn to work together More experience, work faster Non web Early pilot not novice user Many other research communities developing their AAI requirements and workplans

GÉANT Experience - where do we see progress? Sharing knowledge of federation capabilities Survey of Levels of Assurance Federations looking to do more Support of GÉANT Code of Conduct Emerging ‘opt-out’ pilots for eduGAIN REFEDs Federation Operator Best Practice Research communities services appearing in national federations and eduGAIN Knowledge gained with these pilots helps support other communities & plan service Ask us for help: edugain-integration@geant.net

Thank you Please join the BoF after today’s sessions!