Géant-TrustBroker Dynamic inter-federation identity management

Slides:



Advertisements
Similar presentations
Dorian Grid Identity Management and Federation Dialogue Workshop II Edinburgh, Scotland February 9-10, 2006 Stephen Langella Department.
Advertisements

Agenda Project beginnings and funding. Purpose of the federation. Federation members. Federation protocols. Special features in our federation. Pilot.
WebFTS as a first WLCG/HEP FIM pilot
SWITCHaai Team Federated Identity Management.
GakuNin Registration System Motonori Nakamura, NII Japan APAN33 rd Meeting (16 Feb. 2012)
Innovation through participation Interfederation through eduGAIN - steps and challenges eduGAIN interfederation service Federated Identity Systems.
Integrating with UCSF’s Shibboleth system
Shib-Grid Integrated Authorization (Shintau) George Inman (University of Kent) TF-EMC2 Meeting Prague, 5 th September 2007.
AAI-enabled VO Platform “VO without Tears” Christoph Witzig EGI TF, Amsterdam, Sept 15, 2010.
Belnet Federation Belnet – Loriau Nicolas Brussels – 12 th of June 2014.
Mellon Year 1 Review Michael J. Halm Alex Valentine.
The I-Trust Federation: Federating the University of Illinois Keith Wessel Identity Management Service Manager University of Illinois at Urbana-Champaign.
Serving society Stimulating innovation Supporting legislation Danny Vandenbroucke & Ann Crabbé KU Leuven (SADL) AAA-architecture for.
1 Schema Registries Steven Hughes, Lou Reich, Dan Crichton NASA 21 October 2015.
Social Identity Working Group Steve Carmody. Agenda Intro to Using Social Accounts Status and Recent News –Current UT Pilot –Current InCommon Pilot with.
Connect. Communicate. Collaborate Federation Interoperability Made Possible By Design: eduGAIN Diego R. Lopez (RedIRIS)
Using Enterprise Logins in Portal for ArcGIS via SAML Greg Ponto & Tom Shippee.
Technical Break-out group What are the biggest issues form past projects – need for education about standards and technologies to get everyone on the same.
Géant-TrustBroker project overview Slides assembled by the Géant-TrustBroker team at Leibniz Supercomputing Centre, Germany for a short presentation by.
INTRODUCTION: THE FIRST TRY InCommon eduGAIN Policy and Community Working Group.
Connect. Communicate. Collaborate AAI scenario: How AutoBAHN system will use the eduGAIN federation for Authentication and Authorization Simon Muyal,
Innovation through participation eduGAIN policy: A worm report TF-EMC2 Vienna Mikael Linden, CSC The worm farmer.
Authentication and Authorisation for Research and Collaboration Peter Solagna Milano, AARC General meeting Report and plans Attribute.
Authentication and Authorisation for Research and Collaboration Christos Kanellopoulos GRNET Proposed Pilots for Libraries and eGov.
Géant-TrustBroker Project Overview Daniela Pöhn 7 th FIM4R meeting Frascati, Italy April 24 th, 2014.
Connect. Communicate. Collaborate Deploying Authorization Mechanisms for Federated Services in the eduroam architecture (DAMe)* Antonio F. Gómez-Skarmeta.
Brown University Leveraging Social Identities Steve Carmody CSG, May 15, 2013.
Linus Joyeux Valerie Alonso Managing consultantLead consultant blue-infinity (Switzerland) Active Directory Federation Services v2.
INTRODUCTION: THE FIRST TRY InCommon eduGAIN Policy and Community Working Group.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Interoperability Shibboleth - gLite Christoph.
Federated Identity Fundamentals Ann Harding, SWITCH Cambridge July 2014.
Replace OpenText with Alfresco in a SAP environment
INTRODUCTION TO IDENTITY FEDERATIONS Heather Flanagan, NSRC.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI-InSPIRE PY5 new activities Peter Solagna – EGI.eu.
Project Moonshot Daniel Kouřil EGI Technical Forum
Networks ∙ Services ∙ People Licia Florio TNC, Lisbon Consuming identities across e- Infrastructures 16 June 2015 PDO GÈANT.
Adapting Webconference Cloud Services to R&E communities Session: Successful instantiations of cloud services Rui Ribeiro FCCN|FCT 21 May 2014.
Community Sign-On and BEN. Table of Contents  What is community sign-on?  Benefits  How it works (Shibboleth)  Shibboleth components  CSO workflow.
Authentication and Authorisation for Research and Collaboration Taipei - Taiwan Mechanisms of Interfederation 13th March 2016 Alessandra.
Géant-TrustBroker Dynamic inter-federation identity management Daniela Pöhn TNC2014 Dublin, Ireland May 19 th, 2014.
Access Policy - Federation March 23, 2016
WLCG Update Hannah Short, CERN Computer Security.
Applying eduGAIN to network operations The perfSONAR case
Cross-sector and user-centric AAI
LIGO Identity and Access Management
Shibboleth Roadmap
Federation Systems, ADFS, & Shibboleth 2.0
Overall Roadmap and Timeline
eduTEAMS platform for collaboration Niels Van Dijk
eduTEAMS – Current status & Future Plans
An authorization service for Virtual Organizations (VO)
University of Stuttgart University of Murcia
Identity Federations - Overview
Identity Management and Authorization
Scalability of trust and metadata exchange across federations
cNIS Update Anand Patil, DANTE NML-WG, Open Grid Forum 22,
GakuNin: Federated Identity Management Activities in Japan
Introduction How to combine and use services in different security domains? How to take into account privacy aspects? How to enable single sign on (SSO)
Identity Management and Authorization
Identity Management and Authorization
GÉANT project update eduTEAMS - AAI as a Service for Collaborative organisations Introduction Status Pilots New Features – input requested InAcademia –
GÉANT 4-2 JRA3 T1 and T2 Federations and Campus (CaFe) e-Infrastructures and Service Providers (RASP) Daniela Pöhn JRA3 T1 LRZ/DFN-AAI Technology Exchange.
Choosing the Discovery Model Martin Forsberg
ESA Single Sign On (SSO) and Federated Identity Management
EduTEAMS at a Glance Mandeep Saini Linz, Austria 30 May 2017.
Björn Erik Abt :: Paul Scherrer Institut
Example Use Case for Attribute Authorities and Token Translation Services - the case for eduGAIN Andrea Biancini.
GEANT Data protection Code of Conduct 2.0 REFEDS meeting 16 June 2019
eIDAS-enabled Student Mobility
Check-in Identity and Access Management solution that makes it easy to secure access to services and resources.
Presentation transcript:

Géant-TrustBroker Dynamic inter-federation identity management Daniela Pöhn TNC2014 Dublin, Ireland May 19th, 2014

Agenda Introduction Motivation GNTB Overview GNTB in Details Workflow Initiation of GNTB Workflow Metadata Registry Feature Attribute Repository Conclusion

GNTB Introduction Géant-TrustBroker (GNTB): Dynamic establishment of technical trust between Identity Provider (IDP) and Service Provider (SP) Dynamic metadata exchange First time contact initiated by the user GN3+ Open Call project (10/2013 – 03/2015) Internet-Draft to IETF in summer 2014 Shibboleth-based prototype

GNTB Motivation Current situation: Two types of federations: National federations operated by NRENs Community federations operated by research communities / projects Inter-federations, e.g., eduGAIN Source: eduGAIN membership status

GNTB Motivation The resulting problem: SP and the user’s IDP need to be in same federation or inter-federation. Communities need to participate in national federations or need to join eduGAIN as a federation. IDPs/SPs might need to join several federations. Research partners outside eduGAIN / national federation cannot make use of Federated Identity Management. Industry Employee No access German researcher Researcher Waiting 3 weeks IDP No trust SP Community DFN-AAI

GNTB Motivation Further Issues: Initial efforts Complexity: Additional contracts increase the overall complexity for IDPs and SPs. Manual work: IDPs need to set up configuration, e.g., attribute filters / release policies, manually.  Users may have to wait. Trust: IDPs have to trust SPs.  SPs may not get all required attributes. Limitation through schema: Inter-federation schema is only the common denominator of NREN federations.

Agenda Introduction Motivation GNTB Overview GNTB in Details Workflow Initiation of GNTB Workflow Metadata Registry Feature Attribute Repository Conclusion

GNTB Overview Our goal: SPs connected to user’s IDPs. Independent of federation borders. Dynamic establishing technical trust and automated configuration. Immediate access Configuration Researcher IDP Information about SP Metadata SP Community GÉANT- TrustBroker DFN-AAI

GNTB Overview Basic function: Automate established workflows No manual setup work for IDPs No waiting time for users Features: Attribute Conversion Rule Repository + Account Choosing Re-use of attribute conversion rules One rule for all Only needed: registration + plugin Complements existing approaches

Agenda Introduction Motivation GNTB Overview GNTB in Details Workflow Initiation of GNTB Workflow Metadata Registry Attribute Repository Conclusion

GNTB Workflow Researcher R wants to use a service at SP. R chooses his IDP at GNTB. a) R triggers the technical setup. b) SP has to register at GNTB. GNTB redirects R to his IDP for authentication. a) IDP fetches metadata of SP. b) Configuration is automatically updated. IDP looks for attribute conversion rules. IDP sends assertion to SP. R gets access to service at SP.   5   1   4b Researcher   2a   4a IDP   3   2b SP Community Géant- TrustBroker DFN-AAI

GNTB Initiation - Mockup User R wants to make use of a service. Since he cannot find his IDP in the list, he chooses GNTB.

GNTB Initiation - Mockup User R chooses his IDP at GNTB.

GNTB Initiation - Mockup User R is redirected to his IDP for authentication.

Agenda Introduction Motivation GNTB Overview GNTB in Details Workflow Initiation of GNTB Workflow Metadata Registry Attribute Repository Conclusion

GNTB Metadata Registry IDP/SP first needs to register at GNTB and install the plugin. Ownership and metadata are validated. Exchange of metadata on demand.  Automatically added to the local configuration.  Technical trust relationship established.

Agenda Introduction Motivation GNTB Overview GNTB in Details Workflow Initiation of GNTB Workflow Metadata Registry Attribute Repository Conclusion

GNTB Attribute Repository Typical conversion rules: Renaming: attribute is named differently, e.g., gecos  displayName Transforming: attribute transformed into another format, e.g., using yyyymmdd instead of dd.mm.yyyy Splitting / Merging: source attribute needs to be split by a regex, e.g., attribute role (“Administrator”) of a given DN entry “cn=Administrator, ou=Groups, ou=application, o=lrz, c=de” Merging two source attributes, e.g., givenName and surname, into a new one, e.g., commonName.

GNTB Attribute Repository Rules can be searched and re-used, e.g., within a federation Rules can be fetched by API calls by plugins Rule automatically added to local configuration Only one IDP has to create rule SPs receive all requested attributes Rules could be used by other services, e.g., Attribute Authorities use conv rule write conv rule IDP SP Géant- TrustBroker

GNTB Attribute Repository - Mockup Possible Administration Interface for managing conversion rules

GNTB Conclusion Advantages of GNTB: Metadata registry: SPs and IDPs can download metadata. User attribute conversion rule repository: IDPs can share and re-use conversion rules.  Reduces manual work of IDPs.  Conversion rules automated integrated into local configuration. Virtual IDP and SP: GNTB workflow seamlessly integrates into standard SAML workflows to “connect” SPs and IDPs on demand.  SPs / IDPs only need a plugin.

GNTB Conclusion Shibboleth-based prototype Further development of GNTB in GN4 Pilot operations hopefully start in GN4 What have we done so far: Workflows and Requirements Data Model and Data Access Layer Started with Protocols What we still need to do: Protocols Implementation Internet-Draft to IETF in summer 2014 Documentation

https://intranet.geant.net/JRA0/GEANT-TrustBroker For more details, please see the documents published on TrustBroker’s Géant Intranet website: https://intranet.geant.net/JRA0/GEANT-TrustBroker To contact the project team, please email geant-trustbroker@lists.lrz.de