GakuNin: Federated Identity Management Activities in Japan

Slides:



Advertisements
Similar presentations
eduroam Delegate Authentication System with Shibboleth SSO
Advertisements

Lousy Introduction into SWITCHaai
Eduserv Athens Federations David Orrell Eduserv Athens Technical Architect.
Access & Identity Management “An integrated set of policies, processes and systems that allow an enterprise to facilitate and control access to online.
EduPerson and Federated K-12 Activities InCommon/Quilts Pilot Group February 27, 2014 Keith Hazelton UW-Madison, InCommon/I2.
Update of Japanese Academic Access Management Federation GakuNin in 2011 Nakamura, M, Yamaji, K.
Introduction to Identity Management Federation Kazu Yamaji, National Institute of Informatics, Japan.
2006 © SWITCH Authentication and Authorization Infrastructures in e-Science (and the role of NRENs) Christoph Witzig SWITCH e-IRG, Helsinki, Oct 4, 2006.
1 Issues in federated identity management Sandy Shaw EDINA IASSIST May 2005, Edinburgh.
Federation of Campus PKI and Grid PKI for Academic GOC Management Conformable to APGrid PMA National Institute of Informatics, JAPAN Toshiyuki Kataoka,
16/3/2015 META ACCESS MANAGEMENT SYSTEM Implementing Authorised Access Dr. Erik Vullings MAMS Programme Manager
Innovation through participation eduGAIN federation operator training eduGAIN policy eduGAIN training in Vienna Oct 2011
Federated Identity, Levels of Assurance, and the InCommon Silver Certification Jim Green Identity Management Academic Technology Services © Michigan State.
Information Resources and Communications University of California, Office of the President UCTrust Implementation Experiences David Walker, UCOP Albert.
NJVid New Jersey Video Portal 1 Grant partners. NJVid New Jersey Video Portal 2 NJTrust - New Jersey Identity Trust Federation NJViD Advisory Board Meeting.
FIM-ig Federated Identity Management Interest Group.
AAI with simpleSAMLphp
InCommon Michigan State Common Solutions Group, January 2011 Matt Kolb
Federated Identity Management in New Zealand Sat Mandri Service Manager TNC15 REFEDs Meeting, 14 th June 2015.
GakuNin Registration System Motonori Nakamura, NII Japan APAN33 rd Meeting (16 Feb. 2012)
Australian Access Federation Robert Hazeltine Identity and Access Management Enterprise Systems Office.
The InCommon Federation The U.S. Access and Identity Management Federation
FIM-related activities and issues being discussed in Japan 1.GEO Grid Yoshio Tanaka (AIST) 2.HPCI, GakuNin Eisaku Sakane, Kento Aida (NII)
Copyright JNT Association 2005Copyright JNT Association An Introduction to Access Management and the UK Federation Simon Cooper.
Internet2 – InCommon and Box Marla Meehl Colorado CIO 11/1/11.
TEIN Shibboleth Training Course Introduction to SAML/Shibboleth at ComLabs USDI ITB, (updated version)
ADFS in the U.T. System U.S. Federations Call - May 18, 2011 Paul Caskey System-wide Information Services.
IDENTITY ASSURANCE PROFILES AND FRAMEWORK DOCUMENTS: PEEK INTO PROPOSED FICAM CHANGES 12/12/12 1.
Belnet Federation Belnet – Loriau Nicolas Brussels – 12 th of June 2014.
Stuff, including interfederation stuff Dr Ken Klingenstein, Director, Middleware and Security, Internet2.
Michael Ghens Information Systems Specialist Santa Barbara City College.
The UK Access Management Federation for education and research John Chapman, Project Adviser, Technical Policy & Standards.
Kalmar Union, a Conferedation of Nordic Identity Federations TNC2009 Mikael Linden, CSC Andreas Solberg, UNINETT.
Social Identity Working Group Steve Carmody. Agenda Intro to Using Social Accounts Status and Recent News –Current UT Pilot –Current InCommon Pilot with.
Outsourcing Student at USC Institute for Computer Policy and Law Cornell University, August 2008 Asbed Bedrossian Director of Enterprise Applications.
Kalmar Union lessons: Findings in federation harmonisation REFEDS Mikael Linden, CSC.
Federations round table Haka federation of Finland EuroCAMP Mikael Linden CSC, the Finnish IT Center for Science.
INTRODUCTION: THE FIRST TRY InCommon eduGAIN Policy and Community Working Group.
Overview of schemas used for IdM community Setting up of identity provider Motonori Nakamura, National Institute of Informatics, Japan 2nd TEIN IAM Workshop.
1 UPKI-Federation based on Shibboleth National Institute of Informatics Motonori Nakamura Toshiyuki Kataoka, Kyoto University Yasuo Okabe.
Innovation through participation eduGAIN interfederation service for research and education Cern FedID workshop in RAL, UK 2-3 Nov 2011 Mikael Linden,
Community Sign-On and BEN. Table of Contents  What is community sign-on?  Benefits  How it works (Shibboleth)  Shibboleth components  CSO workflow.
Test your IdP
Connect. Communicate. Collaborate AAI scenario: How AutoBAHN system will use the eduGAIN federation for Authentication and Authorization Simon Muyal,
Innovation through participation eduGAIN policy: A worm report TF-EMC2 Vienna Mikael Linden, CSC The worm farmer.
AuEduPerson Schema Schema Derived from: - eduPerson - person [RFC 4517, RFC 4519] - organizationalPerson [RFC 4517, RFC 4519] - inetOrgPerson [RFC 2798]
The UK Access Management Federation John Chapman Project Adviser – Becta.
Géant-TrustBroker Project Overview Daniela Pöhn 7 th FIM4R meeting Frascati, Italy April 24 th, 2014.
Brown University Leveraging Social Identities Steve Carmody CSG, May 15, 2013.
INTRODUCTION: THE FIRST TRY InCommon eduGAIN Policy and Community Working Group.
Connect communicate collaborate Trust & Identity EC meets GÉANT 19 June 2014 Brussels Valter Nordh, NORDUnet Federation as a Service Task Leader Trust.
Identities and Azure AD Premium
Introduction to Shibboleth Attribute Delivery for Campuses New to Shibboleth Paul Caskey The University of Texas System.
Leveraging Campus Authentication to Access the TeraGrid Scott Lathrop, Argonne National Lab Tom Barton, U Chicago.
Community Sign-On and BEN. Table of Contents  What is community sign-on?  Benefits  How it works (Shibboleth)  Shibboleth components  CSO workflow.
Authentication and Authorisation for Research and Collaboration Taipei - Taiwan Mechanisms of Interfederation 13th March 2016 Alessandra.
Géant-TrustBroker Dynamic inter-federation identity management Daniela Pöhn TNC2014 Dublin, Ireland May 19 th, 2014.
The IGTF to eduGAIN Bridge
Shibboleth Architecture
Federation made simple
University of Texas System
Géant-TrustBroker Dynamic inter-federation identity management
John O’Keefe Director of Academic Technology & Network Services
Scalability of trust and metadata exchange across federations
GÉANT project update eduTEAMS - AAI as a Service for Collaborative organisations Introduction Status Pilots New Features – input requested InAcademia –
Shibboleth Implementation in EZproxy
Identity Management: Shibboleth Activity Update
Federations: Introduction Justin Knight, Jisc
Verifying student status with
REFEDS Assurance Suite
Presentation transcript:

GakuNin: Federated Identity Management Activities in Japan Takeshi Nishimura/Academic Authentication Systems Office National Institute of Informatics

Most of Major Publishers 2009/8/5 An Academic Identity Federation in Japan Build up new ICT infrastructure to support R&E based on SSO technologies Provides trust framework (technologies, policies and assessment) Towards value added services (academic discount, etc.) by collaboration with commercial Improves usability and security with continuous R&D (including multifactor/cert. auth.) Lib Services Web mail Groupware E-Learning SP Univ. A Univ. B Univ. C IdP GakuNinSteering Committee Federation Policy IdP Auditing Promotion Faculty Staff Student Inter University Unified Campus Auth Identity Provider Service Attributes E-Journals Privacy-Preserved Info. Web Site Registration Sys. Metadata Repo. Discovery Service Easy Access from out of Campus Seamless access with SSO Reduction of ID management cost, Improvement of security Academic Federations have been established per country basis Content Services Application Services Admin Services eLearning ePortfolio Most of Major Publishers 2 Foodle

Number of IdPs/SPs (As of Oct. 2017) #IdP Users #SPs 200 M Users 1.42M 153 pilot Production Japanese total HE population is about 3.7million National Public Private Junior College Tech. College Inter-Univ. Institute Other Total Participants 67 17 54 51 1 10 200 Ratio 78% 19% 9% 0% 89% # Total 86 91 600 343 57

History of GakuNin ID Federation 2008 Feasibility Study with test accounts Participants: 30 IdP sites and 18 SP sites (incl. Elsevier) 2009 Pilot Operation (UPKI-Fed) with real accounts and services Preparation of policy documents 2010 Production Operation started (As a 3 years project) Renamed as “GakuNin” 2012 US FICAM LoA-1 assessment for requested IdPs started by cooperation with OIX (Open Identity eXchange); (switched to Kantara in 2015) 2014 Shifted to an official service by NII Still no fee is required to join

Attributes 2010- 2014 2017 jasn jaGivenName mail jaDisplayName sn jao ou givenName displayName eduPersonAffiliation eduPersonPrincipalName eduPersonEntitlement eduPersonScopedAffiliation eduPersonTargetedID jasn jaGivenName jaDisplayName jao jaou 2014 isMemberOf gakuninScopedPersonalUniqueCode 2017 eduPersonAssurance eduPersonUniqueId eduPersonOrcid

GakuNin enquete (questionnaire) Annual self-audit for IdPs Our rules Operating Policies for GakuNin Participants System Administration Standards for the GakuNin Based on answers, GakuNin asserts grade A & B.

2009/8/5 eduGAIN as you know

GakuNin with eduGAIN GakuNin joined eduGAIN in 2013. With slight update of our rules Our IdPs/SPs joins eduGAIN by opt-in basis (still) We are preparing metadata two times per month.

Our motivation for eduGAIN Formerly, e-Journals Currently, ORCID

Current issues about eduGAIN Building filter settings for Shibboleth IdP How to provide Discovery Service for eduGAIN IdPs Are there Open IdPs in eduGAIN? <afp:AttributeFilterPolicy id="PolicyforCUP" xmlns:afp="urn:mace:shibboleth:2.0:afp"> <afp:PolicyRequirementRule xsi:type="basic:AttributeRequesterString" value="https://shibboleth.cambridge.org/shibboleth-sp" /> <afp:AttributeRule attributeID="eduPersonScopedAffiliation"> <afp:PermitValueRule xsi:type="basic:ANY" /> </afp:AttributeRule> </afp:AttributeFilterPolicy>