Trust & Identity Whitepaper

Slides:



Advertisements
Similar presentations
Creating a Secured and Trusted Information Sphere in Different Markets Giuseppe Contino.
Advertisements

FIM-ig Federated Identity Management Interest Group.
AARC Overview Licia Florio, David Groep 21 Jan 2015 presented by David Groep, Nikhef.
Authentication and Authorisation for Research and Collaboration Licia Florio (GÉANT) Christos Kanellopoulos (GRNET) Service orientation.
NMI End-to-End Diagnostic Advisory Group BoF Fall 2003 Internet2 Member Meeting.
Authentication and Authorisation for Research and Collaboration Licia Florio REFEDS Meeting The AARC Project I2 Technology Exchange.
Authentication and Authorisation for Research and Collaboration Licia Florio AARC Workshop The AARC Project Brussels, 26 October.
NREN Trust and Identity Strategy Ann Harding, SWITCH Cambridge July 2014.
Networks ∙ Services ∙ People Thomas Bärecke Journée Fédération, Paris Collaboration européenne GÉANT SA5 03/07/2015 SA5 T5 team
Connect communicate collaborate Trust & Identity EC meets GÉANT 19 June 2014 Brussels Valter Nordh, NORDUnet Federation as a Service Task Leader Trust.
Networks ∙ Services ∙ People Marina Adomeit FIM4R meeting Virtual Organisation Platform as a Service VOPaaS Nov 30, 2015, Austria Task Leader,
Networks ∙ Services ∙ People Ann Harding eduGAIN Town Hall eduGAIN in the GÉANT Project Activity Leader GÉANT Trust and Identity.
Networks ∙ Services ∙ People Ann Harding GÉANT Symposium, Vienna Users Session A3 Trust and Identity March GÉANT Activity Leader Trust.
Networks ∙ Services ∙ People Ann Harding + Marina Adomeit GÉANT Symposium 2016 What’s changed, what stays the same? Project future - services.
Authentication and Authorisation for Research and Collaboration Licia Florio REFEDS Meeting AARC and AARC2 Vienna, 1 st December.
Networks ∙ Services ∙ People Licia Florio TNC, Lisbon Consuming identities across e- Infrastructures 16 June 2015 PDO GÈANT.
Authentication and Authorisation for Research and Collaboration Licia Florio AARC CORBEL Workshop The AARC Project Paris, 31 May.
THE VALUE PROPOSITION FOR IDENTITY FEDERATIONS APAN 41 – TF-IAM 27 January 2016.
Networks ∙ Services ∙ People Marina Adomeit TNC16 Conference, Prague Towards a platform for supporting collaboration GÉANT VOPaaS
International Planetary Data Alliance Registry Project Update September 16, 2011.
Authentication and Authorisation for Research and Collaboration Taipei - Taiwan Mechanisms of Interfederation 13th March 2016 Alessandra.
Networks ∙ Services ∙ People Marina Adomeit JRA3 kick off SA2 in GN July, Zürich SA2 Activity leader.
Authentication and Authorisation for Research and Collaboration Licia Florio IGTF Meeting The AARC Project Amsterdam, 8 September.
Networks ∙ Services ∙ People Nicole Harris and Licia Florio 30 th September 2015 Building the Greenhouse Amsterdam Project Development Officers.
Networks ∙ Services ∙ People Di4R Network. Services. People. GÉANT 28 th September, Krakow.
IT Service Transition – purpose and processes
Cross-sector and user-centric AAI
The Policy Puzzle Many groups and (proposed) policies, but leaving many open issues AARC “NA3” is tackling a sub-set of these “Levels of Assurance” –
Campus IdP Status and plans GARR Mario Reale
AARC Update What’s been happening in AARC which matters for GÉANT
Project Cycle Management
User Community Driven Development in Trust and Identity
EOSC MODEL Pasquale Pagano CNR - ISTI
eduTEAMS platform for collaboration Niels Van Dijk
eduTEAMS – Current status & Future Plans
Integrated Management System and Certification
Ian Bird GDB Meeting CERN 9 September 2003
Identity Management and Authorization
InCommon Steward Program: Community Review
Summit 2017 Breakout Group 2: Data Management (DM)
Trilateral Research EUROPEAN COMMISSION
Federated Identity Management for Researchers (FIM4R)
GÉANT 4-2 JRA3 T1 Something with Federations and Campus VC
CLARIN Federated Identity Vision
Head Statistics and Data Unit
OmniRAN Introduction and Way Forward
Neil Witheridge’s slides
SIP Report – Nov 2017 Overview Headlines Workstream report
The AARC Project Licia Florio (GÉANT) Christos Kanellopoulos (GRNET)
The AARC Project Licia Florio AARC Coordinator GÉANT
C2CAMP (A Working Title)
GÉANT 4-2 JRA3 T1 and T2 Federations and Campus (CaFe) e-Infrastructures and Service Providers (RASP) Daniela Pöhn JRA3 T1 LRZ/DFN-AAI Technology Exchange.
President’s Administrative Innovation Fund: Connecting IT Subject Matter Expertise CIO Council Update
Solutions for federated services management EGI
Policy in harmony: our best practice
ESA Single Sign On (SSO) and Federated Identity Management
Sustainability and Operational models
Policy and Best Practice … in practice
GlobAL Public Procurement Conference September 2018
AARC Blueprint Architecture and Pilots
Enterprise Program Management Office
Björn Erik Abt :: Paul Scherrer Institut
Statistical Information Technology
OmniRAN Introduction and Way Forward
Agenda Purpose for Project Goals & Objectives Project Process & Status Common Themes Outcomes & Deliverables Next steps.
Baseline Expectations for Trust in Federation
Executive Project Kickoff
eIDAS-enabled Student Mobility
Task Force Peer reviews and quality Eurostat
Check-in Identity and Access Management solution that makes it easy to secure access to services and resources.
Presentation transcript:

Trust & Identity Whitepaper Ann Harding, Nicole Harris, Marina Adomeit, Licia Florio, Klaas Wierenga T&I Meeting, Amsterdam 7/12/2017

Timeline for GN4-3 submission Find out what we want to do … - Dec 2017 Get NRENs feedback + NIFs for missing ideas Jan-Feb 2018 Select the GN4-3 project elements Mar 2018 Write the Work Packages Apr – Jul 2018 Finalise – Submit GN4-3 Sep – Oct 2018 White Papers phase (Sep 2017 – Feb 2018) Write White papers, incorporating input from user requirements gathering using PLM, Quality Control and NRENs’ review NRENs will provide feedback to white papers mid Jan 2018 – Feb 2018 + NIFs if something is missing the body of each White Paper will be max 10 pages & that the assessment process will be based on short templates giving a general roadmap, budget and milestones Selection of project elements phase (Mar – Apr 2018) Assess the contents of the White papers taking into account the feedback from the NRENs, based on NRENs’ levels of interest Detailed GN4-3 Planning, Budgeting & Recruitment phase (May – July 2018) GN4-3 Proposal writing & Submission phase (July – September 2018, to be submitted Q3 2018) 5

Topic areas and main editors for initial White paper phase White Papers 1. Network Network Architectures & Services and Tools (including global connectivity & multi-domain services/ network monitoring, management and performance verification) Editors: Shaun Cairns, Ivana Golub, Afrodite Sevasti 2. Security & Privacy Editors: Sigita Jurkynaite, Alf Moens, Steve Kennett 3. Trust & Identity Editors: Klaas Wierenga, Ann Harding, Licia Florio, Nicole Harris 4. Application Services and Clouds Editors: Andres Steijaert, Peter Szegedi 5. General services Part A: Software development Editors: Marcin Wolski Part B: Operations ( i.e. general first line support), procurement, PLM, Legal, IPR, Project Management Editors: Toby Rodwell, Paul Rouse, Marina Adomeit 6. User, Community, Outreach (incl. open calls, other e-infrastructures) and Human Capital Development Editors: Cathrin Stover, Annabel Grant 7

Trust and Identity White Paper High-level Areas Consultation Plans eduGAIN Operations  eduGAIN Core Operations  Discovery  eduGAIN Maturity  eduGAIN Disruptive OIDC  Evolution of metadata Management  eIDAS  Above and below eduGAIN  eduTEAMS Service Delivery, Operations and Continuous Service Improvements  inAcademia - Business Process development & transition to service Federation as a Service - Service Delivery, refocus, integration of campus IdP Step-up Authentication and Identity Assurance  eduroam  Certificates  Fundamental infrastructure Carried out so far Post-it exercise at Symposium. RDA workshop eduGAIN & eduroam SG calls for ideas Session(s) at Internet2 Technology Exchange. AARC Meeting. DI4R / FIM4R. Pending Consolidation at T&I leaders meeting. eduGAIN TownHall / REFEDS meeting. Final editors meeting (December). (links in whitepaper)

eduGAIN Operations

eduGAIN Operations

eduGAIN Maturity Response Testing for Security Contacts. Developing the eduGAIN technical database further to flag maturity for federations / entities based on the eduGAIN Best Current Practice documentation. Working with external registries (such as a PEER registry?) for community-based aggregates. Developing processes to allow MDS to select the most mature entity formulation within federations rather than simply the first submitted. Working with eduGAIN on flagged errors and warnings. Standardise metadata registration and publication across eduGAIN federations. Service Catalogue.  

eduGAIN Maturity

eduGAIN Disruptive Why? ID Feds/eduGAIN work but: Attribute release is still problematic Federated access for non-web services not really solved Metadata mng could be more dynamic eIDAS – promise to deliver eIDS to all EU member states by mid 2019 Why running an IdP if institutions can use gov eIDs? OIDC is already the preferred choice for services: ID Fed are/will implement interface for it Expected to handle metadata more efficiently

eduGAIN Disruptive What ? What’s the impact on eduGAIN ? If IdPs become attr prov, how do we discover them? MDQ not sufficiently mature yet – will it be mature by mid 2019? OIDC we need to turn it into an opportunity to gain more services that are no in eduGAIN to date.

eduGAIN Disruptive What

Above and below eduGAIN Why? eduGAIN speaks for itself But it is not one of these To participate, some infrastructure is needed Federation Campus Sometimes eduGAIN is not enough Additional sources of attributes Groups Assurance Sometimes eduGAIN is too much Only want validation

Above and below eduGAIN What?

Above and below eduGAIN eduroam Why Continue to improve the service. Address problems with adoption: End-users (small) IdPs SPs Deal with emerging WiFi deployments City WiFi govroam Hotspot 2.0

Above and below eduGAIN What?

Certificates Why? We do need certificates/PKI for nearly everything GÉANT/NRENs offer certificates services for years TCS, eduPKI, ettc New technologies and pilots/services: Certificate transparencies Certbot/Let’s Encrypt, letsradsec Shouldn’t we consider this area in a more strategic way? Only want validation

Certificates What

Certificates Proposal Operations of existing services Y1- Y4 Formulation of strategy Y1 Complete/support completion of transition to service of letsrasec and certificate transparency Y1-2 Y2-4 Implement any changes in existing portfolio based on outcome of strategy. Can we formulate the strategy in 2018? Create a task-force Use the result to inform the work in GN4-3

Fundamental infrastructure Why? Portfolio of T&I services is expanding to a point where establishing a set of internal core services to support the IT operations control is a necessity Benefits of this approach are: Strengthens the service ownership by fostering the operational practices across different service operators and makes services more manageable. Lowers the burden on the service operational teams Enables the harmonisation and unification of services operations. Potential savings on the operational costs by grouping the common functions.

Fundamental infrastructure What? Resource inventory – the master repository with basic data about all infrastructure and resources used for services delivery Platform for service monitoring -  provide basic monitoring of availability and performance parameters, provides alerting function, collects history data necessary for reports and capacity management Centralized logging targets - similar, have insight. This is more proactive rather than reactive. Solution for backup & restore and archive – enhances the reliability of the services and underpins the SLA and OLA Service Desk and ticketing system -  support the common requirements for first level support for services; Source code repository (non-public and public) – stores the operational data such as configurations, scripts, deployment automation recipes etc. PKI requirements - includes eduPKI which should be rebranded as internal supporting service (mostly for eduroam now) Key signing requirements -  investigate the common requirements of FaaS, eduGAIN, Managed eduroam IdP VMs –arrange the virtual machines for operating services in production and pilot.