The AARC Project Licia Florio (GÉANT) Christos Kanellopoulos (GRNET)

Slides:



Advertisements
Similar presentations
Federated Identity Management for Researchers – A quick overview from GÉANT BoF TNC May 2014 Dublin.
Advertisements

Federated Identity Management for Research Communities (FIM4R) David Kelsey (STFC-RAL) EGI TF, AAI workshop 19 Sep 2012.
BoF: Federated Identity Management for Researchers David Kelsey (STFC-RAL) TNC2014, Dublin 20 May 2014.
AARC Overview Licia Florio, David Groep 21 Jan 2015 presented by David Groep, Nikhef.
Federated Identity Management for HEP David Kelsey WLCG GDB 9 May 2012.
Updates Licia Florio, TERENA REFEDS Meeting 5 Sept 2012.
Authentication and Authorisation for Research and Collaboration Licia Florio (GÉANT) Christos Kanellopoulos (GRNET) Service orientation.
7 th FIM 4 R meeting April 2014 ESRIN Frascati.
Authentication and Authorisation for Research and Collaboration Licia Florio REFEDS Meeting The AARC Project I2 Technology Exchange.
Authentication and Authorisation for Research and Collaboration Licia Florio AARC Workshop The AARC Project Brussels, 26 October.
Authentication and Authorisation for Research and Collaboration Peter Solagna Milano, AARC General meeting Current status and plans.
JRA1.4 Models for implementing Attribute Providers and Token Translation Services Andrea Biancini.
Federated Identity Management for HEP David Kelsey HEPiX, IHEP Beijing 18 Oct 2012.
Authentication and Authorisation for Research and Collaboration Christos Kanellopoulos
Authentication and Authorisation for Research and Collaboration Christos Kanellopoulos Open Day Event: Towards the European Open.
Federated Identity Management for Scientific Collaborations The Common Vision David Kelsey (STFC) 3 Nov 2011.
Networks ∙ Services ∙ People Thomas Bärecke Journée Fédération, Paris Collaboration européenne GÉANT SA5 03/07/2015 SA5 T5 team
Research Community Requirements Ann Harding, SWITCH Cambridge July 2014.
Networks ∙ Services ∙ People Ann Harding GÉANT Symposium, Vienna Users Session A3 Trust and Identity March GÉANT Activity Leader Trust.
Authentication and Authorisation for Research and Collaboration Taipei Taiwan Authentication and Authorisation for Research and.
Authentication and Authorisation for Research and Collaboration Licia Florio REFEDS Meeting AARC and AARC2 Vienna, 1 st December.
David Groep Nikhef Amsterdam PDP programme Authentication and Authorization for Research and Collaboration David Groep, Nikhef with materials gratefully.
Connect communicate collaborate Case Studies in Federated Identity Management for Research Communities Ann Harding, SWITCH/GN3plus Peter Gietz, DAASI International.
David Groep Nikhef Amsterdam PDP & Grid AARC Authentication and Authorisation for Research and Collaboration an impression of the road ahead.
Networks ∙ Services ∙ People Licia Florio TNC, Lisbon Consuming identities across e- Infrastructures 16 June 2015 PDO GÈANT.
Authentication and Authorisation for Research and Collaboration Licia Florio AARC CORBEL Workshop The AARC Project Paris, 31 May.
Authentication and Authorisation for Research and Collaboration Christos Kanellopoulos David Groep 9 th FIM4R Meeting The AARC Project.
Authentication and Authorisation for Research and Collaboration Licia Florio AARC f-2-f Meeting One Year of AARC Utrecht, 24 May.
Authentication and Authorisation for Research and Collaboration AARC/CORBEL Workshop for Life Sciences AAI AARC Draft Blueprint.
Authentication and Authorisation for Research and Collaboration Brussels Training and Outreach Authentication and Authorisation.
Authentication and Authorisation for Research and Collaboration Licia Florio IGTF Meeting The AARC Project Amsterdam, 8 September.
Authentication and Authorisation for Research and Collaboration On behalf of the MJRA1.2 scribes J Jensen.
Security in the wider world David Kelsey (STFC-RAL) GridPP37 – Ambleside 2 Sep 2016.
SCI & Sirtfi David Kelsey (STFC-RAL) EGI Conference, Lisbon 19 May 2015.
Introduction to AAI Services
WLCG Update Hannah Short, CERN Computer Security.
Boosting AAI for research and collaboration
RCauth.eu CILogon-like service in EGI and the EOSC
Authentication and Authorisation for Research and Collaboration
The Policy Puzzle Many groups and (proposed) policies, but leaving many open issues AARC “NA3” is tackling a sub-set of these “Levels of Assurance” –
EGI Updates Check-in Matthew Viljoen – EGI Foundation
AARC Update What’s been happening in AARC which matters for GÉANT
User Community Driven Development in Trust and Identity
eduTEAMS – Current status & Future Plans
Wrap up Licia Florio AARC Coordinator
Case Studies in Federated Identity Management for Research Communities
Identity Management and Authorization
Christos Kanellopoulos
AARC Strategy and Approach
Federated Identity Management for Researchers (FIM4R)
An AAI solution for collaborations at scale
Boosting AAI for research and collaboration
Updates on Training Andrea Biancini (AARC2.AHM)2 NA2 WP leader
Federated Identity Management for Scientific Collaborations
The AARC Project Licia Florio AARC Coordinator GÉANT
Minimal Level of Assurance (LoA)
Identity Management and Authorization
Policy in harmony: our best practice
Policy and Best Practice … in practice
Pilots in AARC Arnout Terpstra (AARC2) / Paul van Dijk (AARC1)
AAI For Researchers Licia Florio AARC Project Coordinator GÉANT DI4R
AARC Blueprint Architecture and Pilots
Supporting communities with harmonized policy
AAI Architectures – current and future
RCauth.eu CILogon-like service in EGI and the EOSC
Community AAI with Check-In
Community Engagement & Competence Centre
Liaisioning with other projects and partners
FIM4R Requirements where GN3+ (SA5) is Active and Involved (9/2013)
Check-in Identity and Access Management solution that makes it easy to secure access to services and resources.
Presentation transcript:

The AARC Project Licia Florio (GÉANT) Christos Kanellopoulos (GRNET) Service orientation to data and high-performance computing infrastructures Paris, 22 September 2015

Authentication and Authorisation for Research and Collaboration AARC Facts Authentication and Authorisation for Research and Collaboration Two-year EC-funded project 20 partners NRENs, e-Infrastructure providers and Libraries as equal partners About 3M euro budget Starting date 1st May, 2015 https://aarc-project.eu/

AARC Vision and Objectives Avoid a future in which new research collaborations develop independent AAIs Impacts Create a cross-e-infrastructure ‘network’ for identities Reduce duplication of efforts in the service delivery Improve the penetration of federated access Outputs Design of integrated AAI built on federated access Harmonised policies to easy cross-discipline collaboration Pilot selected use-cases Offer a diversified training package

Design an integrated AAI built on production infrastructures Approach Integration, policy harmonisation, piloting and training Design an integrated AAI built on production infrastructures Use existing e-infrastructures in the delivery chain Work with e-infras and user communities to solve existing challenges, pilot use-cases and get feedback on the results

AARC Work areas

First Results

Repackage and add what is missing Training and Outreach Requirements & existing material - - Value proposition - Federation 101 - Training for SPs - Training on AARC results Repackage and add what is missing First document describing the approach to the training: https://aarc-project.eu/documents/milestones/ Report on the identified target groups for training and their requirements https://aarc-project.eu/wp-content/uploads/2015/04/AARC-DNA2.1.pdf End of the month the first online module on federated access

Policy and Best Practices Harmonisation Security Incident on FIM To agree on a generic security incident response procedure for federations Sirtfi Trust Framework to be finalised at the next I2 Tech Exc Sirtfi WG: https://wiki.refeds.org/display/GROUPS/ SIRTFI LoA work To agree on a sustainable LoA framework AARC (through surveys and FIM4R) looking at immediate and longer-term need by SPs and RPs: https://wiki.geant.org/display/AARC/LoA+ survey+for+SP+communities Key challenge is cost of operation, and who bears this costs R&E federations and their IdPs looking at the ‘service aspect’ of providing assurance

Architecture Design Analysis of requirements Analysis of AA technologies Guest Identities Attribute Authorities – Token Translation Blueprint Architecture Sep15 Dec15 Apr15 Apr17 Jul16

Architecture Design – Analysis of requirements Past Activities FIM4R & TERENA AAA Study AARC Surveys BioVel, CLARIN, D4Science, DARIAH, EISCAT, EUDAT, FMI, PSNC, UMBRELLA, … AARC Requirement Analysis (available end of Sept.) AARC Interviews EGI, ELIXIR, EUDAT, GN4, LIBRARIES (UKB), …

Architecture Design – Analysis of requirements User Friendliness Homeless Users Different Levels of Assurance Community based authorization Flexible and scalable attribute release policies Attribute Aggregation & Account Linking Federation solutions based on open and standards based technologies Persistent & Unique User Identifiers User managed Identity Information Up to date identity information User groups and roles Step up authentication Browser and non-browser based federated access Delegation Social media identities Integration with e-Government infrastructures Service Provider Friendliness Effective Accounting Policy Harmonization Federated Incident report Handling Sufficient Attribute release Awareness about R&E Federations Semantically harmonized identity attributes Simplified process for joining identity federation Best practices for terms and conditions

Architecture Design – Analysis of requirements User Friendliness Homeless Users Different Levels of Assurance Community based authorization Flexible and scalable attribute release policies Attribute Aggregation & Account Linking Federation solutions based on open and standards based technologies Persistent & Unique User Identifiers User managed Identity Information Up to date identity information User groups and roles Step up authentication Browser and non-browser based federated access Delegation Social media identities Integration with e-Government infrastructures Effective Accounting Policy Harmonization Federated Incident report Handling Sufficient Attribute release Awareness about R&E Federations Semantically harmonized identity attributes Simplified process for joining identity federation Service Provider Friendliness Best practices for terms and conditions

Architecture Design – Next steps Continue the interviews with the AARC stakeholders and the parallel work on Guest Identities and Attribute Authorities (AA) & Token Translation Services (TTS) End of October first internal draft release of AARC High Level Architecture End of December: Analysis of available AA technologies January – February: Consultation with stakeholders around the AARC High Level Architecture Arpil: Release work on Guest Identities , AAs and TTS July: 1st version of the AARC AAI Architecture Framework

Licia.Florio@geant.org