Update of Japanese Academic Access Management Federation GakuNin in 2011 Nakamura, M, Yamaji, K.

Slides:



Advertisements
Similar presentations
Substantive Change Requesting Commission Approval of Substantive Changes at Institutions MSCHE Annual Meeting December 2009.
Advertisements

Identity Network Ideals – Heterogeneity & Co-existence
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
Access & Identity Management “An integrated set of policies, processes and systems that allow an enterprise to facilitate and control access to online.
Authentication solutions for Outlook and Office 365 Multi-factor authentication for Office 365 Outlook client futures.
Cross Sector Digital Identity Initiative March 12, 2014 Hearing on the National Strategy for Trusted Identities in Cyberspace (NSTIC) Cross Sector Digital.
Federated Identity Management for Research Communities (FIM4R) David Kelsey (STFC-RAL) EGI TF, AAI workshop 19 Sep 2012.
1 Issues in federated identity management Sandy Shaw EDINA IASSIST May 2005, Edinburgh.
Beispielbild Shibboleth, a potential security framework for EDIT Lutz Suhrbier AG Netzbasierte Informationssysteme (
© 2009 The MITRE Corporation. All rights Reserved. April 28, 2009 MITRE Public Release Statement Case Number Norman F. Brickman, Roger.
Information Resources and Communications University of California, Office of the President Current Identity Management Initiatives at UC & Beyond: UCTrust.
Information Resources and Communications University of California, Office of the President UCTrust Implementation Experiences David Walker, UCOP Albert.
Shibboleth & IMPETUS 1.What are they? 2.Demo. Shibboleth - A system to support the sharing of Web resources among organisations IMPETUS - Infrastructure.
NJVid New Jersey Video Portal 1 Grant partners. NJVid New Jersey Video Portal 2 NJTrust - New Jersey Identity Trust Federation NJViD Advisory Board Meeting.
NIH iTrust Peter Alterman/Debbie Bucci National Institutes of Health October 2010.
Development and Implementation of Multifactor Authentication Motonori Nakamura at National Institute of Informatics and Takuya Matsuhira at Kanazawa University,
WebFTS as a first WLCG/HEP FIM pilot
Shibboleth and InCommon Copyright Texas A&M University This work is the intellectual property of the author. Permission is granted for this material.
Credential Provider Operational Practices Statement CAMP Shibboleth June 29, 2004 David Wasley.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
GakuNin Registration System Motonori Nakamura, NII Japan APAN33 rd Meeting (16 Feb. 2012)
Identity Management in Education. Welcome Scott Johnson, NetProf, Inc. Creator of OmnID Identity Management for Education
Identity Management Report By Jean Carreon and Marlon Gonzales.
FIM-related activities and issues being discussed in Japan 1.GEO Grid Yoshio Tanaka (AIST) 2.HPCI, GakuNin Eisaku Sakane, Kento Aida (NII)
Copyright JNT Association 2005Copyright JNT Association An Introduction to Access Management and the UK Federation Simon Cooper.
SAML Right Here, Right Now Hal Lockhart September 25, 2012.
Federated Identity Management for HEP David Kelsey WLCG GDB 9 May 2012.
·
2005 © SWITCH Perspectives of Integrating AAI with Grid in EGEE-2 Christoph Witzig Amsterdam, October 17, 2005.
An XML based Security Assertion Markup Language
Kerberos and Identity Federations Daniel Kouřil, Luděk Matyska, Michal Procházka, Tomáš Kubina AFS & Kerberos Best Practices Worshop 2008.
Edugate Glenn Wearen HEAnet.. Summary 1 year Pilot Project / 2 years in production All IoT’s, Universities, Colleges, but only half of HEAnet’s members.
1 UPKI-Federation based on Shibboleth National Institute of Informatics Motonori Nakamura Toshiyuki Kataoka, Kyoto University Yasuo Okabe.
Art Education Spring 2012 TExES and Student Advising Office.
Payment in Identity Federations David J. Lutz Universitaet Stuttgart.
Federation as a Service Marina Vermezović, AMRES Federated Identity Technology Workshop Sofia, Bulgaria, 20. Jun 2014.
Authentication and Authorisation for Research and Collaboration Michał Jankowski, Maciej Brzeźniak AARC General Meeting, Milan.
Identity Management in DEISA/PRACE Vincent RIBAILLIER, Federated Identity Workshop, CERN, June 9 th, 2011.
1 Earth System Grid Center for Enabling Technologies ESG-CET Security January 7, 2016 Frank Siebenlist Rachana Ananthakrishnan Neill Miller ESG-CET All-Hands.
Diego R. Lopez, RedIRIS TF-EMC2, Umea SIR, FedSSH and more to come…
Federated Identity Management for HEP David Kelsey HEPiX, IHEP Beijing 18 Oct 2012.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
Case Study: Applying Authentication Technologies as Part of a HIPAA Compliance Strategy.
b2access.eudat.eu B2ACCESS The simple and secure authorisation and authentication platform of EUDAT This work is licensed under the Creative.
Trust and Identity Infrastructure Services Above the Network Ann Harding, SWITCH/GÉANT UbuntuNetConnect 2014.
Networks ∙ Services ∙ People Marina Adomeit FIM4R meeting Virtual Organisation Platform as a Service VOPaaS Nov 30, 2015, Austria Task Leader,
Agenda  Microsoft Directory Synchronization Tool  Active Directory Federation Server  ADFS Proxy  Hybrid Features – LAB.
AAI needs of the Distributed Computing Infrastructures - CLARIN Dieter Van Uytvanck Max Planck Institute for Psycholinguistics
INTRODUCTION TO IDENTITY FEDERATIONS Heather Flanagan, NSRC.
F5 APM & Security Assertion Markup Language ‘sam-el’
Networks ∙ Services ∙ People Marina Adomeit TNC16 Conference, Prague Towards a platform for supporting collaboration GÉANT VOPaaS
Azure Active Directory Uday Hegde 2016 Redmond Summit | Identity Without Boundaries May 26, 2016 Group Program Manager, Azure AD
Authentication and Authorisation for Research and Collaboration Taipei - Taiwan Mechanisms of Interfederation 13th March 2016 Alessandra.
The Federal E-Authentication Initiative David Temoshok Director, Identity Policy GSA Office of Governmentwide Policy February 12, 2004 The E-Authentication.
E-Authentication Guidance Jeanette Thornton, Office of Management and Budget “Getting to Green with E-Authentication” February 3, 2004 Executive Session.
Access Policy - Federation March 23, 2016
David Millman—Columbia January 2005
WLCG Update Hannah Short, CERN Computer Security.
INFORMATION TECHNOLOGY NEW USER ORIENTATION
Implementing bomgar remote support tool in the school of medicine
Federation made simple
Identity Federations - Overview
Future Ideas: Federation and Integration
LearningOn, Smart Learning Platform
Scalability of trust and metadata exchange across federations
GakuNin: Federated Identity Management Activities in Japan
South African Identity Federation
Federated Identity Management for Scientific Collaborations
GÉANT project update eduTEAMS - AAI as a Service for Collaborative organisations Introduction Status Pilots New Features – input requested InAcademia –
Check-in Identity and Access Management solution that makes it easy to secure access to services and resources.
Presentation transcript:

Update of Japanese Academic Access Management Federation GakuNin in 2011 Nakamura, M, Yamaji, K.

2

3

4  Operation  Registration System  In detail by next speaker  Assessment of Administration/Operations of IdP  GakuNin Training Course  For Academic: 3 times  For Commercial Vendor: 2 times  GakuNin CAMP  Collaboration with e-learning consortium  Collaboration with OpenID Summit Tokyo  GakuNin Symposium in March  R&D  VO platform  Developing more secured protocol  DS  Deploying GakuNin embedded DS to domestic SPs  uApprove.jp  In detail by next speaker

requests Level-1 5 How sure am I that you are who you say you are? Authentication focuses on verifying a person’s identity based on the reliability of a credential offered.  Level 1  Little or no confidence in asserted identity  e.g. self identified user/password, essentially a persistent identifier  Level 2  Some confidence in asserted identity  e.g. PIN/Password, used frequently for self service applications  Level 3  High confidence in asserted identity  e.g. digital cert, used to access restricted data  Level 4  Very high confidence in the asserted identity  e.g. Smart Card, used to access highly restricted data

6  Integrate NIH’s PubMed as a GakuNin SP  PubMed request Level 1  IdPs in GakuNin need to obtain Level I in accordance with FICAM(Federal Identity, Credential, and Access Management).  GakuNin have to be a Trust Framework Provider to be able to issue the Level 1 to GakuNin IdPs  It’s a long way. Is there any magic?  MoA between NII and NIH, which states GakuNin’s policy is Level 1 comparable at least.

 2010 October  Access to PubMed manager then requested Level 1 condition  2010 Nobember  Review for level 1 on GakuNin side. ( realized it is a bit complecated )  2011 January  Teleconference with NIH in order to look for more easy way to integrate  2011 February  First Version of MoA  2011 March  Prepare required policy document on GakuNin Side  2011 from April to August  Prepare required attachment such as “interpretation of our policy”  2011 September  Regular Survey on Administration/Operation of IdPs Regular Survey on Administration / Operation of IdPs (Self Assessment)  2011 October  Signed by NII then … 7

8 Education &Research Student Service Library Service Faculty Office Work Secure Services Relatively Simple Services Welfare Program & Healthcare RegistrationCertificate Facility Usage Attendance Edu. Affairs Time ManagePersonnelFinancial School Record Bulletin Board Facility Usage Inspection Rent Book e-journal SanctionApplication Health Record e-MoneyValue Point DB Access Entrance Researcher DB Personal Money, Killer Application Modified from the slide by Prof.Nagai at Tao of Attribute meeting in Kyoto ( )

9  Japanese Grant Application System e-Rad will be shibbolized in  e-Rad have its own IdP and SP first.  By using the IdP e-Rad will SSO with researchers’ e- CV system in order to pull applicant’s publication lists from e-CV to e-Rad.  GakuNin’s IdPs also be able to connect  After 2014?  May request more trusted IdPs than Level 1 Pure SAML system

10  Level 1 TFP by OIX, then Level 2  Service Provider  GakuNin ready commercial wireless network: WiMAX (recently started)  University site license is required  Security Policy e-Learning  Cloud, Cloud and Cloud  More applications which request ePA  GakuNin IdP -> OpenID Connect RP