Step-up Authentication as-a Service Pieter van der Meulen Technical Product Manager.

Slides:



Advertisements
Similar presentations
Lousy Introduction into SWITCHaai
Advertisements

Cost-based tariff system SURFnet Walter van Dijk.
Office 365 Identity June 2013 Microsoft Office365 4/2/2017
Access & Identity Management “An integrated set of policies, processes and systems that allow an enterprise to facilitate and control access to online.
Account Advising & Product Walter van Dijk 27 September 2012.
Federated Identity, Levels of Assurance, and the InCommon Silver Certification Jim Green Identity Management Academic Technology Services © Michigan State.
TF-CPR February 10, 2011 Erwin Bleumink Managing director SURFnet.
Geneva, Switzerland, September 2014 Introduction of ISO/IEC Identity Proofing Patrick Curry Director, British Business Federation Authority.
Widely Distributed Access Management Tom Barton University of Chicago.
Health IT RESTful Application Programming Interface (API) Security Considerations Transport & Security Standards Workgroup March 18, 2015.
Naam van de Auteur 7 januari 2008 Kennisnet Entree: federated authentication Pieter BruringTechnical Product Manager.
AAI with simpleSAMLphp
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
EduGAIN Code of Conduct Workshop, , Brussels GEANT eduGAIN Data Protection "Code of Conduct" Workshop Dieter Van Uytvanck
Copyright 2006 Archistry Limited. All Rights Reserved. SOA Federated Identity Management How much do you really need? Andrew S. Townley Founder and Managing.
EuroPKI 2008 Manuel Sánchez Óscar Cánovas Gabriel López Antonio F. Gómez Skarmeta University of Murcia Levels of Assurance and Reauthentication in Federated.
Identity Management Report By Jean Carreon and Marlon Gonzales.
Federated Identity Management for HEP David Kelsey WLCG GDB 9 May 2012.
Serving society Stimulating innovation Supporting legislation Danny Vandenbroucke & Ann Crabbé KU Leuven (SADL) AAA-architecture for.
GHG SURFnet – Longitudinal effects Albert Hankel, SURFnet.
Campus Identity Management Requirements (=IAP) REFEDs meeting Mikael Linden,
MAT U M A T U Middleware Assisted Take-Up Service For JISC Funded Early Adopters.
SURFnet. We make innovation work0. 1 State-of-the-art Network IT InnovationLicensing.
SURFfederatie & SURFconext Federated identity system for scientific collaborations 9-10 June 2011 CERN Remco Poortinga – van Wijnen*, SURFnet
Edugate Glenn Wearen HEAnet.. Summary 1 year Pilot Project / 2 years in production All IoT’s, Universities, Colleges, but only half of HEAnet’s members.
GFIPM FICAM Status Update GFIPM Delivery Team Meeting November 2011.
INTRODUCTION: THE FIRST TRY InCommon eduGAIN Policy and Community Working Group.
Shibboleth What is it and what is it good for? Chad La Joie, Georgetown University.
Authentication and Authorisation for Research and Collaboration Peter Solagna Milano, AARC General meeting Current status and plans.
Connect. Communicate. Collaborate Universität Stuttgart A Client Middleware for Token- Based Unified Single Sign On to eduGAIN Sascha Neinert, University.
The UK Access Management Federation John Chapman Project Adviser – Becta.
Status Update on Other GFIPM Activity Threads GFIPM Delivery Team Meeting November 2011.
Federated Identity Management for HEP David Kelsey HEPiX, IHEP Beijing 18 Oct 2012.
Connect. Communicate. Collaborate Deploying Authorization Mechanisms for Federated Services in the eduroam architecture (DAMe)* Antonio F. Gómez-Skarmeta.
University of Washington Collaboration: Identity and Access Management Lori Stevens University of Washington October 2007.
June 9, 2009 SURFfederatie: implementing a multi- protocol federation Hans Zandbelt & Joost van Dijk, SURFnet.
Federated Identity Management for Scientific Collaborations The Common Vision David Kelsey (STFC) 3 Nov 2011.
Introduction & use-cases FedAuth IETF78 Maastricht, July 27, 2010
Understanding deployment issues on the Supply Chain Ann Harding, SWITCH, Nicole Harris, TERENA Cambridge July 2014.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
A uthentication & A uthorization for R esearch & C ollaboration Pilots in SA1 Paul van Dijk, SURFnet AARC.
Connect communicate collaborate Trust & Identity EC meets GÉANT 19 June 2014 Brussels Valter Nordh, NORDUnet Federation as a Service Task Leader Trust.
Networks ∙ Services ∙ People Marina Adomeit FIM4R meeting Virtual Organisation Platform as a Service VOPaaS Nov 30, 2015, Austria Task Leader,
Federated Identity Fundamentals Ann Harding, SWITCH Cambridge July 2014.
Secure Mobile Development with NetIQ Access Manager
European Grid Initiative AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
AAI needs of the Distributed Computing Infrastructures - CLARIN Dieter Van Uytvanck Max Planck Institute for Psycholinguistics
Open Collaboration Exchange Alexander Blanc, Niels van Dijk, Jocelyn Manderveld, Remco Poortinga - van Wijnen VAMP 2013, Espoo.
Networks ∙ Services ∙ People Marina Adomeit TNC16 Conference, Prague Towards a platform for supporting collaboration GÉANT VOPaaS
How eduGAIN can help education: a real life story Sabita Behari Product Manager TNC14.
Authentication and Authorisation for Research and Collaboration AARC/CORBEL Workshop for Life Sciences AAI AARC Draft Blueprint.
Authentication and Authorisation for Research and Collaboration Taipei - Taiwan Mechanisms of Interfederation 13th March 2016 Alessandra.
ELIXIR AAI Michal Procházka, Mikael Linden, EGI VC 15 March 2016.
WLCG Update Hannah Short, CERN Computer Security.
Cross-sector and user-centric AAI
Mechanisms of Interfederation
User Community Driven Development in Trust and Identity
eduTEAMS platform for collaboration Niels Van Dijk
eduTEAMS – Current status & Future Plans
Extending Authentication to Members of Social Networks
Identity Federations - Overview
Identity Management and Authorization
An AAI solution for collaborations at scale
Identity Management and Authorization
Identity Management and Authorization
GÉANT project update eduTEAMS - AAI as a Service for Collaborative organisations Introduction Status Pilots New Features – input requested InAcademia –
InAcademia Simple Validation Service Niels van Dijk
ESA Single Sign On (SSO) and Federated Identity Management
Matthew Levy Azure AD B2B vs B2C Matthew Levy
INTEGRATIONS WITH Single Sign-On
Presentation transcript:

Step-up Authentication as-a Service Pieter van der Meulen Technical Product Manager

SURFnet: the Dutch NREN SURFnet is the Dutch National Research & Education Network (NREN) –Services, innovation, knowledge –Not for profit –Task organisation of Stichting SURF = ICT collaboration of higher education & research A small operation serving a large community : –85 employees –160 connected institutions –1 million end-users –Turnover 35 million Euro; 1/3 innovation subsidies SURFnet - We make innovation work 1

OpenConext SURFnet - We make innovation work 2

SAML Federation Types Mesh federation –Each SP connects to (potentially) each IdP SURFnet - We make innovation work 3 Hub-and-Spoke federation –All SPs and IdPs connect to a Gateway (aka SAML Proxy)

SURFconext Platform SURFnet - We make innovation work 4 Federated Authentication Centralized Groups Federated Authentication Hub and Spoke SAML Federation 140 Identity Providers, 240 Service Providers Centralized groups Used for Adhoc collaborations and institutional groups Group Provider Provide group membership information to service providers Receive group data from external group providers

SURFnet - We make innovation work 5 OpenConext

Service Delivery Platform SURFnet - We make innovation work 6 Federated Authentication Attribute based Authorization National Procurement & Licencing Create Trusted Services By combining Identity Federation, privacy and data protection regulations and license deal in one contract between Service Provider and (all) Dutch institutions

Services Dashboard SURFnet - We make innovation work 7

Barriers to strong authentication Deadlock –SPs do not require strong authentication because few IdPs can provide it –IdPs do not implement string authentication because few SP require it Implementation by IdP –High entry cost for a small userbase –Risk of vendor lock-in Implementation by SP –Not their core business –Results is many tokens for users SURFnet - We make innovation work 8

Level of Assurance Strong credential means both –Strong identification –Strong authentication Level of Assurance –1: Low –2: Medium –3: High –4: Very high SURFnet - We make innovation work 9

Step-up authentication as a Service SURFnet - We make innovation work 10

Step-up authentication SURFnet - We make innovation work 11 Create a stronger credential by combining: –Existing SAML authentication with institutional IdP –Authentication with a second factor: Phone, Token, …

Step-up Authentication Flow SURFnet - We make innovation work 12

Determining the required LoA SP can request LoA using RequestedAuthnContext –Each LoA is represented by an URI Step-up gateway configuration –SP requires a minimum LoA for an IdP –IdP requires a minimum LoA for an SP Resulting LoA is communicated using AuthnConext in Response SURFnet - We make innovation work 13

Registration Flow User Self Service registration –User authenticates with institutional IdP –User selects and registers step-up authentication device –User confirms –User receives a registration code User Visits RA –User presents registration code to RA –RA verifies Identity of the user Step-up authentication device SURFnet - We make innovation work 14

SURFnet - We make innovation work 15

SURFnet - We make innovation work 16

SURFnet - We make innovation work 17

SURFnet - We make innovation work 18

SURFnet - We make innovation work 19

SURFnet - We make innovation work 20

SURFnet - We make innovation work 21

SURFnet - We make innovation work 22

Registration Authorities SURFnet - We make innovation work 23

SAML Implementation SURFnet - We make innovation work 24 Interoperable SAML 2.0 Web Browser SSO Profile – Transparent SAML Proxy –Publish SAML Metadata with IDPSSODescriptor –Add supported LoA’s using EntityAttributes Proxy friendly proxy –Sent Scoping with RequesterID

More Information OpenConext is Open for collaboration – – Step-up development – – SURFnet - We make innovation work 25