CSG 1 TIER* Trust and Identity in Education and Research.

Slides:



Advertisements
Similar presentations
1 Leveraging Your Existing Campus Systems to Access Resource Partners: Federated Identity Management and Tales of Campus Participation EDUCAUSE 2006 October.
Advertisements

The Internet2 NET+ Services Program Jerry Grochow Interim Vice President CSG January, 2012.
TIER – before, now and after If you do not talk this will be a very long hour because we can only repeat the same stuff for so long… 1.
NSF Middleware Initiative: Managing Identity on Campus Michael R Gettes, Duke University Tom Barton, University of Chicago.
TIER: Quick Preview STEVEN ZOPPI AVP, NET+ Services Integration and Architecture 14 MAY 2014 / NOTRE DAME [CSG]
Bill Yock University of Washington Coordinating Education and Research Communities to radically improve Identity and Access Management. Shel.
Drive-By Dialogues. Presenter’s Name Topics The Long Strange Trip of I2 – NLR Merger A Brief Comment on Optical Networking Middleware Developments Security.
1 Issues in federated identity management Sandy Shaw EDINA IASSIST May 2005, Edinburgh.
Federated Identity, Levels of Assurance, and the InCommon Silver Certification Jim Green Identity Management Academic Technology Services © Michigan State.
Information Resources and Communications University of California, Office of the President UCTrust Implementation Experiences David Walker, UCOP Albert.
Presenter’s Name InCommon Approximately 80 members and growing steadily More than two million “users” Most of the major research institutions (MIT joining.
FIM-ig Federated Identity Management Interest Group.
InCommon Forum Fall 2012 Internet2 Member Meeting Wednesday, October 3,
Use case: Federated Identity for Education (Feide) Identity collaboration and federation in Norwegian education Internet2 International Workshop, Chicago,
AAF Middleware update February Presented by Terry Smith Technical Manager and Heath Marks Manager.
Federated Identity Management in New Zealand Sat Mandri Service Manager TNC15 REFEDs Meeting, 14 th June 2015.
The InCommon Federation The U.S. Access and Identity Management Federation
BfB: Supporting Collaboration with Infrastructure.
IAMOhio: OARnet’s Trusted Identity Federation Internet2 Fall Member Meeting 2012 Philadelphia, PA Mark Beadles Program Manager, IAMOhio Federation
Maturation & Convergence in Authentication & Authorization Services in US Higher Education: Keith Hazelton, Sr. IT Architect, University.
INTERNET2 COLLABORATIVE INNOVATION PROGRAM DEVELOPMENT Florence D. Hudson Senior Vice President and Chief Innovation.
External Identity and Authorization in GENI. Topics Federated identity and virtual organizations ABAC Creating and transporting attributes.
AARC Overview Licia Florio, David Groep 21 Jan 2015 presented by David Groep, Nikhef.
Climate Sciences: Use Case and Vision Summary Philip Kershaw CEDA, RAL Space, STFC.
Internet2 – InCommon and Box Marla Meehl Colorado CIO 11/1/11.
Federated Identity Management for HEP David Kelsey WLCG GDB 9 May 2012.
SUNY System Administration Federation Overview Gavin Hogan July 15th, 2009 A work in progress….
Belnet Federation Belnet – Loriau Nicolas Brussels – 12 th of June 2014.
Presented by: Presented by: Tim Cameron CommIT Project Manager, Internet 2 CommIT Project Update.
Social Identity Working Group Steve Carmody. Agenda Intro to Using Social Accounts Status and Recent News –Current UT Pilot –Current InCommon Pilot with.
Collaborative Platforms. Collaborations and Virtual Organizations IdM is a critical dimension of collaboration, crossing many applications.
COmanage and InCommon: Present and Future Activities and Interactions Heather Flanagan, COmanage Project Coordinator, Internet2.
Federations 101 John Krienke Internet2 Fall 2006 Internet2 Member Meeting.
Integrated Institutional Identity Infrastructure: Implications and Impacts RL “Bob” Morgan University of Washington Internet2 Member Meeting, May 2005.
Considering Community and Open Source Lois Brooks Stanford Terry Ryan UCLA A Decision Framework for Selecting.
Baltic IT&T, Riga 2007 Identity Management within the educational sector in Norway Senior Adviser Jan Peter Strømsheim, Norwegian ministry of Education.
The InCommon Federation The U.S. Access and Identity Management Federation
Shibboleth Update Eleventh Federal & Higher Education PKI Coordination Meeting (Fed/Ed Thursday, June 16, 2005.
INTRODUCTION: THE FIRST TRY InCommon eduGAIN Policy and Community Working Group.
University of Washington Identity and Access Management IEEAF – RENU Network Design Workshop Seattle - 29 Nov 2007 Lori Stevens, Director, Distributed.
Federated Identity in Texas Paul Caskey The University of Texas System HEAnet National Conference Kilkenny, Ireland 13 November 2008.
Federated Identity Management for HEP David Kelsey HEPiX, IHEP Beijing 18 Oct 2012.
Internet2 and Cyberinfrastructure Russ Hobby Program Manager,
Transforming Government Federal e-Authentication Initiative David Temoshok Director, Identity Policy and Management GSA Office of Governmentwide Policy.
University of Washington Collaboration: Identity and Access Management Lori Stevens University of Washington October 2007.
Identity Federations: Here and Now David L. Wasley Thomas Lenggenhager Peter Alterman John Krienke.
NSF Middleware Initiative Purpose To design, develop, deploy and support a set of reusable, expandable set of middleware functions and services that benefit.
Identity Management, Federating Identities, and Federations November 21, 2006 Kevin Morooney Jeff Kuhns Renee Shuey.
Brown University Leveraging Social Identities Steve Carmody CSG, May 15, 2013.
INTRODUCTION: THE FIRST TRY InCommon eduGAIN Policy and Community Working Group.
NMI-EDIT and Rice University Federated Identity Management: Managing Access to Resources in Texas Barry Ribbeck Director System Architecture and Infrastructure.
Networks ∙ Services ∙ People Marina Adomeit FIM4R meeting Virtual Organisation Platform as a Service VOPaaS Nov 30, 2015, Austria Task Leader,
1 Identities and Federation: The Next IT Wave (The Canadian Access Federation) Rick Bunt President The Canadian University Council of CIOs (CUCCIO)
Shibboleth Use at the National e-Science Centre Hub Glasgow at collaborating institutions in the Shibboleth federation depending.
INTRODUCTION TO IDENTITY FEDERATIONS Heather Flanagan, NSRC.
Leveraging Campus Authentication to Access the TeraGrid Scott Lathrop, Argonne National Lab Tom Barton, U Chicago.
Networks ∙ Services ∙ People Licia Florio TNC, Lisbon Consuming identities across e- Infrastructures 16 June 2015 PDO GÈANT.
Designing Identity Federation Policy, the right way Marina Vermezović, Academic Network of Serbia TNC2013 conference 4 May 2013.
Networks ∙ Services ∙ People Marina Adomeit TNC16 Conference, Prague Towards a platform for supporting collaboration GÉANT VOPaaS
Trust and Identity in Education and Research: Identity for Everyone
LIGO Identity and Access Management
Shibboleth Roadmap
Use case: Federated Identity for Education (Feide)
eduTEAMS platform for collaboration Niels Van Dijk
University of Stuttgart University of Murcia
California State University CSUconnect Federation
Géant-TrustBroker Dynamic inter-federation identity management
InCommon Steward Program: Community Review
Context, Gaps and Challenges
Presentation transcript:

CSG 1 TIER* Trust and Identity in Education and Research

What is TIER 2 Internet 2 runs InCommon Federation. InCommon provides a secure and privacy-preserving trust fabric for research and higher education, and their partners. InCommon operates an identity management federation and a related assurance program. InCommon has about 700 participants. T rust Management of individual principals, their authentication, authorization, and privileges within or across system and enterprise boundaries with the goal of increasing security and productivity while decreasing cost, downtime and repetitive tasks. Internet 2 provides cloud based services (certificate service, MFA) as well as software (Shibboleth, Grouper, etc.) I dentity Universities are institutions of higher education and research which grant academic degrees in a variety of subjects and provides both undergraduate education and postgraduate education. They are "communities of teachers and scholars”. The community remains location based. E ducation Comprises "creative work undertaken on a systematic basis in order to increase the stock of knowledge, including knowledge of man, culture and society, and the use of this stock of knowledge to devise new applications." Research communities are increasingly virtual and cross boundaries of Universities. R esearch

TIER Vision: Service Development “WE BELIEVE” Identity components can be aggregated into services Inaction is a greater risk than action (e.g., If we do not develop identity as componentized services, someone else will e.g., social identities). A common R&E approach is possible. Most identity components can be instantiated as a cloud service. Higher Education is well positioned to do this (trusted relationships with each other and key partners like federal agencies). We are 3-5 years from achieving this vision. 3

4 Grouper Kuali KIM CommIT Shibboleth Consortium Shibboleth Consortium InCommon Federation Multi Factor Okta, Ping, OneLogin Oracle Identity Manager Social Identity (Google, Facebook) Certificates Apereo CAS CoManage Coordinated via personal communications and individual best effort. Privacy Lens EduRoam EduGAIN

5 TIER LANDSCAPE Service & Middleware Development InCert, Grouper, CoManage, I2 – Shibboleth, Kuali KIM, CommIT, Other community investment, etc. Campus IdM standards (prevision/de- provisioning/ac cess) Service Delivery (InCommon “ branded” identity services) (MFA: Duo, Toopher; certs: Comodo), etc. * (Service fees – cover cost – FY15 $800K income) Service Delivery InCommon Federation Federation standards, Research collaboration (R&S) * (Federation dues – cover cost – FY15 $1M income) External relationships Vendors/Partne rs such as Apereo, Okta, Ping, Other, etc. Entity relationships such as REFEDS, Shib consortium board, Kuali Board, etc. TIER Subcommittee 2: InCommon Steering TIER Subcommittee 1: Investor Campus Steering TIER Subcommittee 3: External Relationships for federation, service development and delivery = Existing Activities

Governance Structure Internet 2 Board TIER Steering/Board Service Development Steering Committee (SDSC) InCommon Steering Committee (ICSC) External Relations Subcommittee (includes members from ICSC and SDSC) 6 = Existing Activities

Current TIER Charter Committee 7 TIER Committee MembersRepresenting Klara JelinkovaUniversity of Chicago, InCommon Steve CorbatoUniversity of Utah, Kuali Tracy FutheyDuke University Kevin MorooneyPenn State University (also Kuali) Eric DennaUniversity of Maryland (also Kuali) Joel CooperSwarthmore College,, InCommon Melissa WooUniversity of Oregon,, InCommon Chris HolmesBaylor University,, InCommon Dennis CromwellIndiana University,, InCommon Kelli TrosvigUniversity of Washington (also Kuali) Shel WaggenerInternet2 Ron KraemerUniversity of Notre Dame

August 2014 © Internet2 GOAL: TIER Community Unified Middleware Model Secure, Identity and Metadata Services Single Signon and Identity Components AuthN (Who) Multi Factor Multi- Level (Groups) AuthZ (What) Business Rules Engine / Grammar Federated Registry (Directory Search / Lookup) Network Objects (Files, Datasets, etc.) People Files / Datasets Nodes Metadata Registry Services Persistence and Replication Lightweig ht Workflow Services Automated Provisioning / Deprovisioning and Rules Enforcement

Transformational frame- work to support inter- institutional research and collaboration, within the future context of identity being “owned” by the individual, not the university Extend IAM to the cloud AND deliver federated IdM, including role-based IAM (e.g., encompassing AD/LDAP/Kerberos), R&S attribute release, EduGAIN (interfederation) IAM in a box: person registry, identity/attribute storage, provisioning/deprovisioning. and AuthN/Z Maturity of Campus IDM Operations and Outstanding Need Multi Year Journey with Regular Interim Milestones

Transformational frame- work to support inter- institutional research and collaboration, within the future context of identity being “owned” by the individual, not the university Extend IAM to the cloud AND deliver federated IdM, including role-based IAM (e.g., encompassing AD/LDAP/Kerberos), R&S attribute release, EduGAIN IAM in a box: person registry, identity/attribute storage, provisioning/deprovisioning and AuthN/Z Campus with emerging or less mature “IDM Program” Recognizes value of I2 (& InCommon) services and participation but lacks resources or ability to implement. Campus IdM not (or little) leveraged for research. Campus with IDM Team that has delivered Shib/Grouper Mature campus IDM operations are sustainable but would be enhanced with systematic non- SAML role-based IAM. Campus IdM in support of research via federation services. R1 with advanced IDM team & inter- institutional collaboration needs Researchers have urgent need to conduct research across institutions (whether an I2 member or not) Maturity of Campus IDM Operations and Outstanding Need

How will we get there: Structure The current TIER Committee assembled over the summer & will continue as a standing governance committee for TIER. We will not fix what is not broken. – InCommon federation works well. – We will integrate InCommon Steering through its ER&G subcommittee (already done) as a subcommittee of TIER. This subcommittee will continue to be staffed by InCommon/Internet 2 – John Krienke. 11

How will we get there: Funding We will concentrate on what needs attention. Internet2 community middleware development efforts should not (really cannot) continue to without expanded and updated governance and investment. Budget (and spend) set and governed by the community. We will recruit investment campuses (e.g., $50K-100K/yr for 3yrs). Those campuses will establish a Service Development subcommittee to guide campus investments. This subcommittee will be staffed by Internet2 – AVP Steve Zoppi. 12

How will we get there: External Relations We will start working on external relations. – InCommon has both IdP and SP entity relationships as well as some service brokerage. – NET+ Service Brokerage to be primary home for cloud services, with service oversight by TIER. – We will set up an External Relations subcommittee from InCommon Steering, Service development and Internet2 industry support. This subcommittee will be staffed by Internet2. 13

So What’s Next Join the Mail List: We Need your Feedback (Architecture, Governance, Funding, Vision) EDUCAUSE: CIO Discussion TechExchange: Technical Deep Dive 14

Conversation 15

Maturity of Campus IDM Operations and Outstanding Need Transformational frame- work to support inter- institutional research and collaboration, within the future context of identity being “owned” by the individual, not the university Extend IAM to the cloud AND deliver federated IdM, including role-based IAM (e.g., encompassing AD/LDAP/Kerberos), R&S attribute release, EduGAIN IAM in a box: person registry, identity/attribute storage, provisioning/deprovisioning and AuthN/Z This is what we are eager for ASAP… federation of non-SAML authN services (AD/LDAP/Kerberos) still is needed for remote access services including VPN, RDP, and system access needed for research collaboration that includes protected data across institutions. Federated support for research VOs (IdP of last resort, EduGAIN, campus R&S attribute release) “IAM in a box” helps large schools even if previously rolled their own and have “solved problem”. For smaller schools or those that haven’t yet solved, gives a very clear step to take with clear deployment guide to get to baseline for IAM. The details and requirements for this come from the investors. This is the direction and vision but detailed scope would be set the direction here….