Federated Identity Management for Research Communities (FIM4R) David Kelsey (STFC-RAL) EGI TF, AAI workshop 19 Sep 2012.

Slides:



Advertisements
Similar presentations
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
Advertisements

Federated Identity Management for Research Communities: FIM 4 R CSC, Helsinki 2 nd October 2013 Bob Jones, CERN.
Federated Identity Management for Researchers – A quick overview from GÉANT BoF TNC May 2014 Dublin.
Information Resources and Communications University of California, Office of the President UCTrust Implementation Experiences David Walker, UCOP Albert.
FIM-ig Federated Identity Management Interest Group.
Security Incident Response Trust Framework for Federated Identity (Sir-T-Fi) David Kelsey (STFC-RAL) REFEDS, Indianapolis 26 Oct 2014 and now abbreviated.
Identity Management for Research Collaborations: from Pilots to Production Bob Jones IT dept CERN.
Trust and Security for FIM (Sirtfi/SCI) David Kelsey (STFC-RAL) FIM4R at CERN 4 Feb 2015.
BoF: Federated Identity Management for Researchers David Kelsey (STFC-RAL) TNC2014, Dublin 20 May 2014.
Authentication and Authorization in a federated environment Jules Wolfrat (SARA)
AARC Overview Licia Florio, David Groep 21 Jan 2015 presented by David Groep, Nikhef.
Sirtfi David Kelsey (STFC-RAL) REFEDS at TNC15 14 June 2015.
Climate Sciences: Use Case and Vision Summary Philip Kershaw CEDA, RAL Space, STFC.
Federated Identity Management for HEP David Kelsey WLCG GDB 9 May 2012.
CLARIN Infrastructure Vision (and some real needs) Daan Broeder CLARIN EU/NL Max-Planck Institute for Psycholinguistics.
EMI AAI Strategy & Plans John White / Helsinki Institute of Physics Federated Identity Systems for Scientific Collaborations Workshop , CERN,
Authentication and Authorisation for Research and Collaboration Licia Florio (GÉANT) Christos Kanellopoulos (GRNET) Service orientation.
European Life Sciences Infrastructure for Biological Information Life science community update for the 7 th Federated Identity Management.
Federated Identity Management for Research Communities (FIM4R) David Kelsey (STFC-RAL) EGI CF, FIM workshop 11 Apr 2013.
7 th FIM 4 R meeting April 2014 ESRIN Frascati.
Jamie Hall (ILL). SciencePAD Persistent Identifiers Workshop PANData Software Catalogue January 30th 2013 Jamie Hall Developer IT Services, Institut Laue-Langevin.
EResearchers Requirements the IGTF model of interoperable global trust and with a view towards FIM4R AAI Workshop Presenter: David Groep, Nikhef.
Federated Identity Management for Research Collaborations Bob Jones, CERN Daan Broeder, Max-Planck Institute for Psycholinguistics David Kelsey, Particle.
Authentication and Authorisation for Research and Collaboration Licia Florio REFEDS Meeting The AARC Project I2 Technology Exchange.
Authentication and Authorisation for Research and Collaboration Licia Florio AARC Workshop The AARC Project Brussels, 26 October.
Authentication and Authorisation for Research and Collaboration David Kelsey AARC AHM Milan And mechanisms NA3 Task 4 – Scalable.
Authentication and Authorisation for Research and Collaboration Peter Solagna Milano, AARC General meeting Current status and plans.
A Trust Framework for Security Collaboration among Infrastructures David Kelsey (STFC-RAL, UK) 1 st WISE, Barcelona 20 Oct 2015.
Federated Identity Management for HEP David Kelsey HEPiX, IHEP Beijing 18 Oct 2012.
Jacques Bus Head of Unit, DG INFSO-F5 “Security” European Commission FP7 launch in the New Member States Regional on-line conference 22 January 2007 Objective.
Federated Identity Management for HEP David Kelsey HEPiX, Ann Arbor MI 30 Oct 2013.
Security Policy: From EGEE to EGI David Kelsey (STFC-RAL) 21 Sep 2009 EGEE’09, Barcelona david.kelsey at stfc.ac.uk.
Authentication and Authorisation for Research and Collaboration Christos Kanellopoulos Open Day Event: Towards the European Open.
A European Open Science Cloud
Federated Identity Management for Scientific Collaborations The Common Vision David Kelsey (STFC) 3 Nov 2011.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
Networks ∙ Services ∙ People Thomas Bärecke Journée Fédération, Paris Collaboration européenne GÉANT SA5 03/07/2015 SA5 T5 team
Research Community Requirements Ann Harding, SWITCH Cambridge July 2014.
Case Studies in Federated Identity Management for Research Communities Ann Harding, SWITCH/GN3plus Peter Gietz, DAASI International GmbH/DARIAH Tommi Nyro.
Connect communicate collaborate Case Studies in Federated Identity Management for Research Communities Ann Harding, SWITCH/GN3plus Peter Gietz, DAASI International.
David Groep Nikhef Amsterdam PDP & Grid AARC Authentication and Authorisation for Research and Collaboration an impression of the road ahead.
Federated Identity Management for Research Communities: FIM4R PSI workshop objectives Bob Jones, CERN.
Networks ∙ Services ∙ People Licia Florio TNC, Lisbon Consuming identities across e- Infrastructures 16 June 2015 PDO GÈANT.
Authentication and Authorisation for Research and Collaboration Christos Kanellopoulos David Groep 9 th FIM4R Meeting The AARC Project.
Authentication and Authorisation for Research and Collaboration Peter Solagna, Nicolas EGI AAI integration experiences AARC Project.
Authentication and Authorisation for Research and Collaboration David Kelsey AARC AHM Utrecht NA3 Task 4 – Scalable Policy Negotiation.
Authentication and Authorisation for Research and Collaboration AARC/CORBEL Workshop for Life Sciences AAI AARC Draft Blueprint.
Research Community Requirements (FIM4R) David Kelsey (STFC-RAL) VAMP Workshop 6 Sep 2012.
SCI & Sirtfi David Kelsey (STFC-RAL) EGI Conference, Lisbon 19 May 2015.
Security Incident Response Trust Framework for Federated Identity (Sir-T-Fi) David Kelsey (STFC-RAL) REFEDS, Indianapolis 26 Oct 2014.
Welcome to 11th FIM4R 11th Meeting, Montréal September 2017
Introduction to AAI Services
Boosting AAI for research and collaboration
Cross-sector and user-centric AAI
User Community Driven Development in Trust and Identity
Case Studies in Federated Identity Management for Research Communities
Identity Management and Authorization
Federated Identity Management for Researchers (FIM4R)
EGI Security Policy Update
CLARIN Federated Identity Vision
Boosting AAI for research and collaboration
Incident Response for Federated Identities
Federated Identity Management for Scientific Collaborations
The AARC Project Licia Florio (GÉANT) Christos Kanellopoulos (GRNET)
The AARC Project Licia Florio AARC Coordinator GÉANT
Policy in harmony: our best practice
Updated (VO) Community Security Policies
AARC Blueprint Architecture and Pilots
David Kelsey (STFC-RAL)
FIM4R Requirements where GN3+ (SA5) is Active and Involved (9/2013)
Presentation transcript:

Federated Identity Management for Research Communities (FIM4R) David Kelsey (STFC-RAL) EGI TF, AAI workshop 19 Sep 2012

Overview FIM4R –“Federated Identity Management for Research” Some background FIM4R workshops and our paper The Research Communities Vision and Common Requirements Next steps 19 Sep 12FIM4R, Kelsey2

Background Issue of IdM raised in EIROforum (Jan 2011) –CERN, EFDA-JET, EMBL, ESA, ESO, ESRF, European XFEL and ILL These laboratories, as well as national and regional research organizations, are facing similar challenges –Scientific data deluge means massive quantities of data –needs to be accessed by expanding user bases in dynamic collaborations across organisational and national boundaries Also encouraged by EEF and eIRG Global problem, not just EU 19 Sep 12FIM4R, Kelsey3

Workshops and Paper 4 workshops to date –link to Jun 2012 agenda below (other links contained within) Prepared a paper that documents common requirements, a common vision and recommendations Paper: CERN-OPEN : Sep 12FIM4R, Kelsey4

The communities 19 Sep 12FIM4R, Kelsey5

Common vision statement A common policy and trust framework for Identity Management based on existing structures and federations either presently in use by or available to the communities. This framework must provide researchers with unique electronic identities authenticated in multiple administrative domains and across national boundaries that can be used together with community defined attributes to authorize access to digital resources 19 Sep 12FIM4R, Kelsey6

Common Requirements User friendliness –Many users use infrequently Browser and non-browser federated access Bridging between communities Multiple technologies and translators –Translation will often need to be dynamic Open standards and sustainable licenses –For interoperability and sustainability Different Levels of Assurance –When credentials are translated, LoA provenance to be preserved Authorisation under community and/or facility control –Externally managed IdPs cannot fulfil this role Well defined semantically harmonised attributes –For interoperable authorisation –Likely to be very difficult to achieve! 19 Sep 12FIM4R, Kelsey7

Requirements (2) Flexible and scalable IdP attribute release policy –Different communities and different SPs need different attributes –Negotiate with IdF not all IdPs – for scaling Attributes must be able to cross national borders –Data protection/privacy considerations Attribute aggregation for authorisation Privacy and data protection to be addressed with community- wide individual identities –We need to identify individuals E.g. ethical committees can require names, addresses, supervisors to grant access Legal issues and contracts –Data protection, scalability, … 19 Sep 12FIM4R, Kelsey8

Operational Requirements Risk analysis Traceability –Audit trails include IdPs Security incident response –To include all IdPs and SPs Transparency of policies –To gain trust of SPs and users Reliability and resilience Smooth transition (from today’s production) Easy integration with local SP –SP likely to want to support multiple AuthN technologies 19 Sep 12FIM4R, Kelsey9

Example FIM Pilot Projects Life Sciences –Users authenticate with FIM to access sensitve data –Automated electronic workflow for authenticated user to be granted access to a dataset (Data Access Comm) Photon and Neutron facilities –Umbrella system being developed –A common Federated IdM system across all facilities with all facility User Offices linked Humanities –CLARIN is gradually building a federation of SPs 19 Sep 12FIM4R, Kelsey10

Next steps Awaiting response from REFEDS Can then jointly prioritise requirements Pilot projects are very important –Simple way to engage both sides Next FIM4R meeting – 20/21 March 2013 (PSI, Switzerland) 19 Sep 12FIM4R, Kelsey11

Questions? 19 Sep 12FIM4R, Kelsey12