InCommon Policy Conference April 2005
2 Uses In order to encourage and facilitate legal music programs, a number of universities have contracted with Napster to provided discounted programs for student access to popular music. How should the university provide access to those materials from authenticated users? This is a job for Shibboleth!
3 Uses History professor at Cornell who wants to partner with a NYU professor in an urban history class. Each professor has digitized materials for this class, and that they want to use to compare and contrast. Eighty students, two professors and two teaching assistants who want to move seemlessly between each of the institutions and among all of the materials for the course. Must have authenticated services, but do not want nor have the authority to give network identifiers for each institutions: This is a job for Shibboleth!
4 Uses International team, doing earthquake simulation, made up of researchers from Australian National University, USC and Kyoto. All three members require access to research data owned by Southern California Earthquake Center stored at USC. All three members require access to HPCC: High Performance Computing Center at USC. This is a job for Shibboleth!
5 InCommon can help make sharing protected online resources easier InCommon is… a formal federation of organizations focused on creating a common framework for trust in support of research and education… whose purpose is to facilitate collaboration through the sharing of protected resources, by means of an agreed-upon, common trust fabric. The InCommon federation is intended to support production-level end- user access to protected resources by providing the means to allow organizations to make effective decisions about sharing resources, based upon the attributes presented by a requester. Risk and Trust between resource and credential providers will drive technology and policies
6 InCommon, LLC Management Governance Steering Committee – Carrie Regenstein - chair (Wisconsin- Madison), Jerry Campbell, (USC), Lev Gonick (CWRU), Clair Goldsmith (Texas System), Mark Luker (EDUCAUSE),Tracy Mitrano (Cornell), Susan Perry (Mellon), Mike Teets, (OCLC), David Yakimischak (JSTOR) Internet2 Member – Ken Klingenstein Operations – Internet2 InCommon Certificate Authority –Issuing the enterprise certificate signing keys Identity proofing the enterprise (Registry Authority) Metadata and Certificate submission User Interface Hosting the WAYF (Where Are You From) interface Supporting campuses in posting their policies
7 InCommon Pilot 11 Phase One participants Cornell University Dartmouth College Elsevier The Ohio State University Online Computer Library Center (OCLC) Penn State University at Buffalo (SUNY) University of California, Irvine University of California, San Diego University of Rochester University of Washington
8 InCommon The InCommon federation allows Higher Ed institutions to share information and resources between themselves and their business partners in a trusted, standardized fashion that protects privacy, respects copyright, and fosters collaboration and innovation. It provides the trust framework for organizations to make decisions about user access to protected resources based on privacy- preserving attributes presented by the user’s home institution.
9 Etymology shibboleth 1382, the Heb. word shibboleth "flood, stream," also "ear of corn," in Judges xii:4-6. It was the password used by the Gileadites to distinguish their own men from fleeing Ephraimites, because Ephraimites could not pronounce the -sh- sound.
10 Prerequisites Official University Directory Deploying a single, unique electronic identifier Federation: Trust Community Associations of enterprises that come together to exchange information about their users and resources in order to enable collaborations and transactions Middleware: Implementing Technology Identifier Federating software Common language IT framework with focus on security and privacy policies
11 Shibboleth Architecture (still photo, no moving parts)
12 Collaboration & Technology: Shibboleth v Open-source, standards-based, privacy-preserving federating software Global development InCommon National Science Digital Library SWITCH (Swiss Network) Finland, Netherlands, United Kingdom, Australia Commercial information providers in production JSTOR Elsevier “Science Direct” Ohio LInk. Growing international development interest providing resource manager tools, list software, etc.
13 Future of InCommon Collaboration among several hundred participants Layered levels of authentication assurance Interoperability with state and/or regional federations “Gateways” with commercial federations And it’s all possible in higher education’s culture of technology, collaboration, and challenge!