Use case: Federated Identity for Education (Feide) Identity collaboration and federation in Norwegian education Internet2 International Workshop, Chicago,

Slides:



Advertisements
Similar presentations
Lousy Introduction into SWITCHaai
Advertisements

Federation management A mess? Nordunet Conference Mikael Linden CSC, the Finnish IT Center for Science.
NRL Security Architecture: A Web Services-Based Solution
Access & Identity Management “An integrated set of policies, processes and systems that allow an enterprise to facilitate and control access to online.
The Internet2 NET+ Services Program Jerry Grochow Interim Vice President CSG January, 2012.
ELAG Trondheim Distributed Access Control - BIBSYS and the FEIDE solution Sigbjørn Holmslet, BIBSYS, Norway Ingrid Melve, UNINET, Norway.
Federated Digital Rights Management Mairéad Martin The University of Tennessee TERENA General Assembly Meeting Prague, CZ October 24, 2002.
Information Resources and Communications University of California, Office of the President UCTrust David Walker Office of the President University of California.
2006 © SWITCH Authentication and Authorization Infrastructures in e-Science (and the role of NRENs) Christoph Witzig SWITCH e-IRG, Helsinki, Oct 4, 2006.
1 Issues in federated identity management Sandy Shaw EDINA IASSIST May 2005, Edinburgh.
Open Workshop on e-Infrastructures, Helsinki October 4 – 5, 2006 Roadmap Parallel Session on last chapter of e-IRG Roadmap: Crossing the Boundaries of.
U.S. Environmental Protection Agency Central Data Exchange EPA E-Authentication Pilot NOLA Network Node Workshop February 28, 2005.
1 eAuthentication in Higher Education Tim Bornholtz Session #47.
Information Resources and Communications University of California, Office of the President UCTrust Implementation Experiences David Walker, UCOP Albert.
Widely Distributed Access Management Tom Barton University of Chicago.
InCommon Policy Conference April Uses  In order to encourage and facilitate legal music programs, a number of universities have contracted with.
Credential Provider Operational Practices Statement CAMP Shibboleth June 29, 2004 David Wasley.
SWITCHaai Team Federated Identity Management.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
Feide is a identity management system on a national level for the educational sector in Norway. Federated Electronic Identity for Norwegian Education Tromsø,
AAF Middleware update February Presented by Terry Smith Technical Manager and Heath Marks Manager.
Federated Identity Management in New Zealand Sat Mandri Service Manager TNC15 REFEDs Meeting, 14 th June 2015.
The InCommon Federation The U.S. Access and Identity Management Federation
Middleware challenges to service providers, the Nordic view TERENA, Ingrid Melve, UNINETT.
CASE: Haka federation EuroCAMP, 3-5 April, 2006 CSC, the Finnish IT Center for Science
Developments and challenges in authentication and authorisation Klaas Wierenga Berlin, 23 May 2006.
Single Sign-On Multiple Benefits via Alaska K20 Identity Federation 20 May 2011 BTOP Partner Meeting Anchorage, Alaska 20 May 2011 BTOP Partner Meeting.
1 Identity and Transparency ( Bridging the GAPS of Governance Bridging the GAPS of Governance in eGov Initiatives in eGov Initiatives )‏ Badri Sriraman.
UFD ICT in education in Norway Thorvald Astrup, OMEC-OCDE-Canada Seminar, Montreal april 2002 Royal Ministry of Education and Research.
Internet2 – InCommon and Box Marla Meehl Colorado CIO 11/1/11.
Australian Access Federation and other Middleware Initiatives Presented at TF-EMC2, Prague 4 Sep 2007 Patty McMillan, The University of Queensland.
Federated Identity Management for HEP David Kelsey WLCG GDB 9 May 2012.
Belnet Federation Belnet – Loriau Nicolas Brussels – 12 th of June 2014.
2005 © SWITCH Perspectives of Integrating AAI with Grid in EGEE-2 Christoph Witzig Amsterdam, October 17, 2005.
Update Finland TF-EMC Mikael Linden CSC, the Finnish IT Center for Science.
Presented by: Presented by: Tim Cameron CommIT Project Manager, Internet 2 CommIT Project Update.
Kalmar Union, a Conferedation of Nordic Identity Federations TNC2009 Mikael Linden, CSC Andreas Solberg, UNINETT.
Social Identity Working Group Steve Carmody. Agenda Intro to Using Social Accounts Status and Recent News –Current UT Pilot –Current InCommon Pilot with.
Towards Interconnecting the Nordic Identity Federations TNC2007 Walter M Tveter, UiO Mikael Linden, CSC/HAKA Ingrid Melve, Uninett/Feide.
Empowering people-centric IT Unified device management Access and information protection Desktop Virtualization Hybrid Identity.
Ian Bailey Director Application Architecture Office of CIO, Province of BC A User Centric and Claims Based Architecture for British Columbia.
Baltic IT&T, Riga 2007 Identity Management within the educational sector in Norway Senior Adviser Jan Peter Strømsheim, Norwegian ministry of Education.
The Impact of Evolving IT Security Concerns On Cornell Information Technology Policy.
Federations round table Haka federation of Finland EuroCAMP Mikael Linden CSC, the Finnish IT Center for Science.
INTRODUCTION: THE FIRST TRY InCommon eduGAIN Policy and Community Working Group.
State of e-Authentication in Higher Education August 20, 2004.
Federation Building Blocks EuroCAMP, Malaga 18 Oct 2006 Julie Frøseth, UNINETT.
Community Sign-On and BEN. Table of Contents  What is community sign-on?  Benefits  How it works (Shibboleth)  Shibboleth components  CSO workflow.
Federated Identity Management for HEP David Kelsey HEPiX, IHEP Beijing 18 Oct 2012.
Connect. Communicate. Collaborate Deploying Authorization Mechanisms for Federated Services in the eduroam architecture (DAMe)* Antonio F. Gómez-Skarmeta.
Transforming Government Federal e-Authentication Initiative David Temoshok Director, Identity Policy and Management GSA Office of Governmentwide Policy.
University of Washington Collaboration: Identity and Access Management Lori Stevens University of Washington October 2007.
Attribute Delivery - Level of Assurance Jack Suess, VP of IT
Identity Management, Federating Identities, and Federations November 21, 2006 Kevin Morooney Jeff Kuhns Renee Shuey.
Programme ›TERENA ›Overview of the middleware initiatives in the European Higher Education ›What is eduroam: the technology and how to set up eduroam ›eduroam-in-a-box:
Connect communicate collaborate Trust & Identity EC meets GÉANT 19 June 2014 Brussels Valter Nordh, NORDUnet Federation as a Service Task Leader Trust.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Interoperability Shibboleth - gLite Christoph.
INTRODUCTION TO IDENTITY FEDERATIONS Heather Flanagan, NSRC.
Networks ∙ Services ∙ People Licia Florio TNC, Lisbon Consuming identities across e- Infrastructures 16 June 2015 PDO GÈANT.
Authentication and Authorisation for Research and Collaboration Taipei - Taiwan Mechanisms of Interfederation 13th March 2016 Alessandra.
L’Oreal USA RSA Access Manager and Federated Identity Manager Kick-Off Meeting March 21 st, 2011.
Use case: Federated Identity for Education (Feide)
Punching data to the authentication server
John O’Keefe Director of Academic Technology & Network Services
THE STEPS TO MANAGE THE GRID
ESA Single Sign On (SSO) and Federated Identity Management
PASSHE InCommon & Federated Identity Workshop
GNOMIS – the northern light TF-AACE, Ingrid Melve, UNINETT
Feide status TF-EMC2, Malaga 17 Oct 2006 Julie Frøseth, UNINETT
Presentation transcript:

Use case: Federated Identity for Education (Feide) Identity collaboration and federation in Norwegian education Internet2 International Workshop, Chicago, Ingrid Melve, UNINETT CTO

2 Overview Why work on federated identity in education? Feide  Higher education  Schools Rollout process  Applications get «Feidefied» Current identity focused initatives Future plans  Collaboration, research, development, deployment

3 Norway: small European country

4 Norwegian education 7 universities, 46 university colleges ( persons) Extensive collaboration on electronic services in higher education  BIBSYS and other library services  FS and MSTAS student registry systems  Administrative systems: finance, HR, archive, invoice,  High performance computing, super-computers and grids Schools ( persons, pluss parents)  454 upper secondary schools owned by 19 regions  Around 4500 schools owned by 430 municipalities User populations, including parents, make up 43% of population

5 ICT trends: Usage in higher education All Norwegian universities and colleges are online since 1992 Currently all students in higher education use e- learning  Tracking learning, tracking teaching  Personalization requires stronger central ICT systems Half of the students have laptops (growing number), and they grew up with PCs Web self service is increasingly deployed Traffic grows exponentially

6 UNINETT and Feide UNINETT is the Norwegian research network UNINETT is chartered to  Provide advanced network services among the world best  Support open standards and interoperability  Work in collaboration with education and research Feide organization  A central service (7 persons)  Login service, operated by Oslo University, with integration support  Trust model  Information model  Project management  Deployment in higher education (3-1 persons)  Deployment for school owners (4-9 persons)

7 Collaboration Strong involvement from universities and colleges  User groups  Active participation in various project(s)  Close collaboration with SAP roll-out  Operational Feide service run by UiO Backing from Ministry of Education and Research  Financial support  Clear political support for integrating services  Identity management for schools scheduled for 2008 Partnership with commercial technology partner (Sun) for open source Liberty-based software International participation: TF-EMC²/REFEDS, eduGAIN, GNOMIS, EuroCAMP, Internet2

8 Identity management for education Feide since 2000 (initially higher education)  Operational federation with login service since 2003  Universities and university colleges: (7) Schools and Feide  Participation decided by Ministry of Education early 2006  Identity management should be available by 2008 for all schools Strong campus identity management efforts  Universities and colleges develop and deploy IdM software  Organizational process: identify responsibilities and enforce routines for processing personal information  Supporting the Personal Data Act Operational service providers (current: 26)  Adding 2-3 every month this fall

9 Why federate? Users and home organizations and service providers need to exchange information Trust establishment  Feide-name and password  PKI and other credentials supported Policy with privacy support Technology:  Easy service provider integration  Multi-vendor environment  Open standards  Clear integration path

10 Feide – Federated Electronic Identity for Norwegian Education Feide is a non-commercial identity management federation for people in education Feide is technology and platform agnostic Feide offers guidelines and policy for campus identity management Feide-names are valid for all education services, and may be used internally, for community services and with educational related services

11 Feide login User tries to access service Service transfer user to Feide login Authentication is done at campus  Local authentication point  Local control over information Authentication is confirmed with the service, possibly with attribute release  Attribute release controlled by user, governed by contract

12 Feide federates education Federations: Establish trust Authenticate Do privacy control Enforce information flow policy Security

13 Business drivers for Feide End user: one username, one password Each educational institution benefits from  Local dataflow clean-up  Overview and control of services  Common guidelines, requirements and best practice for identity management University, college or school as Service Provider benefits  Easy integration of non-local users  Data protection contracts and guidelines Common shared services benefit from  Integrated user space  Data protection contracts and guidelines

14 Feide is glue in education

15 Collaboration Parents/guardians should be able to log in  How to reuse existing credentials?  How to link parent-child? Public sector: MyID  PKI is on hold  Pincode-based federated ID  SAML2.0 Possibilities in private sector  Private federations  PKI-based login  Not yet concrete plans User groups  Technology based for campus IdM  Regional based Support from vendors  Novell for campus IdM  Various Microsoft-affiliates  Sun for federation support  IBM, Oracle, Kantega for roll-out and applications

16 Ongoing work Feide operates with  One Identity Provider (central login service)  Many Authentication points (one at each educational insitution) Attribute release is important  Feide-name valid only in organizational context  What school, affiliation, group, address, NIN, unit?  Provisioning: started PIFU standardization effort Cross-federations needed (imply IdP chaining)  National: MyID for public sector  Nordic: Kalmar Union for higher education and research  International: eduGAIN, InCommon? Service Oriented Architecture (implies ID-WSF)  Services talk on behalf of user to mediate content delivery

17 More information Information from Feide, including deployment status   for Feide:  Questions for Ingrid  Collaboration builds education

18 Campus Identity Provider benefits Authoritative quality for all affiliated users Control of information flow for all affiliated users Enhanced user management simplifies and automates business processes Federated login provides access to services One contract with Feide eliminates bi-lateral contracts with all service providers

19 Service Provider benefits Access for all Feide users No local administration of user database Feide handles login and gives high quality data about users One contract with Feide eliminates bi-lateral contracts with all identity providers

20 User benefits One username One password (or other credential) Do not need to register information at each service, automatic updates from campus information Informed consent for personal data transfer Familiar log-in page may increase security