Feide is a identity management system on a national level for the educational sector in Norway. Federated Electronic Identity for Norwegian Education Tromsø,

Slides:



Advertisements
Similar presentations
Federated Access implementation: experience of AUCA Library - Kyrgyzstan 4 th -7 th June, 2008, Aberdeen, Scotland Sania Battalova, EIFL Country and FOSS.
Advertisements

© GT/SAPP/USIT University of Oslo, Norway Cerebrum, UoO new UAS Developing a 2 nd generatione of a single user- administration system for University of.
Defining the Security Domain Marilu Goodyear John H. Louis University of Kansas.
Access & Identity Management “An integrated set of policies, processes and systems that allow an enterprise to facilitate and control access to online.
KC-ROLO Project Kidderminster College Repository Of Learning Objects Graham Mason & Ed Beddows.
Research and Innovation Participant Portal How to register for an ECAS account NEXT.
The Internet2 NET+ Services Program Jerry Grochow Interim Vice President CSG January, 2012.
ELAG Trondheim Distributed Access Control - BIBSYS and the FEIDE solution Sigbjørn Holmslet, BIBSYS, Norway Ingrid Melve, UNINET, Norway.
Building the Future: Millennium’s Relationship with Campus Systems and Services John Culshaw Faculty Director for Systems University of Colorado at Boulder.
2006 © SWITCH Authentication and Authorization Infrastructures in e-Science (and the role of NRENs) Christoph Witzig SWITCH e-IRG, Helsinki, Oct 4, 2006.
1 Issues in federated identity management Sandy Shaw EDINA IASSIST May 2005, Edinburgh.
Employment Eligibility Verification Andrea Hubbard, OSUP.
June 1, 2001 Enterprise Directory Service at College Park David Henry Office of Information Technology University of Maryland College Park
Identity and Access Management IAM. 2 Definition Identity and Access Management provide the following: – Mechanisms for identifying, creating, updating.
Identity and Access Management IAM A Preview. 2 Goal To design and implement an identity and access management (IAM) middleware infrastructure that –
Identity Management – Why and How Experiences at CU-Boulder Copyright Linda Drake, Director of Development and Integration, University of Colorado, Boulder,
Managing Information UT November 13-14, 2008 Campus Identity and Access Management Services.
Objectives Understand what a portal is and why we need one Understand what MoCoMotion is Learn the benefits of MoCoMotion Understand the security issues.
Educause 2006, Dallas TX What does a University need from Access Management? John Paschoud InfoSystems Engineer, LSE Library London School of Economics.
Identity and Access Management (IAM) What’s in it for Me? NC State University - Computer Security Day October 26, 2009 Mark Scheible Manager, Identity.
AAI with simpleSAMLphp
Utdanning.no (translated: A governmental service-oriented repository strategy. Trond Håvard Hanssen Project manager.
Use case: Federated Identity for Education (Feide) Identity collaboration and federation in Norwegian education Internet2 International Workshop, Chicago,
Australian Access Federation Robert Hazeltine Identity and Access Management Enterprise Systems Office.
CASE: Haka federation EuroCAMP, 3-5 April, 2006 CSC, the Finnish IT Center for Science
To begin the process of activating your account simply click on this link (the directions are in the ). You may also copy the link and paste it into.
UFD ICT in education in Norway Thorvald Astrup, OMEC-OCDE-Canada Seminar, Montreal april 2002 Royal Ministry of Education and Research.
National eInfrastructure Seminar on infrastructures for research data 17. February 2012
Case Study: DirXML Implementation at Waste Management Rick Wagner Systems Engineer Novell, Inc.
NELLI - INFORMATION RETRIEVAL PORTAL. NELLI Information retrieval portal National ELectronic Library Interface One interface to all material –Licensed.
Federated or Not: Secure Identity Management Janemarie Duh Identity Management Systems Architect Chair, Security Working Group ITS, Lafayette College.
HAKA project HAKA User administration inside Finnish Higher Education Institutes results from the KATO project Barbro Sjöblom EDS 2003 Uppsala.
Shibboleth as Attribute Delivery for Authorization Renee Shuey Penn State University June 27, 2006.
Top Issues Facing Information Technology at UAB Sheila M. Sanders UAB Vice President Information Technology February 8, 2007.
Shibboleth Update Michael Gettes Principal Technologist Georgetown University Ken Klingenstein Director Interne2 Middleware Initiative.
UCLA Enterprise Directory Identity Management Infrastructure UC Enrollment Service Technical Conference October 16, 2007 Ying Ma
1 SMART Training Update – May 2011 Michaela Butterworth.
Empowering people-centric IT Unified device management Access and information protection Desktop Virtualization Hybrid Identity.
Erie 1 BOCES / WNYRIC eBOCES applications Visit us at:
Automated (meta)data collection – problems and solutions Grete Christina Lingjærde and Andora Sjøgren USIT, University of Oslo.
MAT U M A T U Middleware Assisted Take-Up Service For JISC Funded Early Adopters.
Internet2 Middleware Initiative Shibboleth Ren é e Shuey Systems Engineer I Academic Services & Emerging Technologies The Pennsylvania State University.
Baltic IT&T, Riga 2007 Identity Management within the educational sector in Norway Senior Adviser Jan Peter Strømsheim, Norwegian ministry of Education.
FSU Metadirectory Project The Issue of Identity Management Executive Overview.
Federation Building Blocks EuroCAMP, Malaga 18 Oct 2006 Julie Frøseth, UNINETT.
Community Sign-On and BEN. Table of Contents  What is community sign-on?  Benefits  How it works (Shibboleth)  Shibboleth components  CSO workflow.
University of Washington Identity and Access Management IEEAF – RENU Network Design Workshop Seattle - 29 Nov 2007 Lori Stevens, Director, Distributed.
/ 8 FEIDHE Electronic Identification in Finnish Higher Education Janne Kanner FEIDHE Electronic Identification in Finnish Higher Education.
PORTALS WORKSHOP REPORT (group 7) ELAG 2004 Trondheim, Norway
Federations: The New Infrastructure Speaker Name Here Date Here Speaker Name Here Date Here.
2003 © SWITCH Authentication and Authorisation Infrastructure - AAI Christoph Graf Project Leader AAI SWITCH.
KC-ROLO Project Kidderminster College Repository Of Learning Objects Graham Mason & Ed Beddows.
Shibboleth for Middle Schools James Burger -
 Luminis is a SunGard product intended to maximize Banner integration.  The Luminis TM Platform has been designed to provide a web portal with integrated.
Education Portal Solutions for Higher Education Education portals create a common gateway to the data and services that the people throughout your university.
1 Name of Meeting Location Date - Change in Slide Master Authentication & Authorization Technologies for LSST Data Access Jim Basney
Community Sign-On and BEN. Table of Contents  What is community sign-on?  Benefits  How it works (Shibboleth)  Shibboleth components  CSO workflow.
Using Your Own Authentication System with ArcGIS Online
Federated Identity Management at Virginia Tech
Campus Administrator Training March 2, 2012
Use case: Federated Identity for Education (Feide)
Punching data to the authentication server
ESA Single Sign On (SSO) and Federated Identity Management
Shibboleth as Attribute Delivery for Authorization
People Admin / Select Suite
Research4Life Programmes: Similarities and Differences! (Part A)
Feide status TF-EMC2, Malaga 17 Oct 2006 Julie Frøseth, UNINETT
KC-ROLO Project Kidderminster College – Repository Of Learning Objects
Presentation transcript:

Feide is a identity management system on a national level for the educational sector in Norway. Federated Electronic Identity for Norwegian Education Tromsø, the world’s nothernmost university city

 A service provider that is implementing FEIDE FEIDE is managed by UNINETT  A portal owned by the Norwegian Ministry of Education and Research  National common gateway for easy access to everything you need to know about education Course description repository Occupations description repository, NEW Learning Content repository Learning content publishing framework

 A concept based on the principle that every user in the educational sector - pupil, student or employee - receives a user name from their school, college or university, which can be used throughout the sector (both commercial and public services)  FEIDE is partly founded by institutions (campuses and service providers) and partly founded directly by the Ministry

 One username  One password  Do not need to register information at each service, automatic updates from campus information  Informed consent for personal data transfer  Familiar log-in page may increase security

 Access for all Feide users  No local administration of user database  Feide handles login and gives high quality data about users  One contract with Feide eliminates bi- lateral contracts with all identity providers

 Goal: all public schools in 2010  Today Universities: All operative University college: 75 % Upper secondary school (high school): 50%  100% during summer 2009 primary and lower secondary school  Only started Aproach Institutional Local Authority

 Based on SAML 2.0 (Not shibboleth witch is SAML 1.0 based)  Single sign-on  All log-on is run through feide.no as a middleware service  All user data is controlled and maintained on campus institutions (LDAP)

 Bibsys.no (Sentralized library service) Bibsys.no  Fag.utdanning.no Fag.utdanning.no

 The chicken and the egg The institutions hesitated to implement FEIDE because the lack of services The Service providers hesitated to implement because the lack of users  We have to identity providers in Norway 1.FEIDE.no: Education identity provider 2.minside.no (mypage.no): governmental services (Tax, medical information, address of residence, unemployment benefits etc…. )

 Most ID-providers (campus) is using FEIDE password / username but with a local login routine and not single-sign-on It would be better if they where using the “FEIDE single sign-on” service for local services as well (LMS/VLE, etc ) Then the user would already be logged on at external services

 User are commonly redirected to an external login-page. This is bad usability and many users are confused by this  Data quality Few attributes are mandatory No attribute for subject or discipline User role not suited for the primary and lower secondary school  (student, employee, faculty, staff, alum, affiliate)

 Authorization to content The publishing industries want to have control of the business model  Personalization My subject, my curriculum, my content  Web 2.0 Get people together Same school, same subject  A closer connection to the VLE

 Personal identification number  FEIDE username )  User role (employee, student, member, faculty)  Name of the Organization the user are connected to. (legal name, short name, common name)  Given name and surname of user  (Username local institution)   Legal organization number

 7 universities, 46 university colleges ( persons)  Extensive collaboration on electronic services in higher education BIBSYS and other library services FS and MSTAS student registry systems Administrative systems: finance, HR, archive, invoice, High performance computing, super-computers and grids  Schools ( persons, plus parents) 454 upper secondary schools owned by 19 regions Around 4500 schools owned by 430 municipalities