Authentication and Authorization in a federated environment Jules Wolfrat (SARA)

Slides:



Advertisements
Similar presentations
Identity Network Ideals – Heterogeneity & Co-existence
Advertisements

EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
Federated Identity Management for Researchers – A quick overview from GÉANT BoF TNC May 2014 Dublin.
Federated Identity Management for Research Communities (FIM4R) David Kelsey (STFC-RAL) EGI TF, AAI workshop 19 Sep 2012.
The ICAR Federated Identity Model Massimiliano Pianciamore, CEFRIEL Francesco Meschia, CSI-Piemonte
FIM-ig Federated Identity Management Interest Group.
Federated A(A(A))I Jens Jensen hepsysman, RAL,
Security Incident Response Trust Framework for Federated Identity (Sir-T-Fi) David Kelsey (STFC-RAL) REFEDS, Indianapolis 26 Oct 2014 and now abbreviated.
EGI-Engage EGI-Engage Engaging the EGI Community towards an Open Science Commons Project Overview 9/14/2015 EGI-Engage: a project.
BoF: Federated Identity Management for Researchers David Kelsey (STFC-RAL) TNC2014, Dublin 20 May 2014.
AARC Overview Licia Florio, David Groep 21 Jan 2015 presented by David Groep, Nikhef.
Climate Sciences: Use Case and Vision Summary Philip Kershaw CEDA, RAL Space, STFC.
Federated Identity and the International Research Community Dr Ken Klingenstein Director, Internet2 Middleware and Security.
Federated Identity Management for HEP David Kelsey WLCG GDB 9 May 2012.
EMI AAI Strategy & Plans John White / Helsinki Institute of Physics Federated Identity Systems for Scientific Collaborations Workshop , CERN,
EMI INFSO-RI AAI in EEF Projects John White (Helsinki University) EMI Security Area Leader.
Authentication and Authorisation for Research and Collaboration Licia Florio (GÉANT) Christos Kanellopoulos (GRNET) Service orientation.
European Life Sciences Infrastructure for Biological Information Life science community update for the 7 th Federated Identity Management.
ShibGrid: Shibboleth access to the UK National Grid Service University of Oxford and STFC.
AAI WG EMI Christoph Witzig on behalf of EMI AAI WG.
7 th FIM 4 R meeting April 2014 ESRIN Frascati.
EResearchers Requirements the IGTF model of interoperable global trust and with a view towards FIM4R AAI Workshop Presenter: David Groep, Nikhef.
Federated Identity Management for Research Collaborations Bob Jones, CERN Daan Broeder, Max-Planck Institute for Psycholinguistics David Kelsey, Particle.
Authentication and Authorisation for Research and Collaboration Licia Florio REFEDS Meeting The AARC Project I2 Technology Exchange.
Authentication and Authorisation for Research and Collaboration Licia Florio AARC Workshop The AARC Project Brussels, 26 October.
Authentication and Authorisation for Research and Collaboration David Kelsey AARC AHM Milan And mechanisms NA3 Task 4 – Scalable.
Authentication and Authorisation for Research and Collaboration Peter Solagna Milano, AARC General meeting Current status and plans.
Authentication and Authorisation for Research and Collaboration Peter Solagna Milano, AARC General meeting Current status and plans.
Identity Management in DEISA/PRACE Vincent RIBAILLIER, Federated Identity Workshop, CERN, June 9 th, 2011.
Federated Identity Management for HEP David Kelsey HEPiX, IHEP Beijing 18 Oct 2012.
Authentication and Authorisation for Research and Collaboration Christos Kanellopoulos Open Day Event: Towards the European Open.
A European Open Science Cloud
Federated Identity Management for Scientific Collaborations The Common Vision David Kelsey (STFC) 3 Nov 2011.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
Networks ∙ Services ∙ People Thomas Bärecke Journée Fédération, Paris Collaboration européenne GÉANT SA5 03/07/2015 SA5 T5 team
Connect communicate collaborate Trust & Identity EC meets GÉANT 19 June 2014 Brussels Valter Nordh, NORDUnet Federation as a Service Task Leader Trust.
Research Community Requirements Ann Harding, SWITCH Cambridge July 2014.
Networks ∙ Services ∙ People Marina Adomeit FIM4R meeting Virtual Organisation Platform as a Service VOPaaS Nov 30, 2015, Austria Task Leader,
European Grid Initiative AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
AAI needs of the Distributed Computing Infrastructures - CLARIN Dieter Van Uytvanck Max Planck Institute for Psycholinguistics
Case Studies in Federated Identity Management for Research Communities Ann Harding, SWITCH/GN3plus Peter Gietz, DAASI International GmbH/DARIAH Tommi Nyro.
Connect communicate collaborate Case Studies in Federated Identity Management for Research Communities Ann Harding, SWITCH/GN3plus Peter Gietz, DAASI International.
David Groep Nikhef Amsterdam PDP & Grid AARC Authentication and Authorisation for Research and Collaboration an impression of the road ahead.
Federated Identity Management for Research Communities: FIM4R PSI workshop objectives Bob Jones, CERN.
Authentication and Authorisation for Research and Collaboration Licia Florio AARC CORBEL Workshop The AARC Project Paris, 31 May.
Networks ∙ Services ∙ People Marina Adomeit TNC16 Conference, Prague Towards a platform for supporting collaboration GÉANT VOPaaS
Authentication and Authorisation for Research and Collaboration Peter Solagna, Nicolas EGI AAI integration experiences AARC Project.
Authentication and Authorisation for Research and Collaboration David Kelsey AARC AHM Utrecht NA3 Task 4 – Scalable Policy Negotiation.
Authentication and Authorisation for Research and Collaboration AARC/CORBEL Workshop for Life Sciences AAI AARC Draft Blueprint.
Research Community Requirements (FIM4R) David Kelsey (STFC-RAL) VAMP Workshop 6 Sep 2012.
SCI & Sirtfi David Kelsey (STFC-RAL) EGI Conference, Lisbon 19 May 2015.
Welcome to 11th FIM4R 11th Meeting, Montréal September 2017
Introduction to AAI Services
WLCG Update Hannah Short, CERN Computer Security.
User Community Driven Development in Trust and Identity
Case Studies in Federated Identity Management for Research Communities
AAI Alignment Nicolas Liampotis (based on the work of Mikael Linden)
Federated Identity Management for Researchers (FIM4R)
EGI Security Policy Update
CLARIN Federated Identity Vision
Incident Response for Federated Identities
Federated Identity Management for Scientific Collaborations
The AARC Project Licia Florio (GÉANT) Christos Kanellopoulos (GRNET)
The AARC Project Licia Florio AARC Coordinator GÉANT
AARC Blueprint Architecture and Pilots
AAI Architectures – current and future
Community AAI with Check-In
Brian Matthews STFC EOSCpilot Brian Matthews STFC
FIM4R Requirements where GN3+ (SA5) is Active and Involved (9/2013)
Check-in Identity and Access Management solution that makes it easy to secure access to services and resources.
Presentation transcript:

Authentication and Authorization in a federated environment Jules Wolfrat (SARA)

2 Overview Introduction Federation initiatives Trust building PRACE federation 2

Introduction Authentication and Authorisation are different activities but highly related, so can be confusing Identity mgmt is basis for authentication Access mgmt is separate but depends on the identity mgmt Different technologies: LDAP, Kerberos, GSI (X.509), SAML, etc. 3

Identity Provider (IdP) Provides electronic information about an entity (user) –Can be anything: employer, state (electronic id card), science community, infrastructure Information is released based on authentication by user and/or service Authentication based on: login/password, e-tokens (SecureId, X.509, Kerberos, SAML assertion) Difference between IdPs and AAs (Attribute Authorities) but basically both release information about an entity –AA used for authorisation 4

Federated IdPs 5 Identity Provider (IdP) IdP Discovery Service Service User (1) WAYF (2) Token (3) (4) Service examples: eduroam, TCS, ….

Federation of IdPs Enables sharing of attributes ( address, telephone number, organisation, etc.) Single Sign-On (SSO), based on single IdP, e.g. your organisation For sharing of data in different domains Merging of information may be needed –For authorisation, e.g. for access to PRACE system authentication by your organisation won’t be enough –Example: VOMS service will add additional information to your proxy certificate –Problem of different formats 6

FIM for research collaborations (FIM4R) Issue of IdM raised by IT leaders from EIROforum labs (Jan 2011) –CERN, EFDA-JET, EMBL, ESA, ESO, ESRF, European XFEL and ILL These laboratories, as well as national and regional research organizations, are facing similar challenges – Scientific data deluge means massive quantities of data –needs to be accessed by expanding user bases in dynamic collaborations across organisational and national boundaries “Facebook” generation demands all the tools (work & social) integrate smoothly Also encouraged by EEF and eIRG Global problem, not just EU This and following based on slides courtesy of David Kelsey (STFC-RAL, UK) 7

FIM4R (2) A collaborative effort started in June 2011 Not just EIROForum. includes many ESFRI projects and providers and infrastructures (including PRACE) Involves photon & neutron facilities, social science & humanities, high energy physics, climate science, life sciences and fusion energy Workshops included participation by HTC and HPC infrastructures, TERENA, IGTF, Geant/eduGAIN, middleware developers … 8

FIM4R (3) Four workshops held with representatives of research communities and infrastructures 4 th : Paper produced with requirements and recommendations: Federated Identity Management for Research Collaborations 9

FIM4R vision statement A common policy and trust framework for Identity Management based on existing structures and federations either presently in use by or available to the communities. This framework must provide researchers with unique electronic identities authenticated in multiple administrative domains and across national boundaries that can be used together with community defined attributes to authorize access to digital resources 10

Federation requirements User friendliness –Many users use infrequently Browser and non-browser federated access Bridging between communities Multiple technologies and translators –Translation will often need to be dynamic Open standards and sustainable licenses –For interoperability and sustainability Different Levels of Assurance –When credentials are translated, LoA provenance to be preserved –Authorisation under community and/or facility control –Externally managed IdPs cannot fulfil this role 11

Federation requirements (2) Well defined semantically harmonised attributes –For interoperable authorisation –Likely to be very difficult to achieve! Flexible and scalable IdP attribute release policy –Different communities and different SPs need different attributes –Negotiate with IdF not all IdPs – for scaling Attributes must be able to cross national borders –Data protection/privacy considerations Attribute aggregation for authorisation Privacy and data protection to be addressed with communitywide individual identities –We need to identify individuals E.g. ethical committees can require names, addresses, supervisors to grant access 12

Study on AAA Platforms For Scientific data/information Resources in Europe Project by consortium of four partners, led by TERENA, funded by EU. Report published: /AAA-Study-Report pdf?version=1&modificationDate= https://confluence.terena.org/download/attachments/ /AAA-Study-Report pdf?version=1&modificationDate= The goal of this study, prepared for the European Commission, is to evaluate the feasibility of delivering an integrated AAI, to help the emergence of a robust platform for access and preservation of scientific information within a Scientific Data Infrastructure (SDI). 13

Trust building Trust needed between IdPs/federations and service providers –LoA for provided data IGTF for policy management authorities for trusted Certificate Authorities –Privacy requirements must be respected by SPs –TERENA/GEANT produced a Code of Conduct document _GEANT_Data_Protection_Code_of_Conduct_21Jun2012.pdf 215_GEANT_Data_Protection_Code_of_Conduct_21Jun2012.pdf Signed by an SP it should enable the release of attributes by IdPs No need of individual contracts. 14

 European HPC-facilities at the top of an HPC provisioning pyramid –Tier-0: 3-6 European Centres for Petaflop –Tier-0: ? European Centres for Exaflop –Tier-1: National Centres –Tier-2: Regional/University Centres  Creation of a European HPC ecosystem –Scientific and industrial user communities –HPC service providers on all tiers –Grid Infrastructures –The European HPC hard- and software industry 15 The ESFRI Vision for a European HPC service Tier-0 Tier-1 Tier-2 PRACE DEISA/PRACE capability # of systems

Tier-0/Tier-1 infrastructure 16 Tier-0 Tier-1 infrastructure 22 sites by the end of 2012 Tier-0: All > Pflops. 4 are in the top 10 of the June Top500 list

PRACE federation User attributes are shared using LDAP facilities Based on trust between partners –Operational procedures are documented in AAA administration guide –All partners have access to the data Advantage is easy to add or adapt attributes (e.g. new values). SSO based on X.509 certificates, using IGTF as trust basis 17

There is still some work to be done 18

References Fourth workshop on Federated Identity Management for Scientific Collaborations (FIM4R) –Vision document: TERENA workshop on AAA study report: Study-Report-0907.pdf?version=1&modificationDate= Study-Report-0907.pdf?version=1&modificationDate=