The Rise of Federations…Almost Everywhere. Topics Federation Basics Drivers Components International and pulic sector developments InCommon and its uses.


Similar presentations
The Basics of Federated Identity. Overview of Federated Identity and Grids Workshop Session 1 - for all Basics and GridShib Session 2 – more for developers.

The Art of Federations. Topics Federations of what… Federated identity versus federations Federations in other sectors – business, gov, ad hoc R&E Federations.
From Authentication to Privilege Management to the Attribute Economy: Marketing runs amok…
Trends in Identity Management Nate Klingenstein Internet2 EDUCAUSE Security Professional 2007.
Federated Access: Identity Management and Access to Protected Resources Renée Woodten Frost Associate Director, Middleware & Security
Federations in Texas Barry Ribbeck University of Texas Health Science Center at Houston.
Internet2 and other US WMD Update. Topics Update on non-merger, Newnet (and the control plane), InCommon and other feds “Product” update – Shib, Grouper,
Drive-By Dialogues. Presenter’s Name Topics The Long Strange Trip of I2 – NLR Merger A Brief Comment on Optical Networking Middleware Developments Security.
1 Issues in federated identity management Sandy Shaw EDINA IASSIST May 2005, Edinburgh.
Internet Scale Identity, Collaboration and Higher Education.
Some Frontier Issues from the Wild, Wild West Ken Klingenstein.
Agenda Project beginnings and funding. Purpose of the federation. Federation members. Federation protocols. Special features in our federation. Pilot.
Presenter’s Name InCommon Approximately 80 members and growing steadily More than two million “users” Most of the major research institutions (MIT joining.
1 Governance in Identity Management Federations Clair Goldsmith, Ph.D. The University of Texas System Administration.
EAuthentication in Higher Education Tim Bornholtz Session 58.
InCommon Policy Conference April Uses  In order to encourage and facilitate legal music programs, a number of universities have contracted with.
New CyberInfrastructure for Collaboration between Higher Ed and NIH.
1 Update on the InCommon Federation, Higher Education’s Community of Trust EDUCAUSE 2005 October 19 10:30am-11:20am.
Updates on Shib, a bit of InCommon and International Federations.
1 Leveraging Your Existing Campus Systems to Access Resource Partners: Federated Identity Management and Tales of Campus Participation Clair Goldsmith,
Welcome to CAMP Identity Management Integration Workshop Ann West NMI-EDIT EDUCAUSE/Internet2.
Federations and Security: A Multi-level Marketing Scheme Ken Klingenstein Director, Internet2 Middleware and Security.
Intro to Identity for Developers Tom Barton, U Chicago Scott Cantor, Ohio State Patrick Michaud, U Washington.
The InCommon Federation The U.S. Access and Identity Management Federation
Interfederation RL “Bob” Morgan University of Washington and Internet2 Digital ID World 2005 San Francisco.
1 The Partnership Challenge Higher education’s missions are realized in increasingly global, collaborative, online relationships –Higher educations’ digital.
1 The InCommon Federation John Krienke Internet2 Spring Member Meeting Tuesday, April 25, 2006.
External Identity and Authorization in GENI. Topics Federated identity and virtual organizations ABAC Creating and transporting attributes.
Federations: success brings new challenges Ken Klingenstein Director, Internet2 Middleware and Security.
InCommon, other federations, the attribute ecosystem, and some killer apps needing guns…
Campus middleware in the service of Science Keith Hazelton Internet2 Middleware Architecture Committee for Education NSF Internet2 Day October 19, 2006.
Australian Access Federation and other Middleware Initiatives Presented at TF-EMC2, Prague 4 Sep 2007 Patty McMillan, The University of Queensland.
Federated Identity Management for HEP David Kelsey WLCG GDB 9 May 2012.
VO and Internet2 Middleware. Presenter’s Name Topics Motivations for Internet2 Middleware work Federated identity and InCommon Other IdM Groups, privileges,
GridShib: Grid/Shibboleth Interoperability September 14, 2006 Washington, DC Tom Barton, Tim Freeman, Kate Keahey, Raj Kettimuthu, Tom Scavo, Frank Siebenlist,
NSF Middleware Initiative Renee Woodten Frost Assistant Director, Middleware Initiatives Internet2 NSF Middleware Initiative.
Shibboleth A Federated Approach to Authentication and Authorization Fed/Ed PKI Meeting June 16, 2004.
E-Authentication: Simplifying Access to E-Government Presented at the PESC 3 rd Annual Conference on Technology and Standards May 1, 2006.
Internet2 Middleware Initiative. Discussion Outline  What is Middleware why is it important why is it hard  What are the major components of middleware.
1 InCommon Identity & Access Management Federation John Krienke Operations Manager, InCommon Assistant Director, Internet2
Federated Access to US CyberInfrastructure Jim Basney CILogon This material is based upon work supported by the National Science.
Federations 101 John Krienke Internet2 Fall 2006 Internet2 Member Meeting.
Integrated Institutional Identity Infrastructure: Implications and Impacts RL “Bob” Morgan University of Washington Internet2 Member Meeting, May 2005.
Scared Straight… if you want to go outside… Authenticate Locally, Act Globally.
1 Protection and Security: Shibboleth. 2 Outline What is the problem Shibboleth is trying to solve? What are the key concepts? How does the Shibboleth.
National Authentication and Authorization Infrastructures and NRENs Ken Klingenstein Director, Internet2 Middleware and Security.
Internet2: building and using an advanced network environment for research, teaching and learning APRU CIO Forum, 23 March 2007 Heather Boyles,
Shibboleth Update Eleventh Federal & Higher Education PKI Coordination Meeting (Fed/Ed Thursday, June 16, 2005.
Federated Authentication at NIH: Trusting External Credentials at Known Levels of Assurance Debbie Bucci and Peter Alterman November, 2009.
Middleware Futures Internet2 Member Meeting Arlington VA, April 2006 RL “Bob” Morgan, University of Washington and Internet2.
University of Washington Identity and Access Management IEEAF – RENU Network Design Workshop Seattle - 29 Nov 2007 Lori Stevens, Director, Distributed.
Shibboleth: Molecules, Music, and Middleware. Outline ● Terms ● Problem statement ● Solution space – Shibboleth and Federations ● Description of Shibboleth.
Federated Identity Management at NIH…NIH Login and Beyond Debbie Bucci September 2009.
Shibboleth & Federated Identity A Change of Mindset University of Texas Health Science Center at Houston Barry Ribbeck
AAI in Europe ++ Ken Klingenstein Director, Internet2 Middleware and Security.
Transforming Government Federal e-Authentication Initiative David Temoshok Director, Identity Policy and Management GSA Office of Governmentwide Policy.
Welcome to Base CAMP: Enterprise Directory Deployment Ken Klingenstein, Director, Internet2 Middleware Initiative Copyright Ken Klingenstein This.
Federated Identity in the Global Landscape. Presenter’s Name Topics Federated identity basics International deployments and issues National, local and.
InCommon® for Collaboration Institute for Computer Policy and Law May 2005 Renee Shuey Penn State Andrea Beesing Cornell David Wasley Internet 2.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
InCommon Federation: Federating Relationships. Topics Administration Library Research Student Services Personal and Collaborative Applications Federal.
01 October 2001 “...By Any Other Name…”. Consequences and Truths (Ken) The Pieces and the Processes (Bob) Directories (Keith) Shibboleth and SAML (Scott)
Networks ∙ Services ∙ People Licia Florio TNC, Lisbon Consuming identities across e- Infrastructures 16 June 2015 PDO GÈANT.
Tom Barton, Senior Director for Integration, University of Chicago
Shibboleth Roadmap
John O’Keefe Director of Academic Technology & Network Services
New CyberInfrastructure for Collaboration between Higher Ed and NIH
Context, Gaps and Challenges
Updates on Shib, a bit of InCommon and International Federations
Presentation transcript:

The Rise of Federations…Almost Everywhere

Topics Federation Basics Drivers Components International and pulic sector developments InCommon and its uses Next steps for federations Peering, confederation, and similar issues Support for collaboration and virtual organizations Development of other aspects of the attribute ecosystem Libraries and federations in the US Issues and opportunities Next steps

Middleware vision in one slide Build a campus/enterprise core middleware infrastructure that Serves the overall enterprise IT environment, providing business drivers and institutional investment for sustainability and scalability Is designed from the start to support the research and instructional missions Implies consistent approaches and common practices across campuses and internationally Build, plumb, and replumb the tools of research on top of that emergent infrastructure Domain-specific middleware (grids, sensor nets, etc) Common collaboration tools (video, protected wikis, shared calendaring, audioconferencing, etc.)

Federated identity Leveraging enterprise identity management beyond the enterprise Creates general purpose interrealm trust fabrics Standards (SAML) and open source (Shibboleth) well aligned and gaining broad adoption Persistent and broad R&E federations in many countries now

Drivers Campuses want to allow their community to use their local credentials to access external partners in academia, government, businesses, etc. Relying Parties want to use campus authn For economies Not another sso to incorporate into the app Avoid much of the costs of account management For scaling in users Interest is tempered by legal considerations, policy considerations, and unintended disruptive economic consequences

Uses - Content To protect IPR (the JSTOR incident…) To open up markets Popular content – Ruckus, CDigix, etc MS Scholarly content – Google, OCLC WorldCat Scope of IdM may be an issue

Services Student travel, charitable giving, web learning and testing, plagiarism testing service, etc. Allure for alumni services and other internal businesses Student loans, student testing, graduate school admissions, etc. The Teragrid

Government NSF Fastlane Grant Submission Dept of Agriculture Permits Social Security NIH Dept of Ed

Components of Federation Federating Software Federation operator and metadata Participants Policies on identity management Policies on privacy Shared set of attributes, including LOA Legal agreements among participants Management and governance (Peering, economics,…)

International Federations Widespread in Europe (over 15 countries), emergent in Australia, nascent in Asia. The UK federation ( already has over five million active users and intends to grow to all of higher ed, K-12 and further education. Used for academic content access, research support, national level services, etc Clear needs for peering; some need for confederation or dynamic relationships.

Public sector federations State-based among health agencies (NY), presenting a SSO to citizens (Washington), etc. GSA EAuthentication NSF, NIH, and the Dept of Ed… State university federations - Texas, California, Maryland, etc InCommon

UTexas Federation Apps Project Tracking (CHA) Monthly Financial Reporting (BUD) TIXX (GOV) UT Plane (ADM) Compliance Training (ADM) Research Projects Tracking (ACA) Academic Affairs Jobs (ACA) Degree Programs (ACA) Grad Registration (ACA) System Administration Wireless (OTIS) Legal Tracking (OGC) Parking Management (APS) Signature Authority (APS) Bid Specification (OFPC) Project Time Reporting (OFPC) Student Couponing (UT Austin) Online Education via Blackboard (UTHSCH) Board of Regents Agenda (BOR) 12/06 Budget Change Request (BUD) 12/06 UTANOP (BUD) 12/06

InCommon US R&E Federation Members join a 501(c)3 Addresses legal, LOA, shared attributes, business proposition, etc issues Approximately 50 members and growing A low percentage of national Shib use…

InCommon Members 2/27/07 Case Western Reserve University Clemson University Cornell University Dartmouth Duke University Florida State University Georgetown University Miami University New York University Ohio University Penn State Stanford University Stony Brook University SUNY Buffalo The Ohio State University The University of Chicago University of Alabama at Birmingham University of California, Irvine University of California, Los Angeles University of California, Merced University of California, Office of the President University of California, Riverside University of California, San Diego University of Maryland University of Maryland Baltimore County University of Maryland, Baltimore University of Rochester University of Southern California University of Virginia University of Washington University of Wisconsin - Madison Cdigix EBSCO Publishing Elsevier ScienceDirect Houston Academy of Medicine - Texas Medical Center Library Internet2 JSTOR Napster, LLC OCLC OhioLink - The Ohio Library & Information Network ProtectNetwork Symplicity Corporation Thomson Learning, Inc. Turnitin WebAssign

Key aspects of InCommon Federating software Shib 1.2+ (other possibilities in the future) Shared attributes and schema eduPerson right now Levels of authentication POP (participant operational practices) InCommon Bronze and Silver will map to LOA 1 & 2 Management Steering committee of members IT executives Operations staffed by Internet2

Shibboleth Shib 1.3 widely deployed; 1.2 still common Along the way, other capabilities added: ADFS compatibility for WS-Fed, (MS $) Eauthentication certification (with waiver form:)) Shib 2.0 completes the SAML+Shib integration More compatible with COTS SAML 2.0 products than they are with each other A Shib/SAML to TCP/IP analogy isn’t bad; Shib adds multi-party federation support through metadata, ARPS, etc. Also eases support for n-tier, non-web and other capabilities Alpha in April

The Shibboleth 2.0 Sidebar Support for the attribute ecosystem attribute handling, including policy, in both SP and IdP designed to be reusable for other protocols (eg CardSpace) sets stage for further work on multiple attribute sources, reputation management, etc. All Java SP (in addition to current Java/Apache), easing integration for some applications Trust management PKI still seems too hard, even at the simpler enterprise level Supports a broad set of trust choices – CA’s, certs, plain keys, managing site metadata (naming, acquisition, validating) A product of years of painful experience

InCommon Management/Governance Steering Committee of campus/vendor CIO’s and policy people – sets policies for membership, business model, etc. Technical advisory committee - Sets common member standards for attributes (eduPerson 2.0), identity management good practices, etc.

InCommon Uses Access control to content Popular content – Ruckus, CDigix, etc Scholarly content – Google, OCLC WorldCat Downloads – Microsoft Access to external services Student travel, charitable giving, web learning and testing, plagiarism testing service, etc. Allure for alumni services and other internal businesses Student loans, student testing, graduate school admissions, etc. Access to national services The National Science Digital Library The Teragrid pilot

Inter-federation key issues Peering, peering, peering At what size of the globe? Confederation, overlapping, leveraged Tightly coupled autonomous federations How do vertical sectors relate? How to relate to a government federation? On what policy issues to peer and how? Legal framework Treaties? Indemnification? Adjudication How to technically implement Wide variety of scale issues WAYF functionality Virtual organization support

Virtual Organizations The big team science efforts, and smaller collaborations across a broad set of disciplines with real resources to be managed seriously Have their own IdM issues Collaboration tools Domain science identity management Today’s solutions are non-existent, insecure or widely despised… Could leverage federated identity for both ease of use and better security

Peering Parameters: LOA Attribute mapping Legal structures Liability Adjudication Metadata VO Support Economics Privacy

VOs plumbed to federations

The Attribute Ecosystem We now understand, we think, an overall “attribute ecosystem” Shibboleth is the real-time transport of attributes from an IdP to an SP for an authorization decision Other, “compile-time” means are used to ship attributes from sources of authority to IdP Or to the SP, or to the various middlemen (portals, proxies, etc.) And a user needs to be manage all of this

Libraries and Shib in the US Not the driver that it is overseas Content acquisition at local versus national levels Poor communication between campus IT management and library management Many universities have Shib in some form of deployment; very few use it for library content access Preference of patron db for authentication and authorization over central directory services Failure of Internet2 to publicize the many hybrid models available (eg IP address on campus, Shib for off campus, with or without SSO)

Libraries and Shib in the US Misunderstandings on Shibboleth and privacy Shibboleth is privacy preserving Institutions and users can change that “Extra step” of authentication Confusion about the relationship of federations and licenses Shibboleth is not worth the work since some form of IP address control will always be needed Too many publishers Additional features not worth the work

The “Stepping Up” Group University of Chicago, Penn State University, UCSD, and the University of Maryland System Library Consortium InCommon-library-services Identity issues in technology, user experience, policy, and practices for access to external licensed resources (Identify opportunities for value-added services that leverage infrastructure) Report back…

First thoughts… Internal SP’s Different policies for walk-ins and remote People not in the institutional db – paid alumni… PKI management in trust Students working as RA’s and proxies for faculty Looking up ARP’s for various SP

Opportunities Integration with repositories NITLE and its offerings… NSDL type collaborations Collaboration tool platforms New joint licensing possibilities