© 2006 Open Grid Forum OGF20 LoA-RG Monday 11:00am Charter Suite 4 Chairs: Ning Zhang and Yoshio Tanaka.

Slides:



Advertisements
Similar presentations
© 2006 Open Grid Forum GHPN-RG Status update co-chairss:Cees de Laat Dimitra Simeonidou GGF22, Boston, February 2008.
Advertisements

© 2006 Open Grid Forum JSDL 1.0: Parameter Sweeps OGF 23, June 2008, Barcelona, Spain.
© 2006 Open Grid Forum Network Services Interface OGF30: Connection Services Guy Roberts, 27 th Oct 2010.
© 2006 Open Grid Forum Ellen Stokes, IBM Michel Drescher, Fujitsu Information Model, JSDL and XQuery: A proposed solution OGF-19 Chapel Hill, NC USA.
© 2006 Open Grid Forum Network Services Interface Introduction to NSI Guy Roberts.
© 2006 Open Grid Forum Federated Identity in the Cloud OGF 32, Salt Lake City.
© 2006 Open Grid Forum JSDL 1.0: Parameter Sweeps: Examples OGF 22, February 2008, Cambridge, MA.
© 2006 Open Grid Forum GridRPC Interoperability Test Response to comments Yusuke Tanimura.
© 2006 Open Grid Forum OGF19 Federated Identity Rule-based data management Wed 11:00 AM Mountain Laurel Thurs 11:00 AM Bellflower.
© 2007 Open Grid Forum JSDL-WG Session OGF27 – General Session 10:30-12:00, 14 October 2009 Banff, Canada.
©2010Open Grid Forum OGF28 OGSA-DMI Status Chairs: Mario Antonioletti, EPCC Stephen Crouch, Southampton Shahbaz Memon, FZJ Ravi Madduri, UoC.
© 2006 Open Grid Forum JSDL Session (CIM Job) OGF 21 - Seattle, 17 October 2007.
© 2006 Open Grid Forum Joint Session on Information Modeling for Computing Resources OGF 20 - Manchester, 7 May 2007.
© 2007 Open Grid Forum JSDL-WG Session OGF21 – Activity schema session 17 October 2007 Seattle, U.S.
© 2006 Open Grid Forum 2 nd March 09 Enterprise Grid Requirements Research Group OGF25 EGR-RG Session Group.
Oct 15 th, 2009 OGF 27, Infrastructure Area: Status of FVGA-WG Status of Firewall Virtualization for Grid Applications - Working Group
© 2006 Open Grid Forum OGSA Profiles Interoperability Testing Dr. David Snelling Fujitsu Laboratories of Europe.
© 2008 Open Grid Forum Resource Selection Services OGF22 – Boston, Feb
© 2006 Open Grid Forum Network Services Interface OGF29: Working Group Meeting Guy Roberts, 19 th Jun 2010.
© 2007 Open Grid Forum JSDL-WG Session 1 OGF25 – General Session 11:00-12:30, 3 March 2009 Catania.
© 2006 Open Grid Forum JSDL Optional Elements OGF 24 Singapore.
© 2007 Open Grid Forum Data/Compute Affinity Focus on Data Caching.
© 2007 Open Grid Forum OGSA-RUS Specification Update, Adoption and WS-RF Profile Discussions (Molly Pitcher) Morris Riedel (Forschungszentrum Jülich –
© 2006 Open Grid Forum Grid Resource Allocation Agreement Protocol GRAAP-WG working session 2 Wenesday, 17 September, 2008 Singapore.
© 2006 Open Grid Forum Joint Session on Information Modeling for Computing Resources (OGSA Modeling Activities) OGF 21 - Seattle, 16 October 2007.
© 2006, 2007 Open Grid Forum Michel Drescher, FujitsuOGF-20, Manchester, UK Andreas Savva, FujitsuOGF-21, Seattle, US (update) Extending JSDL 1.0 with.
© 2006 Open Grid Forum Network Services Interface OGF30: Working Group Meeting Guy Roberts, Inder Monga, Tomohiro Kudoh 27 th Oct 2010.
© 2009 Open Grid Forum Usage Record Working Group Alignment and Production Profile.
1 ©2013 Open Grid Forum OGF Working Group Sessions Security Area – FEDSEC Jens Jensen, OGF Security Area.
OGF26 Grid Information Retrieval Research Group May 26, 2008 Chapel Hill.
© 2006 Open Grid Forum DCI Federation Protocol BoF Alexander Papaspyrou, TU Dortmund University Open Grid Forum March 15-18, 2010, Munich, Germany.
© 2007 Open Grid Forum Data Grid Management Systems: Standard API - community development Arun Jagatheesan, San Diego Supercomputer Center & iRODS.org.
© 2006 Open Grid Forum Service Level Terms Andrew Grimshaw.
© 2010 Open Grid Forum Standards All Hands Meeting OGF28, München, March 2010.
© 2006 Open Grid Forum Network Services Interface OGF 32, Salt Lake City Guy Roberts, Inder Monga, Tomohiro Kudoh 16 th July 2011.
© 2010 Open Grid Forum OCCI Status Update Alexander Papaspyrou, Andy Edmonds, Thijs Metsch OGF31.
© 2007 Open Grid Forum JSDL-WG Session OGF22 – General Session (11:15-12:45) 25 February 2008 Boston, U.S.
© 2006 Open Grid Forum FEDSEC-CG Andrew Grimshaw and Jens Jensen.
© 2006 Open Grid Forum Activity Instance Schema Philipp Wieder (with the help of the JSDL-WG) Activity Instance Document Schema BoF Monday, 25 February,
© 2006 Open Grid Forum Network Services Interface OGF 33, Lyon Guy Roberts, Inder Monga, Tomohiro Kudoh 19 th Sept 2011.
© 2015 Open Grid Forum ETSI CSC activities Wolfgang Ziegler Area Director Applications, OGF Fraunhofer Institute SCAI Open Grid Forum 44, May 21-22, 2015.
© 2006 Open Grid Forum HPC Job Delegation Best Practices Grid Scheduling Architecture Research Group (GSA-RG) May 26, 2009, Chapel Hill, NC, US.
© 2006 Open Grid Forum GridRPC Working Group 15 th Meeting GGF22, Cambridge, MA, USA, Feb
© 2006 Open Grid Forum Network Services Interface CS Errata Guy Roberts, Chin Guok, Tomohiro Kudoh 29 Sept 2015.
© 2006 Open Grid Forum OGSA-WG: EGA Reference Model GGF18 Sept. 12, 4-5:30pm, #159A-B.
© 2006 Open Grid Forum FEDSEC-CG FEDerated infrastructure SECurity.
© 2006 Open Grid Forum Remote Instrumentation Services in Grid Environment Introduction Marcin Płóciennik Banff, OGF 27 Marcin Płóciennik.
© 2006 Open Grid Forum NML Progres OGF 28, München.
© 2008 Open Grid Forum PGI - Information Security in the UNICORE Grid Middleware Morris Riedel (FZJ – Jülich Supercomputing Centre & DEISA) PGI Co-Chair.
© 2007 Open Grid Forum OGF Management Area Meeting OGF20 7 May, am-12:30pm Manchester, UK.
© 2006 Open Grid Forum VOMSPROC WG OGF36, Chicago, IL, US.
© 2007 Open Grid Forum OGF20 Levels of the Grid Workflow Interoperability OGSA-WG F2F meeting Adrian Toth University of Miskolc NIIF 11 th May, 2007.
© 2008 Open Grid Forum Production Grid Infrastructure WG State Model Discussions PGI Team.
© 2007 Open Grid Forum JSDL-WG Session OGF26 – General Session 11:00-12:30, 28 May 2009 Chapel Hill, NC.
Network Services Interface
Welcome and Introduction
RISGE-RG use case template
GridRPC Working Group 13th Meeting
Grid Resource Allocation Agreement Protocol
OGF session PMA, Florence, 31 Jan 2017.
Sharing Topology Information
Network Services Interface
Network Services Interface Working Group
OGSA-Workflow OGSA-WG.
Network Measurements Working Group
WS Naming OGF 19 - Friday Center, NC.
Activity Delegation Kick Off
Network Services Interface Working Group
Introduction to OGF Standards
OGF 40 Grand BES/JSDL Andrew Grimshaw Genesis II/XSEDE
Presentation transcript:

© 2006 Open Grid Forum OGF20 LoA-RG Monday 11:00am Charter Suite 4 Chairs: Ning Zhang and Yoshio Tanaka

© 2007 Open Grid Forum 2 Agenda today LoA-RG Charter Authentication use-cases Identifying LoA attributes

© 2007 Open Grid Forum 3 Administrative Information Name and Acronym: OGF LoA-RG (Levels of authentication Assurance – Research Group) Chairs: Ning Zhang, Yoshio Tanaka, list: Web page: jects.sec/wiki/LoAI jects.sec/wiki/LoAI

© 2007 Open Grid Forum 4 Group Mission AuthN LoA is determined by AuthN methods/processes/procedures should be a factor in controlling the access to resources with varying sensitivity levels and/or in environments with varying risk levels This LoA-RG is aimed at investigating use case scenarios in the e-Science/Grid contexts, and identifying gaps in applying existing LoA definitions to such contexts

© 2007 Open Grid Forum 5 Group Scope The LoA-RG tackles the issues related to defining the criteria for assurance assessment, the identification of gaps between the criteria defined by other standards bodies (in particular NIST, ETSI and EU standards) and the relevant grid use cases for (identity) assertions. The LoA-RG will NOT pursue the conveyance of LoA assertions in authentication protocols, or the technical consumption of such assertions by software. These topics are within the remit of the OGSA- AuthN-WG (proposed) The LoA-RG will NOT pursue the definition of identity levels and policies, or the implementation thereof. These topics are within the remit of the grid participants, their management, regulatory bodies and coordinating groups (CAOPS-WG, IGTF, inCommon, etc). The LoA-RG will NOT define any standards or recommendations under this charter.

© 2007 Open Grid Forum 6 Output - 1 Title: A risk analysis in relation to LoA and use case gathering in an e-Science context Editor: Michael Helm Abstract: This document will present a risk analysis from the prospective of relying parties (or service providers). It will address such questions as: What is it that relying parties really need to know about an identity assertion? What qualities do they require? Which attributes do they 'need to know' about an assertion provider in order to decide on trust in the assertion? The document will also gather specific use cases in relation to LoA in the context.

© 2007 Open Grid Forum 7 Output - 2 Title: A gap analysis of current LoA definitions versus LoA requirements in e-Science/Grid context Editors: N Zhang, M Jones, and A Nenadic Abstract: This document will give an overview of current LoA definitions and the related efforts, and identify gaps between these definitions and the potential use of LoA in the e-Science/Grid context.

© 2007 Open Grid Forum 8 Authentication Use-cases To identify gaps in existing LoA definitions, we need to identify attributes that may affect the values of LoA in different Grid authentication scenarios AuthN Usecase -1: End entity to service direct authentication using end-entity credentials AuthN Usecase -2: End entity to service authentication using proxy credentials stored locally AuthN Usecase -3: End entity to service authentication using proxy credentials stored remotely AuthN Usecase -4: End entity to IdP authentication + IdP to service assertion

© 2007 Open Grid Forum 9 LoA attributes Identity vetting/proofing Credential issuance Certification Authority (CA) Credential types Biometrics, PKI credentials, username/password pairs, One-time password, proxy credentials Key stores Soft token (desktop key store), Hard token (smartcard key store), Secure coprocessor, online credential repository (myproxy or virtual smartcard) Credential strengths Password entropy: password space, password length, mixed use of lower/upper case, digits, etc, not dictionary words, validity duration PKI credential strength: key size, algorithm, validity duration Proxy credential strength: validity duration, depth of delegation Assertion message reliability Validity duration How attributes are stored and managed – procedures and policies are required to govern these Signature strength: signature key size, signature algorithm, hash function strength How assertion messages are conveyed Reliable source of time

© 2007 Open Grid Forum 10 AuthN Usecase - 1 User to Service direct authN using ID credentials LoA attributes Token type (key storage), credential strength, authentication protocols, message level or transport level Grid Services User Authenticate and access services using end-entitys credential, e.g. username/password Message level or transport level (SSL)

© 2007 Open Grid Forum 11 AuthN Usecase - 2 Authenticate using end-entitys proxy credential stored locally How proxy is activated (activating token type and strength), where the proxy is stored (key store) Proxy credential strength (key size, and delegation depth) Grid Services User Client Authentication using proxy User local authN to activate the proxy credential

© 2007 Open Grid Forum 12 AuthN Usecase - 3 Online Credential Repository (OCR) Grid Services Client Proxy credential sent by Client Proxy credential sent from OCR Client-to-RP authN and proxy credential retrieval User Long term credential

© 2007 Open Grid Forum 13 AuthN Usecase - 3 End-entity to OCR authN: All the attributes defined for {AuthN Usecase -1} apply here OCRs assurance level Client to Service authN using proxy, or Service fetches proxy directly from OCR Proxy strength Delegation depth Accompanying intermediarys credential? Proxy transmission channel security strength Method/algorithm is required to calculate the overall LoA?

© 2007 Open Grid Forum 14 AuthN Usecase - 4 IdP Grid Services Client Users ID/attribute assertions End entity authentication with IdP Attributes Authority

© 2007 Open Grid Forum 15 AuthN Usecase - 4 End-entity to IdP authN: {AuthN Usecase – 1} IdP trust level = accredited with what level (dictated by procedures and policy)? How attributes are stored and protected at the IdP (i.e. IdPs assurance level) Signed and stored, or bare attributes? How assertion messages are conveyed? Message level or over SSL Assertion message security strength Signature key strength, Signature key storage, signature algorithm ID/strength, and hash function strength Method/algorithm is required to calculate the overall LoA?

© 2007 Open Grid Forum 16 Acknowledgements + Survey Thank David Groep and Blair Dillaway for their contributions to the Charter Thank Yao Li, the University of Manchester, for his work on authentication usecase models LoA survey available at: loa.org/outputhttp:// loa.org/output

© 2007 Open Grid Forum 17 OGF IPR Policies Apply I acknowledge that participation in this meeting is subject to the OGF Intellectual Property Policy. Intellectual Property Notices Note Well: All statements related to the activities of the OGF and addressed to the OGF are subject to all provisions of Appendix B of GFD-C.1, which grants to the OGF and its participants certain licenses and rights in such statements. Such statements include verbal statements in OGF meetings, as well as written and electronic communications made at any time or place, which are addressed to: the OGF plenary session, any OGF working group or portion thereof, the OGF Board of Directors, the GFSG, or any member thereof on behalf of the OGF, the ADCOM, or any member thereof on behalf of the ADCOM, any OGF mailing list, including any group list, or any other list functioning under OGF auspices, the OGF Editor or the document authoring and review process Statements made outside of a OGF meeting, mailing list or other function, that are clearly not intended to be input to an OGF activity, group or function, are not subject to these provisions. Excerpt from Appendix B of GFD-C.1: Where the OGF knows of rights, or claimed rights, the OGF secretariat shall attempt to obtain from the claimant of such rights, a written assurance that upon approval by the GFSG of the relevant OGF document(s), any party will be able to obtain the right to implement, use and distribute the technology or works when implementing, using or distributing technology based upon the specific specification(s) under openly specified, reasonable, non- discriminatory terms. The working group or research group proposing the use of the technology with respect to which the proprietary rights are claimed may assist the OGF secretariat in this effort. The results of this procedure shall not affect advancement of document, except that the GFSG may defer approval where a delay may facilitate the obtaining of such assurances. The results will, however, be recorded by the OGF Secretariat, and made available. The GFSG may also direct that a summary of the results be included in any GFD published containing the specification. OGF Intellectual Property Policies are adapted from the IETF Intellectual Property Policies that support the Internet Standards Process.

© 2007 Open Grid Forum 18 Full Copyright Notice Copyright (C) Open Grid Forum (applicable years). All Rights Reserved. This document and translations of it may be copied and furnished to others, and derivative works that comment on or otherwise explain it or assist in its implementation may be prepared, copied, published and distributed, in whole or in part, without restriction of any kind, provided that the above copyright notice and this paragraph are included on all such copies and derivative works. The limited permissions granted above are perpetual and will not be revoked by the OGF or its successors or assignees.