Identity Federation Policy Marina Vermezović, AMRES Federated Identity Technology Workshop Sofia, Bulgaria, 20. Jun 2014.

Slides:



Advertisements
Similar presentations
Module N° 4 – ICAO SSP framework
Advertisements

Freedom of Information Act 2000 and the PCT Audit Procedure Background: The Act was passed in November The Act will be fully in force by January.
Policy interoperability in electronic signatures Andreas Mitrakas EESSI International event, Rome, 7 April 2003.
Research Contracts and IP Services TRAINING WORKSHOPS ON HORIZON 2020 – 27 NOV 2014 The Grant Agreement Roger Wallace – Research Contracts & IP Services.
Department of Transportation Support Services Branch ODOT Procurement Office Intergovernmental Agreements 455 Airport Rd. SE, Bldg K Salem, OR
Copyright JNT Association 20051Optional Copyright JNT Association Joining the UK Access Management Federation 4th April.
1 Issues in federated identity management Sandy Shaw EDINA IASSIST May 2005, Edinburgh.
Information Resources and Communications University of California, Office of the President UCTrust Implementation Experiences David Walker, UCOP Albert.
An Introduction to the Hennepin County Hennepin County GIS Technical Advisory Group (eGTAG) 10/20/2009.
Access and Benefit Sharing and the Nagoya Protocol Nashina Shariff Manager Environmental Stewardship Branch November 2014.
Expanded Version of COSO a presentation by Steve Wadleigh Expanded Version of COSO a presentation by Steve Wadleigh Standards for Internal Control in the.
Regulatory Body MODIFIED Day 8 – Lecture 3.
Governance requirements for Regional Associations as specified by Ocean.US Worth D. Nowlin, Jr. Texas A&M University NDBC and CSC of NOAA GCOOS Stakeholders.
Networks ∙ Services ∙ People John DYER TF-MSP Video Conference Community Procurement Support Building on the SPOT-ON Proposal Smart Procurement,
Implementation of Leader Axis measures by Jean-Michel Courades AGRI-F3.
UNLV Data Governance Executive Sponsors Meeting Office of Institutional Analysis and Planning August 29, 2006.
Non-governmental Actors in the Compliance with and Monitoring of Multilateral Environmental Decisions.
Credential Provider Operational Practices Statement CAMP Shibboleth June 29, 2004 David Wasley.
A SOUND INVESTMENT IN SUCCESSFUL VR OUTCOMES FINANCIAL MANAGEMENT FINANCIAL MANAGEMENT.
SWITCHaai Team Federated Identity Management.
To identity federation and beyond! Josh Howlett JANET(UK) HEAnet 2008.
Circulation of authentic instruments under Regulation 650/2012 speaker – Ivaylo Ivanov – Bulgarian Notary Chamber.
Info Day on New Calls and Partner Café Brussels, 10 February 2011 How to apply: Legal Framework – Beneficiaries – Application and Selection Procedure.
Ray Collins27th September 2005LGfL Project – workshop report1 LGfL Project Report Proof of Principle of the Shibboleth Authentication & Authorisation Infrastructure.
Nov/Dec 2003ElectraNet BSP-2 Workshop (khb) 1 EU Telecoms Regulatory Status Governing Legislation Package 2002  Directive 2002/19/EC Access to, and interconnection.
Feasibility Study of a Wiki Collaboration Platform for Systematic Review Eileen Erinoff AHRQ Annual Meeting September 15, 2009.
Innovation through participation Interfederation through eduGAIN - steps and challenges eduGAIN interfederation service Federated Identity Systems.
The ReFEDS/GÉANT Code of Conduct (CoC) An Approach to Compliance with the EU Data Protection Directive Steve Carmody April 23, 2012.
The Professions and Professional Reliance Objectives Pillars Workshops – March 2009.
Internet2 – InCommon and Box Marla Meehl Colorado CIO 11/1/11.
Recognition: the national centre and the ENIC Network Seminar on the recognition of qualifications Baku, 22 April 2005 Gunnar Vaht Head of the Estonian.
TETRA MoU Association and its Regional Forums John Cox Chief Executive Officer.
PDLN Connect Outline for IFRRO Brussels June 2010.
FleetBoston Financial HIPAA Privacy Compliance Agnes Bundy Scanlan Managing Director and Chief Privacy Officer FleetBoston Financial.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
European Commission - DG Research - Directorate B – “Structuring the European Research Area” Jean-David MALO – Bucharest, February 12-13, NOT LEGALLY.
Géant-TrustBroker project overview Slides assembled by the Géant-TrustBroker team at Leibniz Supercomputing Centre, Germany for a short presentation by.
The Impact of Evolving IT Security Concerns On Cornell Information Technology Policy.
STATE AND LOCAL IMPLEMENTATION GRANT PROGRAM 1 December 6, 2012.
DGS Recommendations to the Governor’s Task Force on Contracting & Procurement Review Report Overview August 12, 2002.
Data Governance 101. Agenda  Purpose  Presentation (Elijah J. Bell) Data Governance Data Policy Security Privacy Contracts  FERPA—The Law  Q & A.
Test your IdP
Federation as a Service Marina Vermezović, AMRES Federated Identity Technology Workshop Sofia, Bulgaria, 20. Jun 2014.
9-Oct-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security (Report from the LCG Security Group) FNAL 9 October 2003 David Kelsey CCLRC/RAL, UK
Géant-TrustBroker Project Overview Daniela Pöhn 7 th FIM4R meeting Frascati, Italy April 24 th, 2014.
HIT Policy Committee NHIN Workgroup HIE Trust Framework: HIE Trust Framework: Essential Components for Trust April 21, 2010 David Lansky, Chair Farzad.
Biosafety Clearing House Training Workshop date place.
JRA1.4 Models for implementing Attribute Providers and Token Translation Services Andrea Biancini.
Copyright JNT Association 2009GN3, 8 th September Inter-Federation Agreements eduGAIN and beyond? Andrew Cormack Chief Regulatory Adviser, JANET(UK)
Connect. Communicate. Collaborate Deploying Authorization Mechanisms for Federated Services in the eduroam architecture (DAMe)* Antonio F. Gómez-Skarmeta.
Understanding deployment issues on the Supply Chain Ann Harding, SWITCH, Nicole Harris, TERENA Cambridge July 2014.
NREN Trust and Identity Strategy Ann Harding, SWITCH Cambridge July 2014.
Networks ∙ Services ∙ People Thomas Bärecke Journée Fédération, Paris Collaboration européenne GÉANT SA5 03/07/2015 SA5 T5 team
Networks ∙ Services ∙ People eduGAIN Townhall Meeting Nicole Harris (or updating the eduGAIN policy suite) “Unicorns can be sued in Wales”
Networks ∙ Services ∙ People Nicole Harris UK federation meeting eduGAIN, REFEDS and the UK 23 June 2015 Project Development Officer GÉANT.
Networks ∙ Services ∙ People Marina Adomeit FIM4R meeting Virtual Organisation Platform as a Service VOPaaS Nov 30, 2015, Austria Task Leader,
Federated Identity Fundamentals Ann Harding, SWITCH Cambridge July 2014.
true potential An Introduction to the Middle Manager Programme’s CMI Qualifications.
European Life Sciences Infrastructure for Biological Information ELIXIR Collaboration Agreement Template ELIXIR/2014/10 Vera Herkommer.
Designing Identity Federation Policy, the right way Marina Vermezović, Academic Network of Serbia TNC2013 conference 4 May 2013.
The statistical act, its application and challenges BY ABERASH TARIKU ABAYE NATIONAL STATISTICAL DATA QUALITY AND STANDARDS COORDINATION DIRECTORATE DIRECTOR.
TAIEX-REGIO Workshop on Applying the Partnership Principle in the European Structural and Investment Funds Bratislava, 20/05/2016 Involvement of Partners.
BOTSWANA TEACHERS’ UNION VICE REGIONAL ORGANISERS INDUCTION WORKSHOP
Cross-sector and user-centric AAI
Update from the Faster Payments Task Force
Updates to Expedited Review Procedures
Updates to Expedited Review Procedures
Setting Actuarial Standards
Draft ETSI TS Annex C Presented by Michał Tabor for PSD2 Workshop
Taking the STANDARDS Seriously
Presentation transcript:

Identity Federation Policy Marina Vermezović, AMRES Federated Identity Technology Workshop Sofia, Bulgaria, 20. Jun 2014.

2 Connect | Communicate | Collaborate Identity Federation Identity federation enables campus authentication systems to integrate with a wide variety of services on campus, between campuses in a country and beyond Supports different technologies RADIUS Moonshot

3 Connect | Communicate | Collaborate Identity Federation Technology can be straightforward, but what about Enabling an Identity federation demands a formalized policy

4 Connect | Communicate | Collaborate European Identity Federations the Evolution Identity federations started emerging 10 years ago leading to approx. half of European countries have deployed an WebSSO Identity federation Significant knowledge and experience has been gathered through the operation of those Identity federations Identity federation communities such as REFEDS enabled the exchange of knowledge and addressed the common issues Existing Identity federation policies has evolved based on local needs

5 Connect | Communicate | Collaborate European Identity Federations The Evolution The “Federation Policy Best Practice Approach” and “Federation Policy Mapping” analyses were performed by REFEDS

6 Connect | Communicate | Collaborate Identity Federation Policy Template eduGAIN GN3 task supported the creation of Identity Federation Policy Template document Gathered experience from existing Identity Federations in what not to put, and what to put in a Policy Based on Sweden Identity Federation - SWAMID policy Policy template is easy to be changed for local conditions Existing federations can use it if they want to change or update their existing policies

7 Connect | Communicate | Collaborate Allow multiple technologies Identity federation Policy should cover all these and allow for future adding new technologies Organizations join Identity federation only one time and then pick out which federation services they want to implement Identity Federation eduroam WebSSO Moonshot … Make the Policy in such a way that it allows for multiple technologies to be served using the same policy structure

8 Connect | Communicate | Collaborate Make resistant (as possible) to changes Make the Policy document in such a way to avoid the need for repeated changes Definitions that falls into changeable category should be put elsewhere e.g. federation website or appendix Find the right balance : Do not over specify Do not leave out important stuff Make resistant (as possible) to changes

9 Connect | Communicate | Collaborate Make future changes easy Policy will keep evolving and in certain degree changes will happen Make procedure for changing the policy lightweight as possible Important issue that can make effect on how easily a policy can be changed is what members sign when they join the Identity federation: Member fills in a separate form agreeing to be bound by the Policy document Member signs a copy of the actual policy (there are placeholders for signatures at the end the policy document)

10 Connect | Communicate | Collaborate Identity Federation Policy document suite Identity Federation Policy document Identity Federation Policy (main) Appendices Technology Profile eduroam Technology Profile Web single sign-on Level of Assurance Profiles Data Protection Profile Federation Operational Practices Appendix Governance Appendix Fees

11 Connect | Communicate | Collaborate Identity Federation Policy Template Sections Definitions and TerminologyIntroductionGovernance and Roles Governance Obligations and Rights of Federation Operator Obligations and Rights of Federation Members EligibilityProcedures How to Join How to Withdraw Legal conditions of use Termination Liability and indemnification Jurisdiction and dispute resolution Interfederation Amendment

12 Connect | Communicate | Collaborate Eligibility Defines which organizations are eligible to become a Member of your Federation, and which Member is eligible to act as Home Organization Depending on your country’s regulations for education and research sector and administrative/political circumstances, you should define which organizations are eligible to become a Member in your federation. However, as eligibility criterion is something you may want to adapt and change over time, it is the best to keep this section very short, and publish the eligibility criteria in some other place - this could simply be the website, or in separate appendix.

13 Connect | Communicate | Collaborate Governance of the federation Federation should have governing body which has advisory, decision or some other rights on certain federation issues. Structure and election process for the governing body falls into changeable category and should be specified elsewhere e.g. appendix Structure will probably highly depend on your local circumstances, how federation is established and funded Rights appointed to the governing body, advisory vs. deciding: Criteria for membership for the Federation Revoking the membership of a Federation Member Entering into interfederation agreement Formal ties with relevant national and international organisations Approving changes to the Federation Policy...

14 Connect | Communicate | Collaborate Obligations and Rights of Federation Operator It is very important to clearly define what are the obligations and rights of the Federation Operator Obligations boosts the members trust to Federation Operator, e.g.: Secure and trustworthy operational management of the federation Provides support services for Federation Members Maintaining relationships with national and international stakeholders in the area of Identity Federations Promoting the idea and concepts implemented in the Federation Federation Operator should keep certain rights, e.g. : temporarily suspend a Member who is in breach in policy publish some data about Federation Members

15 Connect | Communicate | Collaborate Obligations and Rights of Federation Members For mutual Federation Members trust, it is important to clearly define their obligations and rights There can be three types of Federation Members: Home Organization Attribute Authority Service Provider Some obligations and rights are same, but some differ !

16 Connect | Communicate | Collaborate Obligations and Rights of Federation Members - ALL Must cooperate with the Federation Operator and other Members in resolving incidents and should report incidents Must comply with the obligations of the Technology Profiles which it implements Must ensure its IT systems that are used in implemented Technology Profiles are operated securely Must pay the fees. Prices and payment terms are specified in appendix Fees If a Federation Member processes personal data, Federation Member will be subject to applicable data protection laws and must follow the practice presented in Data Protection Profile

17 Connect | Communicate | Collaborate Obligations and Rights of Federation Members – HO Is responsible for delivering and managing authentication credentials for its End Users and for authenticating them, as may be further specified in Level of Assurance Profiles Submit its Identity Management Practice Statement to the Federation Operator Ensures an End User is committed to the Home Organization’s Acceptable Usage Policy Operates a helpdesk for its End Users regarding Federation services related issues

18 Connect | Communicate | Collaborate Obligations and Rights of Federation Members – AA or HO Is responsible for assigning Attribute values to the End Users and managing the values in a way which ensures they are up-to-date Is responsible to releasing the Attributes to Service Providers

19 Connect | Communicate | Collaborate Obligations and Rights of Federation Members - SP Is responsible for making decision on which End Users can access the services they operate and which access rights are granted to an End User It is Service Providers responsibility to implement those decisions

20 Connect | Communicate | Collaborate Interfederation Enables federation to enter into interfederation agreements Technical and administrative issues related to interfederation are dependent of Technology Profile, and should be described there Federation Members will interact with entities which may be bound by very different rules and laws than the Members in this Federation A fundamental idea of an interfederation is that Members are bound by their local federation policies only and if anyone has a problem with the behavior of an entity in an Interfederation, he/she should go and check what the entity’s own Federation’s policy stipulates on it

21 Connect | Communicate | Collaborate Amendment Procedures required to get changes to the Federation Policy implemented Keep things simple and have the same procedure for all documents that make up the Federation Policy Give Federation Members a notification of the upcoming changes well in advance, allowing for feedback and resolution of potential points of contention before the changes come into force

22 Connect | Communicate | Collaborate | | Connect | Communicate | Collaborate Thank you!