1 InCommon Identity & Access Management Federation John Krienke Operations Manager, InCommon Assistant Director, Internet2

Slides:



Advertisements
Similar presentations
The Art of Federations. Topics Federations of what… Federated identity versus federations Federations in other sectors – business, gov, ad hoc R&E Federations.
Advertisements

National Institutes of Health U.S. Department of Health and Human Services The PEPH Resource Center: A New, More Convenient Login.
1 Leveraging Your Existing Campus Systems to Access Resource Partners: Federated Identity Management and Tales of Campus Participation EDUCAUSE 2006 October.
1 The Challenges of Creating an Identity Management Infrastructure for the University of California David Walker Karl Heins Office of the President University.
Federated Identity, Shibboleth, and InCommon Tom Barton University of Chicago © 2009 The University of Chicago.
Federated Access: Identity Management and Access to Protected Resources Renée Woodten Frost Associate Director, Middleware & Security
Information Resources and Communications University of California, Office of the President UCTrust David Walker Office of the President University of California.
Federations in Texas Barry Ribbeck University of Texas Health Science Center at Houston.
David L. Wasley Information Resources & Communications Office of the President University of California Directories and PKI Basic Components of Middleware.
1 eAuthentication in Higher Education Tim Bornholtz Session #47.
Information Resources and Communications University of California, Office of the President Current Identity Management Initiatives at UC & Beyond: UCTrust.
Information Resources and Communications University of California, Office of the President UCTrust Implementation Experiences David Walker, UCOP Albert.
Copyright JNT Association 20051OptionalCopyright JNT Association 2007 Overview of the UK Access Management Federation Josh Howlett.
InCommon and Federated Identity Management 1
The Business of Identity Management Barry R. Ribbeck Director Systems Architecture & Infrastructure Rice University
EAuthentication in Higher Education Tim Bornholtz Session 58.
Shibboleth Update a.k.a. “shibble-ware”
InCommon Policy Conference April Uses  In order to encourage and facilitate legal music programs, a number of universities have contracted with.
Administrative Information Systems Shibboleth: The Next Generation ISIS Technical Information Session for Developers Datta Mahabalagiri March
1 Update on the InCommon Federation, Higher Education’s Community of Trust EDUCAUSE 2005 October 19 10:30am-11:20am.
Updates on Shib, a bit of InCommon and International Federations.
1 Leveraging Your Existing Campus Systems to Access Resource Partners: Federated Identity Management and Tales of Campus Participation Clair Goldsmith,
SWITCHaai Team Federated Identity Management.
CILogon and InCommon: Technical Update Jim Basney This material is based upon work supported by the National Science Foundation under grant numbers
The InCommon Federation The U.S. Access and Identity Management Federation
Jack Suess, CIO University of Maryland, Baltimore County April 5, 2009.
1 The Partnership Challenge Higher education’s missions are realized in increasingly global, collaborative, online relationships –Higher educations’ digital.
1 The InCommon Federation John Krienke Internet2 Spring Member Meeting Tuesday, April 25, 2006.
The Rise of Federations…Almost Everywhere. Topics Federation Basics Drivers Components International and pulic sector developments InCommon and its uses.
Exploring InCommon Getting Started with InCommon: Creating Your Roadmap.
Internet2 – InCommon and Box Marla Meehl Colorado CIO 11/1/11.
InCommon, other federations, the attribute ecosystem, and some killer apps needing guns…
Belnet Federation Belnet – Loriau Nicolas Brussels – 12 th of June 2014.
Identity Federations: Here and Now Renée Shuey Penn State and InCommon.
Shibboleth as Attribute Delivery for Authorization Renee Shuey Penn State University June 27, 2006.
Presented by: Presented by: Tim Cameron CommIT Project Manager, Internet 2 CommIT Project Update.
Federations 101 John Krienke Internet2 Fall 2006 Internet2 Member Meeting.
Federated Identity and Shibboleth Concepts Rick Summerhill Chief Technology Officer Internet2 GEC3 October 29, 2008 Slides by Nate Klingenstein
Shibboleth at Columbia Update David Millman R&D July ’05
MAT U M A T U Middleware Assisted Take-Up Service For JISC Funded Early Adopters.
1 Protection and Security: Shibboleth. 2 Outline What is the problem Shibboleth is trying to solve? What are the key concepts? How does the Shibboleth.
Internet2: building and using an advanced network environment for research, teaching and learning APRU CIO Forum, 23 March 2007 Heather Boyles,
The InCommon Federation The U.S. Access and Identity Management Federation
INTRODUCTION: THE FIRST TRY InCommon eduGAIN Policy and Community Working Group.
State of e-Authentication in Higher Education August 20, 2004.
Shibboleth What is it and what is it good for? Chad La Joie, Georgetown University.
University of Washington Identity and Access Management IEEAF – RENU Network Design Workshop Seattle - 29 Nov 2007 Lori Stevens, Director, Distributed.
Shibboleth: Molecules, Music, and Middleware. Outline ● Terms ● Problem statement ● Solution space – Shibboleth and Federations ● Description of Shibboleth.
1 Support For Research & National Identity Snapshot Jim Leous, Penn State Ann West, Internet2/InCommon Federation.
Federated Identity Management at NIH…NIH Login and Beyond Debbie Bucci September 2009.
Transforming Government Federal e-Authentication Initiative David Temoshok Director, Identity Policy and Management GSA Office of Governmentwide Policy.
University of Washington Collaboration: Identity and Access Management Lori Stevens University of Washington October 2007.
Federations: The New Infrastructure Speaker Name Here Date Here Speaker Name Here Date Here.
Identity Management, Federating Identities, and Federations November 21, 2006 Kevin Morooney Jeff Kuhns Renee Shuey.
InCommon® for Collaboration Institute for Computer Policy and Law May 2005 Renee Shuey Penn State Andrea Beesing Cornell David Wasley Internet 2.
Administrative Information Systems Shibboleth Install Session Technical Information Session for Developers Datta Mahabalagiri.
HATHITRUST A Shared Digital Repository HathiTrust Large Digital Libraries: Beyond Google Books Modern Language Association January 5, 2012 Jeremy York,
Shibboleth at USMAI David Kennedy Spring 2006 Internet2 Member Meeting, April 24-26, 2006 – Arlington, VA.
NMI-EDIT and Rice University Federated Identity Management: Managing Access to Resources in Texas Barry Ribbeck Director System Architecture and Infrastructure.
SEPARATE ACCOUNTS FOR PROSPECTS? WHAT A HEADACHE! Ann West Assistant Director, InCommon Assurance and Community Internet2 at Michigan Tech.
1 Identities and Federation: The Next IT Wave (The Canadian Access Federation) Rick Bunt President The Canadian University Council of CIOs (CUCCIO)
INTRODUCTION TO IDENTITY FEDERATIONS Heather Flanagan, NSRC.
UCTrust Integration for UC Grid David Walker University of California, Davis ucdavis.edu Kejian Jin University of California, Los Angeles kjin.
Tom Barton, Senior Director for Integration, University of Chicago
Shibboleth Architecture
John O’Keefe Director of Academic Technology & Network Services
InCommon Steward Program: Community Review
A Business Case for Identity Management in Higher Education
Shibboleth as Attribute Delivery for Authorization
Updates on Shib, a bit of InCommon and International Federations
Presentation transcript:

1 InCommon Identity & Access Management Federation John Krienke Operations Manager, InCommon Assistant Director, Internet2

2 The Partnership Challenge Higher education’s Staff, students, and faculty are no longer located exclusively on campus Research and missions are increasingly complex, globally interdependent, and on line Security and protection of personal identity information is paramount and increasingly regulated (FERPA, HIPAA, Gramm-Leach-Bliley, SOX, etc.) Business processes and applications are increasingly outsourced and/or distributed –Digital collections and data –Course materials and management –Financial management –Remote instrumentation –Computational resources such as Grids –Music, Software –Travel resources –Government resources

3 The Partnership Solution Develop solutions that efficiently used existing information infrastructures securely and safely Reduce the time and resources spent on all the “one off” requirements for each partner and streamlined interoperation with each partner Reduce help desk calls and the number of user accounts to provision throughout our many partnerships Maximize the control, security, and privacy of personally identifiable, sensitive information Make online services richer, easier to use, and safer for students, faculty, and staff This is what I/A/M federations dodo

4 Identity & Access Management Federations A definition of Federation: A collaboration of independent entities that give up a certain degree of autonomy to a central authority in pursuit of a common set of goals. Central Authority: Federations set common policies, interoperability criteria (vocabulary for exchanges, technology), and provide central services to establish and maintain trust (registration, authoritative metadata and certificates, dispute resolution) Common Set of Goals: Federations enable secure, trustworthy, scalable online partnerships

5 Examples of the Federation Spectrum Homogeneous (vanilla)Heterogeneous (rocky road) CentralizedIndependent Conscription Subscription RequirementsExpectations SuggestionsDeclarations High CostLow Cost eAuth (US)InCommon

6 Federating Software “When is a duet an orchestra?” Not all federated software supports multi-party federated collaboration. National Arts Centre Orchestra Gala 2007 CBC Radio

7 Music Service ID #4 j.o.123 Joe Oval Psych Prof. DOB: 4/4/1955 Password #4 Grant Admin Service ID #2 Joval Dr. Joe Oval Psych Prof. SSN Password #2 Grading Service ID #3 Jo456 Dr. Joe Oval Psych Prof. Password #3 Home Circle University Dr. Joe Oval Psych Prof. SSN Password #1 ???????? IT patch 1 IT patch 2 IT patch 3 Service IDs Challenging Way

8 Home Circle University Anonymous ID# Dr. Joe Oval Psych Prof. SSN Circle University Dr. Joe Oval Psych Prof. SSN Circle University Dr. Joe Oval Psych Prof. SSN Password #1 Circle University Dr. Joe Oval Psych Prof. SSN ! 1. Single Sign On 2. Services no longer manage user accounts & personal data stores 3. Reduced Help Desk load 4. Standards-based Technology 5. Home Org controls privacy Federated Way

9 Home Circle University Anonymous ID# Dr. Joe Oval Psych Prof. SSN Circle University Dr. Joe Oval Psych Prof. SSN Affiliation EPPN Given/SurName Title SSN Password #1 Circle University ID # Dr. Joe Oval Psych Prof. SSN ! Role of the Federation 1. Agreed upon Attribute Vocabulary & Definitions: Member of, Role, Unique Identifier, Courses, … 2. Criteria for IdM practices (user accounts, credentialing, etc.), personal information stewardship, interoperability standards, technologies 3. Digital Certificates 4. Trusted “notary” for all universities and partners Verified By the Federation Verified By the Federation Verified By the Federation Verified By the Federation

10 Home Circle University Anonymous ID# Dr. Joe Oval Psych Prof. SSN Circle University Dr. Joe Oval Psych Prof. SSN Affiliation EPPN Given/SurName Title SSN Password #1 Circle University ID # Dr. Joe Oval Psych Prof. SSN ! Verified By the Federation Verified By the Federation Verified By the Federation Verified By the Federation federation metadata University A IdP: name, key, url, contacts, etc. SP1: name, key, url, contacts, etc. SP2: name, key, url, contacts, etc. University B IdP: name, key, url, contacts, etc. SP1: name, key, url, contacts, etc. University C IdP: name, key, url, contacts, etc. Partner 1 SP1: name, key, url, contacts, etc. Partner 2 SP1: name, key, url, contacts, etc. SP2: name, key, url, contacts, etc. Partner 3 … bronze LoA silver LoA future

11 User Experience Flows First visit the SP then Federation WAYF (“Where Are You From” home organization discovery page) –Wireless (UT System) [screencast]Wireless First visit the SP’s own customized WAYF –ScienceDirectScienceDirect –Spaces.internet2.edu WikisSpaces.internet2.edu Wikis –OhioLINKOhioLINK First visit the IdP –Penn State & WebAssign [screencast]Penn State & WebAssign

12 User Experience Flows Multiple IdPs and SPsMultiple IdPs and SPs in Action: [screencast] Authentication vs. Authorization Federation WAYF Single Sign On to multiple services Anonymous Identifiers Clearing Sessions IdP to SP without a WAYF

13 The Value of InCommon Broad Strokes Identity Providers (Home Institutions) control user accounts and the release (and spillage) of personal information Online services focus on their online resources and not on user account provisioning Users have easy, private, global access Partners have finely-tunable access controls and can quickly and securely deploy new collaborations and service relationships

14 The Value of InCommon Detail Governance by a Representative Steering Committee establishes:Steering Committee –Criteria for participation –Policy and shared direction –Services meet business needs with appropriate security levels and legal requirements –Scalable operational standards and practices Legal Agreement –Official Organizational Designees, Establishment of Trust, Conflict and Dispute Resolution, Basic Protections & Responsibilities Trust “Notary” –InCommon verifies the identity of Organizations and their delegated Officers; Trusted Metadata –InCommon verifies & aggregates location and security data for each participant’s servers, systems, and support contacts Certificate Authority –InCommon issues server certificates to Participants for secure communications Standards for Policies and Practices –How high is the bar? Right now, each Participant decides. Participants self-declare their practices to other Participants. Coming soon: Optional Bronze and Silver Levels of Assurance (Audit Criteria) Technical Interoperability (Technical Advisory Committee)Technical Advisory Committee –InCommon defines shared attributes, standards (SAML), federating software (Shibboleth+)

15 Internet2 InCommon Governance Federation Operator Federation Operator Technical Advisory Committee Technical Advisory Committee Nominations Committee Nominations Committee InCommon LLC: Steering Committee Representing Higher Ed & its Partners InCommon LLC: Steering Committee Representing Higher Ed & its Partners Direction Candidate Approvals Advice

16 Growth

17 78Current InCommon Participants Higher Education (54) Case Western Reserve University Clemson University Cornell University Dartmouth Duke University Florida State University Georgetown University Johns Hopkins University Indiana University Miami University Michigan State University New York University Northwestern University Ohio State University Ohio University Penn State University Stanford University Stony Brook University SUNY Buffalo Texas A & M University University of Alabama at Birmingham University of California, Davis University of California, Irvine University of California, Los Angeles University of California, Merced University of California, Office of the President University of California, Riverside University of California, San Diego University of Chicago University of Maryland University of Maryland Baltimore County University of Maryland, Baltimore University of Rochester University of Southern California University of Virginia University of Washington University of Wisconsin – Madison ….. Sponsored Partners (21) Apple – iTunes U Cdigix Cengage Learning (Formerly Thomson Learning) EBSCO Publishing Elsevier ScienceDirect Houston Academy of Medicine - Texas Medical Center Library Internet2 JSTOR Microsoft NAS Recruitment Communications Nelnet – Next Generation Division OCLC OhioLink - The Ohio Library & Information Network ProtectNetwork RefWorks, LLC Students Only, Inc. SumTotal Systems Symplicity Corporation Turnitin University Tickets WebAssign Gov. and Nonprofit Labs, Research Centers, and Agencies (3) National Institutes of Health Lawrence Berkeley National Laboratory Moss Landing Marine Laboratories NEXT Libraries & their partners Student Services (Registrars, Financial Aid officers, others) U.S. Agencies: –NIH (Libraries, Grants Administration, …) –NSF (FastLane, …) –Dept. of Education (Student Financial Aid, …) Federations on top of the InCommon Federation –University Systems –State & Regional Systems –Coalitions organized around Networks, Grids, others…

18 Join or Create? Or Both? University of California System creates UCTrust within InCommon David Walker, UCOP Interoperability: UC's solution had to fit seamlessly into higher education's broader solution Not reinventing the wheel: policy, criteria, operations Not inventing new wheels: how will multiple federations interoperate?

19 Joining Management Process 1.Eligibility: Higher Ed (accreditation) and Sponsored Partners (sponsors)accreditationsponsors 2.Agreement: InCommon Participation Agreement [PDF]:PDF –Delegating your trusted Executive –Signed by an authorized representative of the organization 3.Pay Fees ($700 registration, $1,000 annual) 4.Federation I.D. Proofing of Executive, appointment of Admin 5.Privacy and Security Policies and Processes articulated, documented, and posted (Participant Operational Practices)Participant Operational Practices Technical Process 1.Official Organization Directory (Identity Management system) 2.Web Single Sign On (SSO) 3.Common Language: EduPerson schemaEduPerson 4.Federating Software: Shibboleth IdP and/or SPsShibboleth 5.Federation I.D. Proofing of Admin 6.Submit Metadata, Certificate Signing Request, and POP URL 7.Install Certificate 8.Test with Partners and Attribute Release Policies 9.Deploy 10.Repeat steps 8 & 9

20 InCommon Benefit Federation enables communities to share information about individuals’ identity, reducing the overall work required to maintain connections and reduce the friction in cross-community interactions. Burton Group, Federating a Distributed World: Asserting Next- Generation Identity Standards

21 InCommon Benefit “To meet the increasing campus demand for using external applications and online resources, we developed and implemented solutions that efficiently use our existing information infrastructures securely and safely in such a way that we maintain control over the release of personal information for people at Penn State. InCommon is a vitally important part of this infrastructure and helps put us in a position to provide a richer, easier to use, safer online experience for Penn State students, faculty, and staff.” -Kevin Morooney, vice provost, Penn State University Scalability: Leverage your investments and your “next times”

22 Questions?

23 Shibboleth Attribute-Based Authorization Resource WAYF Identity Provider Resource Provider Website 1 ACS I don’t know you or your home organization. I redirect your request to the InCommon WAYF 3 2 Where are you from? HS 5 6 I don’t know you. Please authenticate Using your Web login 7 User DB ID+Password OK, I know you now. I redirect your request to the Resource, along with a handle 4 OK, I will now redirect your request to your home org. AR Handle 8 I don’t know the attributes of this user. Let’s ask the Attribute Authority Handle 9 AA I trust you. I’ll pass the attributes the user has allowed me to release Attributes 10 Resource Manager Attributes OK, based on the attributes, I grant access to the resource © Switch user initiates a request