Https://aarc-project.eu Authentication and Authorisation for Research and Collaboration Pilots on the Integrated R&E AAI Paul van Dijk, Activity Lead Pilots.

Slides:



Advertisements
Similar presentations
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
Advertisements

EGI-Engage EGI-Engage Engaging the EGI Community towards an Open Science Commons Project Overview 9/14/2015 EGI-Engage: a project.
AARC Overview Licia Florio, David Groep 21 Jan 2015 presented by David Groep, Nikhef.
This project has received funding from the European Union’s Seventh Framework Programme for research, technological development and demonstration under.
Authentication and Authorisation for Research and Collaboration Licia Florio (GÉANT) Christos Kanellopoulos (GRNET) Service orientation.
European Life Sciences Infrastructure for Biological Information Life science community update for the 7 th Federated Identity Management.
Authentication and Authorisation for Research and Collaboration Licia Florio REFEDS Meeting The AARC Project I2 Technology Exchange.
Authentication and Authorisation for Research and Collaboration Licia Florio AARC Workshop The AARC Project Brussels, 26 October.
Authentication and Authorisation for Research and Collaboration David Kelsey AARC AHM Milan And mechanisms NA3 Task 4 – Scalable.
Authentication and Authorisation for Research and Collaboration Peter Solagna Milano, AARC General meeting Current status and plans.
Authentication and Authorisation for Research and Collaboration Niels van Dijk AARC General Meeting Authentication and Authorisation.
Authentication and Authorisation for Research and Collaboration Peter Solagna Milano, AARC General meeting Report and plans Attribute.
Authentication and Authorisation for Research and Collaboration Michał Jankowski, Maciej Brzeźniak AARC General Meeting, Milan.
Authentication and Authorisation for Research and Collaboration Christos Kanellopoulos GRNET Proposed Pilots for Libraries and eGov.
Authentication and Authorisation for Research and Collaboration Mikael Linden AARC all hands Milan Authentication and Authorisation.
Authentication and Authorisation for Research and Collaboration Michał Jankowski, Maciej Brzeźniak AARC General Meeting, Milan.
Authentication and Authorisation for Research and Collaboration AARC general meeting in Milan, November 3 Authentication and Authorisation.
Authentication and Authorisation for Research and Collaboration NA2 meeting in Brussels, October 26 Authentication and Authorisation.
Authentication and Authorisation for Research and Collaboration Milan, Italy Training and Outreach Authentication and Authorisation.
JRA1.4 Models for implementing Attribute Providers and Token Translation Services Andrea Biancini.
Authentication and Authorisation for Research and Collaboration Christos Kanellopoulos
Authentication and Authorisation for Research and Collaboration David Groep AARC All Hands meeting Milano Policy and Best Practice.
Authentication and Authorisation for Research and Collaboration Christos Kanellopoulos Open Day Event: Towards the European Open.
Networks ∙ Services ∙ People Daniela Pöhn REFEDS EWTI, Vienna IdPs and Federations Service Aspects of Assurance SA5T1.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
A uthentication & A uthorization for R esearch & C ollaboration Pilots in SA1 Paul van Dijk, SURFnet AARC.
NREN Trust and Identity Strategy Ann Harding, SWITCH Cambridge July 2014.
Networks ∙ Services ∙ People Thomas Bärecke Journée Fédération, Paris Collaboration européenne GÉANT SA5 03/07/2015 SA5 T5 team
Connect communicate collaborate Trust & Identity EC meets GÉANT 19 June 2014 Brussels Valter Nordh, NORDUnet Federation as a Service Task Leader Trust.
Networks ∙ Services ∙ People Nicole Harris UK federation meeting eduGAIN, REFEDS and the UK 23 June 2015 Project Development Officer GÉANT.
Networks ∙ Services ∙ People Marina Adomeit FIM4R meeting Virtual Organisation Platform as a Service VOPaaS Nov 30, 2015, Austria Task Leader,
Networks ∙ Services ∙ People Ann Harding GÉANT Symposium, Vienna Users Session A3 Trust and Identity March GÉANT Activity Leader Trust.
Authentication and Authorisation for Research and Collaboration Taipei Taiwan Authentication and Authorisation for Research and.
European Grid Initiative AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
Authentication and Authorisation for Research and Collaboration Licia Florio REFEDS Meeting AARC and AARC2 Vienna, 1 st December.
INDIGO – DataCloud WP5 introduction INFN-Bari CYFRONET RIA
David Groep Nikhef Amsterdam PDP programme Authentication and Authorization for Research and Collaboration David Groep, Nikhef with materials gratefully.
Authentication and Authorisation for Research and Collaboration Bari, Italy Training and Outreach Authentication and Authorisation.
David Groep Nikhef Amsterdam PDP & Grid AARC Authentication and Authorisation for Research and Collaboration an impression of the road ahead.
Networks ∙ Services ∙ People Andrea Biancini #TNC15, Porto, Portugal Implementing Grouper to federate user authorization Federated Authorization.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI-InSPIRE PY5 new activities Peter Solagna – EGI.eu.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Enabling SSO capabilities in the EGI Cloud services Peter Solagna – EGI.eu.
Networks ∙ Services ∙ People Licia Florio TNC, Lisbon Consuming identities across e- Infrastructures 16 June 2015 PDO GÈANT.
Authentication and Authorisation for Research and Collaboration Heiko Hütter, Martin Haase, Peter Gietz, David Groep AARC 3 rd.
Authentication and Authorisation for Research and Collaboration Peter Solagna, Davide Vaghetti, et al. Topics for PY2 activities.
Authentication and Authorisation for Research and Collaboration Licia Florio AARC CORBEL Workshop The AARC Project Paris, 31 May.
Networks ∙ Services ∙ People Marina Adomeit TNC16 Conference, Prague Towards a platform for supporting collaboration GÉANT VOPaaS
Authentication and Authorisation for Research and Collaboration Peter Solagna, Nicolas EGI AAI integration experiences AARC Project.
Authentication and Authorisation for Research and Collaboration David Kelsey AARC AHM Utrecht NA3 Task 4 – Scalable Policy Negotiation.
Authentication and Authorisation for Research and Collaboration AARC/CORBEL Workshop for Life Sciences AAI AARC Draft Blueprint.
Authentication and Authorisation for Research and Collaboration Lalla Mantovani AARC General Meeting, Utrecht What do we want to.
Authentication and Authorisation for Research and Collaboration Brussels Training and Outreach Authentication and Authorisation.
Networks ∙ Services ∙ People Mandeep Saini AARC/CORBEL Workshop Collaborative Organisation Platform as a Service June 1, 2016, Paris Product.
Authentication and Authorisation for Research and Collaboration Licia Florio IGTF Meeting The AARC Project Amsterdam, 8 September.
Authentication and Authorisation for Research and Collaboration On behalf of the MJRA1.2 scribes J Jensen.
Networks ∙ Services ∙ People Di4R Network. Services. People. GÉANT 28 th September, Krakow.
WLCG Update Hannah Short, CERN Computer Security.
AENEAS WP6 first conference call
User Community Driven Development in Trust and Identity
eduTEAMS platform for collaboration Niels Van Dijk
Wrap up Licia Florio AARC Coordinator
EGI-Engage Engaging the EGI Community towards an Open Science Commons
The AARC Project Licia Florio (GÉANT) Christos Kanellopoulos (GRNET)
The AARC Project Licia Florio AARC Coordinator GÉANT
Minimal Level of Assurance (LoA)
Sustainability and Operational models
AARC Blueprint Architecture and Pilots
AARC2 JRA1 Update Nicolas Liampotis
AAI Architectures – current and future
GN2 JRA5 Roaming and Authorisation Jürgen Rauschenbach, DFN-Verein
Presentation transcript:

Authentication and Authorisation for Research and Collaboration Pilots on the Integrated R&E AAI Paul van Dijk, Activity Lead Pilots (SA1) AARC Kick-Off Meeting June 2015 An overview of the “SA1” activities

AARC Work Packages

Current AAI landscape Non-web SSO ✗.....a huge challenge, royal route or workarounds?? Attribute management for AuthZ ✗ / ✔.....available in some communities, others just started “Guest” access ✗ / ✔.....some ad-hoc solutions, not standardized, LoA?? Int’l AuthN ✗ / ✔.....framework available but needs optimization Nat’l AuthN ✔.....many successful national implementations However, many components available to improve current practice status? – need overview, architecture and PoC/Pilots/Demo’s of components to determine: for which use case?, compatible with?, maturity?, suitability? When do components fit together, when not?

Goals/Approaches Pilots (SA1) Demonstrate that the solutions identified and proposed by JRA1 and NA3 are effective in addressing the requirements of the communities Proof of concepts will involve services from the main e-infrastructures in Europe Show to what extent different technologies used by the e-infrastructures and service providers are compatible and interchangeable (Re-)using not building 4

Task1: Pilots of solutions for “guest” users Lead: GARR - Mario Reale, Barbara Monticini, Lalla Montovani Lower barriers for entry of organisations not already participating in identity federations Showcase viable solutions whether commercially available or R&E community supported for guest access to shared resources Showcase ways to support scalable LoA for guest users Showcase AAI Approaches for research libraries 5

Task2: Pilots of an attribute management framework Lead: EGI - Peter Solagna Attribute management: identify tools and services that better support the registration and management of attributes by the research communities Attribute aggregation: multiple scenarios for attribute aggregation are expected to result from the attribute framework definition Attribute based authorisation: service providers will base authorisation on a combination of IdP and community provided attributes 6

Task3: Pilot to improve access to R&E relevant resources and services Lead: PSNC - Maciej Brzeźniak, Michal Jankowski To provide AAI mechanisms to access (non-web) resources relevant for the R&E communities To pilot mechanisms identified in JRA1 to integrate services that are not yet accessible via the federated framework To pilot SSO access for commercial (cloud) services for research communities and consider both technical/architectural solutions (in collaboration with JRA1) and legal and policy aspects (in collaboration with NA3) 7

Time line, pre-set mile stones, and deliverables – The AARC-Pilots Metro Map 8 “PoC on cross sector SSO and attribute management” M24 Termini M0 Kick-off M3 detailed work plan M15 guest access pilot M15 first report on pilots M20 attribute provider framework pilot M23 access to R&E resources pilot April 2017 May 2015 M24 final report on pilots SA1 GN4 VOPaas Elixir JRA1

Agenda – Planning the work ahead... 9

Participation of partners per pilot task (tbd) “guest” users (task1) attribute management (task2) access to (non-web resources) (task3) person- months Involvedcomments SN23 PSNCLEAD12 EGILEAD11 GARRLEAD6 FOM/NIKHEF10 CESNET8 GRNET8 KIT8 DAASI7 CSC4 Moravian Libary1

Thank you Any Questions? © GÉANT on behalf of the AARC project. The work leading to these results has received funding from the European Union’s Horizon 2020 research and innovation programme under Grant Agreement No (AARC).