Diego R. Lopez, RedIRIS JRES2005, Marseille On eduGAIN and the Coming GÉANT Middleware Infrastructure.

Slides:



Advertisements
Similar presentations
The e-Framework Bill Olivier Director Development, Systems and Technology JISC.
Advertisements

GT 4 Security Goals & Plans Sam Meder
Web Service Ahmed Gamal Ahmed Nile University Bioinformatics Group
© 2007 Cisco Systems, Inc. All rights reserved.Cisco Public University of the Future 1 TF-Mobility future Klaas Wierenga
1 On Death, Taxes, & the Convergence of Peer-to-Peer & Grid Computing Adriana Iamnitchi Duke University “Our Constitution is in actual operation; everything.
Connect. Communicate. Collaborate Click to edit Master title style MODULE 1: perfSONAR TECHNICAL OVERVIEW.
TF-EMC2 February 2006, Zagreb Deploying Authorization Mechanisms for Federated Services in the EDUROAM Architecture (DAME) -Technical Project Proposal-
Connect. Communicate. Collaborate The eduGAIN Way Diego R. Lopez - RedIRIS.
EDINA 20 th March 2008 EDINA Geo/Grid - Security Prof. Richard O. Sinnott Technical Director, National e-Science Centre University of Glasgow, Scotland.
A Heterogeneous Network Access Service based on PERMIS and SAML Gabriel López Millán University of Murcia EuroPKI Workshop 2005.
The TERENA Academic CA Repository. eIRG Meeting. Dublin, 16/04/2004 Diego R. Lopez – TF-AACE  Task Force on Authentication and.
Connect. Communicate. Collaborate Federation peering à la European The eduGAIN way Diego R. Lopez - RedIRIS.
AAF Middleware update February Presented by Terry Smith Technical Manager and Heath Marks Manager.
Self Adaptivity in Grid Computing Reporter : Po - Jen Lo Sathish S. Vadhiyar and Jack J. Dongarra.
EuroPKI 2008 Manuel Sánchez Óscar Cánovas Gabriel López Antonio F. Gómez Skarmeta University of Murcia Levels of Assurance and Reauthentication in Federated.
Developments and challenges in authentication and authorisation Klaas Wierenga Berlin, 23 May 2006.
1 Multi Cloud Navid Pustchi April 25, 2014 World-Leading Research with Real-World Impact!
Climate Sciences: Use Case and Vision Summary Philip Kershaw CEDA, RAL Space, STFC.
Connect. Communicate. Collaborate First steps in federation peering: eduGAIN and eduroam Diego R. Lopez - RedIRIS.
European Grid Initiative Federated Cloud update Peter solagna Pre-GDB Workshop 10/11/
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Interoperability Shibboleth - gLite Christoph.
Advanced Techniques for Scheduling, Reservation, and Access Management for Remote Laboratories Wolfgang Ziegler, Oliver Wäldrich Fraunhofer Institute SCAI.
High-quality Internet for higher education and research AAI from the NREN perspective Schiphol, October 17, 2005
Service Oriented Architectures Presentation By: Clifton Sweeney November 3 rd 2008.
Connect. Communicate. Collaborate eduGAIN in Real Life! Ajay Daryanani, RedIRIS TERENA Networking Conference Brugge, 20th May 2008.
Connect. Communicate. Collaborate Place organisation and project logos in this area Usage of SAML in eduGAIN Stefan Winter, RESTENA Foundation TERENA Networking.
Connect. Communicate. Collaborate Federation Interoperability Made Possible By Design: eduGAIN Diego R. Lopez (RedIRIS)
Interoperability Grids, Clouds and Collaboratories Ruth Pordes Executive Director Open Science Grid, Fermilab.
Connect communicate collaborate The GEMBus Way Delivering the Promise of the Internet of Services Diego R. Lopez, RedIRIS.
Cracow Grid Workshop ‘06 17 October 2006 Execution Management and SLA Enforcement in Akogrimo Antonios Litke Antonios Litke, Kleopatra Konstanteli, Vassiliki.
Grid programming with components: an advanced COMPonent platform for an effective invisible grid © 2006 GridCOMP Grids Programming with components. An.
OGF22 25 th February 2008 OGF22 Demo Slides Prof. Richard O. Sinnott Technical Director, National e-Science Centre University of Glasgow, Scotland
CaGrid Overview and Core Services caGrid Knowledge Center February 2011.
Connect. Communicate. Collaborate The authN and authR infrastructure of perfSONAR MDM Ann Arbor, MI, September 2008.
Introduction to Semantic Web Service Architecture ► The vision of the Semantic Web ► Ontologies as the basic building block ► Semantic Web Service Architecture.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE User Forum, Manchester, 10 May ‘07 Nicola Venuti
Overview of Privilege Project at Fermilab (compilation of multiple talks and documents written by various authors) Tanya Levshina.
Connect. Communicate. Collaborate The MetaData Service Distributing trust in AAI confederations Manuela Stanica, DFN.
Connect. Communicate. Collaborate AAI scenario: How AutoBAHN system will use the eduGAIN federation for Authentication and Authorization Simon Muyal,
Independent Insight for Service Oriented Practice Summary: Service Reference Architecture and Planning David Sprott.
Connect. Communicate. Collaborate Universität Stuttgart A Client Middleware for Token- Based Unified Single Sign On to eduGAIN Sascha Neinert, University.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Vassiliki Pouli
Diego R. Lopez, RedIRIS TF-EMC2, Umea SIR, FedSSH and more to come…
1 Gateways. 2 The Role of Gateways  Generally associated with primary sites in ESG-CET  Provides a community-facing web presence  Can be branded as.
Connect. Communicate. Collaborate Deploying Authorization Mechanisms for Federated Services in the eduroam architecture (DAMe)* Antonio F. Gómez-Skarmeta.
GRID ANATOMY Advanced Computing Concepts – Dr. Emmanuel Pilli.
DICE: Authorizing Dynamic Networks for VOs Jeff W. Boote Senior Network Software Engineer, Internet2 Cándido Rodríguez Montes RedIRIS TNC2009 Malaga, Spain.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
Connect communicate collaborate Trust & Identity EC meets GÉANT 19 June 2014 Brussels Valter Nordh, NORDUnet Federation as a Service Task Leader Trust.
Networks ∙ Services ∙ People Marina Adomeit FIM4R meeting Virtual Organisation Platform as a Service VOPaaS Nov 30, 2015, Austria Task Leader,
Shibboleth Use at the National e-Science Centre Hub Glasgow at collaborating institutions in the Shibboleth federation depending.
DEVELOPING WEB SERVICES WITH JAVA DESIGN WEB SERVICE ENDPOINT.
Building Preservation Environments with Data Grid Technology Reagan W. Moore Presenter: Praveen Namburi.
Workshop on Security for Web Services. Amsterdam, April 2010 Applying SAML to Identity Data Exchange.
Connect. Communicate. Collaborate Applying eduGAIN to network operations The perfSONAR case Diego R. Lopez (RedIRIS) Maurizio Molina (DANTE)
Networks ∙ Services ∙ People Licia Florio TNC, Lisbon Consuming identities across e- Infrastructures 16 June 2015 PDO GÈANT.
International Planetary Data Alliance Registry Project Update September 16, 2011.
AMSA TO 4 Advanced Technology for Sensor Clouds 09 May 2012 Anabas Inc. Indiana University.
Enabling Grids for E-sciencE Agreement-based Workload and Resource Management Tiziana Ferrari, Elisabetta Ronchieri Mar 30-31, 2006.
Applying eduGAIN to network operations The perfSONAR case
eduTEAMS platform for collaboration Niels Van Dijk
First steps in federation peering: eduGAIN and eduroam
The GEMBus Architecture and Core Components
Federation peering à la European The eduGAIN way
Federation peering à la European The eduGAIN way
ESA Single Sign On (SSO) and Federated Identity Management
The DAMe’s First Steps: eduroam and NAS-SAML
Multi-Domain User Applications Research (JRA3)
A(nother) view on federation issues
Introduction to SOA Part II: SOA in the enterprise
Presentation transcript:

Diego R. Lopez, RedIRIS JRES2005, Marseille On eduGAIN and the Coming GÉANT Middleware Infrastructure

NRENs & Grids. Barcelona, September 2009 Across the Stack The Network The Application The Middleware Bottom layer of the application  Service location and discovery  {Con-, inter-}federation  Reputation  Logging and diagnostics Top layer of the network  Mobility  Network access  QoS  Measurement

NRENs & Grids. Barcelona, September 2009 eduGAIN in a Nutshell Based on the national identity federations, operated by NRENs  And a community-operated one: EFDA-Fed eduGAIN is a confederation infrastructure  Federates federations SAML 1.1 (and soon SAML 2.0) is the lingua franca Specific software developed  eduGAIN base libraries (Java)  simpleSAMLphp (PHP)  eduGAINFilter (javax.servlet.filter) Direct use of Shibboleth 2.0 possible (with a few restrictions)

NRENs & Grids. Barcelona, September 2009 eduGAIN Elements The Metadata Service – MDS  Updated by authorised components  Tagged according to user communities  Queried by user interfaces or autonomous services PKI and registry  Multi-rooted  Includes component identifiers AM/CC (Attribute Mapping / Credential Conversion)  Adapt syntax and semantics Bridging Elements - BE  Adapt protocols  Not required if eduGAIN profiles are natively supported  Hybrid model of integration

NRENs & Grids. Barcelona, September 2009 Fully Bridged eduGAIN

NRENs & Grids. Barcelona, September 2009 P2P eduGAIN

NRENs & Grids. Barcelona, September 2009 Hybrid eduGAIN

NRENs & Grids. Barcelona, September 2009 eduGAIN Profiles WebSSO  Shib 1.3 for SAML 1.1  SAML2 (except artifact-based) for SAML 2.0  Going into production service in GÉANT3 AC  Certificates plus optional attribute access UbC  Convey user credentials introduced at the client WE  Constrained delegation DAMe

NRENs & Grids. Barcelona, September 2009 The WebSSO Profile

NRENs & Grids. Barcelona, September 2009 The AC Profile

NRENs & Grids. Barcelona, September 2009 The UbC Profile

NRENs & Grids. Barcelona, September 2009 The WE Profile

NRENs & Grids. Barcelona, September 2009 Core Services in GN[\d] GN2 saw the first attempt to offer these core services as part of a multi-domain network infrastructure  Not perfect, but many lessons learned  Actual services and working examples  Taking advantage of previous collaborative initiatives GN3 is continuing this trail  Enhancing those already deployed or piloted  Addressing more core services  Providing dynamic integration and invocation  Considering SLAs as part of the process  Better development and deployment cycles A service integration model: the multi-domain ESB

NRENs & Grids. Barcelona, September 2009 A framework to define, discover, access, and combine network services  From the infrastructure up to application elements  Federated, multi-domain ESB  Able to integrate any service within the GÉANT infrastructure  Flexible negotiation of service provision capabilities Addressed to  NREN staff  e-Science service providers  and users!! Collaborative architecture  Open to collaboration beyond the academic community  Prosumer-oriented Plug-and-play plus Plug-and-be-played The GEMBus Promise

NRENs & Grids. Barcelona, September 2009 α-interfaces  Directly usable by applications β-interfaces  Govern systems and resources γ-interfaces  Abstract access to resources δ-interfaces  Actual control over the resources Source: MANA Position Paper, 2009 Service Interfaces

NRENs & Grids. Barcelona, September 2009 GEMBus will provide a set of α-interfaces  Plus the corresponding orchestration systems Specify how β-interfaces have to be published and registered  From individual GÉANT (and external) services γ-interfaces for core services  Those required for direct integration support  Usable by individual services Source: MANA Position Paper, 2009 What Service Interfaces

NRENs & Grids. Barcelona, September 2009 A Couple of Archetypal Use Cases An institution willing to distribute an arts performance subject to IPR to a variable number of sites needs to:  Create a multicast group  Generate keys for controlling access to the group  Distribute keys to participant sites according to their attributes and the institution authorization policy  Monitor the usage and performance of the distribution at several points of the network A research team defining a workflow to gather and publish a data flow originated by a singular instrument through a federated repository needs to:  Make informed real-time decisions on the route to be used for storing the data  Enforce certain properties in the selected links  Provide the data processors with appropriate credentials to access data stores  Obtain general, location-independent pointers, to the final data

NRENs & Grids. Barcelona, September 2009 Building by Composition Service Components  AutoBAHN DM  perfSONAR MA  eduGAIN AuthN  Composite Services  e-science workflow  A&H performance  eduGAINized repositories  … Service Frameworks  Other NRENs  Governmental  Commercial  … AutoBAHN eduG AIN Grid GÉBusCLARINAPANI2ESNetIPSphereOGSATelcosCanarie Interface descriptions Compositional procedures and orchestration Standard interfaces and support for policy agreements