NRENs, Grids and Integrated AAI In Search For the Utopian Solution Christos Kanellopoulos AUTH/GRNET October 17 th, 2005 skanct at physics.auth.gr 2nd.

Slides:



Advertisements
Similar presentations
Lousy Introduction into SWITCHaai
Advertisements

Introduction of Grid Security
GridShib Tom Barton, U Chicago. 2 Grid Computing Distributed computing and/or data resources Heterogeneous computing & storage environments Interfaces.
Thoughts & Ideas on AuthZ Interoperability Christos Kanellopoulos AUTH/GRNET skanct at physics.auth.gr.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
Federated Digital Rights Management Mairéad Martin The University of Tennessee TERENA General Assembly Meeting Prague, CZ October 24, 2002.
TechSec WG: Related activities overview Information and discussion TechSec WG, RIPE-45 May 14, 2003 Yuri Demchenko.
Authorization WG Update David Kelsey EU Grid PMA, Copenhagen 27 May 2008.
2006 © SWITCH Authentication and Authorization Infrastructures in e-Science (and the role of NRENs) Christoph Witzig SWITCH e-IRG, Helsinki, Oct 4, 2006.
INFSO-RI Enabling Grids for E-sciencE JRA3 2 nd EU Review Input David Groep NIKHEF.
U.S. Environmental Protection Agency Central Data Exchange EPA E-Authentication Pilot NOLA Network Node Workshop February 28, 2005.
TF-EMC2 February 2006, Zagreb Deploying Authorization Mechanisms for Federated Services in the EDUROAM Architecture (DAME) -Technical Project Proposal-
Attributes, Anonymity, and Access: Shibboleth and Globus Integration to Facilitate Grid Collaboration 4th Annual PKI R&D Workshop Tom Barton, Kate Keahey,
Federated Identity Management for the context of storage Bart Kerver - TERENA Storage-meeting, Amsterdam,
NRENs supporting Grids using current Grid technology TERENA NREN-GRID Workshop Amsterdam Milan Sova CESNET.
The EC PERMIS Project David Chadwick
Authentication Policy David Kelsey CCLRC/RAL 15 April 2004, Dublin
The EU Grid PMA David Kelsey CCLRC/RAL 16 April 2004, Dublin
1 July 2005© 2005 University of Kent1 Seamless Integration of PERMIS and Shibboleth – Development of a Flexible PERMIS Authorisation Module for Shibboleth.
GridShib Grid-Shibboleth Integration Von Welch, Tom Barton, Kate Keahey, Frank Siebenlist GlobusWORLD 2005.
Co-ordination & Harmonisation of Advanced e-Infrastructures for Research and Education Data Sharing Grant.
12-May-03D.P.Kelsey, SCG Online Authentication1 Online Authentication SCG Meeting EDG Barcelona, 12 May 2003 David Kelsey CCLRC/RAL, UK
Federated Identity Management for HEP David Kelsey WLCG GDB 9 May 2012.
Grid Security Issues Shelestov Andrii Space Research Institute NASU-NSAU, Ukraine.
2005 © SWITCH Perspectives of Integrating AAI with Grid in EGEE-2 Christoph Witzig Amsterdam, October 17, 2005.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Interoperability Shibboleth - gLite Christoph.
High-quality Internet for higher education and research AAI from the NREN perspective Schiphol, October 17, 2005
John DYER 2 nd NREN – Grids Workshop 17 October 2005, Schiphol. 1 Second NREN – Grids Workshop John DYER TERENA Schiphol, Amsterdam 17 October 2005.
The Grid System Design Liu Xiangrui Beijing Institute of Technology.
EMI INFSO-RI AAI in EEF Projects John White (Helsinki University) EMI Security Area Leader.
TERENA TF-EMC2 Workshop David Groep,
Updates from the EUGridPMA David Groep, July 16 st, 2007.
1 4/23/2007 Introduction to Grid computing Sunil Avutu Graduate Student Dept.of Computer Science.
Identity Management in Open Science Grid Identity Management in Open Science Grid Challenges, Needs, and Future Directions Mine Altunay OSG Security Officer.
Kerberos and Identity Federations Daniel Kouřil, Luděk Matyska, Michal Procházka, Tomáš Kubina AFS & Kerberos Best Practices Worshop 2008.
AAI WG EMI Christoph Witzig on behalf of EMI AAI WG.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Security Token Service Valéry Tschopp - SWITCH.
Authors: Ronnie Julio Cole David
European Grid Policy Management Authority. Event - 2/total Speaker Name – Coverage of the EUGridPMA Green: Countries with an accredited.
ESnet RAF and eduroam ™ Tony J. Genovese ATF Team ESnet/Lawrence Berkeley National Laboratory.
Connect. Communicate. Collaborate The authN and authR infrastructure of perfSONAR MDM Ann Arbor, MI, September 2008.
Connect. Communicate. Collaborate The MetaData Service Distributing trust in AAI confederations Manuela Stanica, DFN.
GridShib and PERMIS Integration: Adding Policy driven Role-Based Access Control to Attribute-Based Authorisation in Grids Globus Toolkit is an open source.
Summary of AAAA Information David Kelsey Infrastructure Policy Group, Singapore, 15 Sep 2008.
Connect. Communicate. Collaborate Universität Stuttgart A Client Middleware for Token- Based Unified Single Sign On to eduGAIN Sascha Neinert, University.
Identity Management in DEISA/PRACE Vincent RIBAILLIER, Federated Identity Workshop, CERN, June 9 th, 2011.
Updates from the EUGridPMA David Groep, May 9 st, 2007.
Federated Identity Management for HEP David Kelsey HEPiX, IHEP Beijing 18 Oct 2012.
DTI Mission – 29 June LCG Security Ian Neilson LCG Security Officer Grid Deployment Group CERN.
Cyberinfrastructure Overview Russ Hobby, Internet2 ECSU CI Days 4 January 2008.
More Allergic Reactions Some Potential Next Steps Tom Barton University of Chicago.
Connect. Communicate. Collaborate Deploying Authorization Mechanisms for Federated Services in the eduroam architecture (DAMe)* Antonio F. Gómez-Skarmeta.
GRID ANATOMY Advanced Computing Concepts – Dr. Emmanuel Pilli.
Security Policy Update WLCG GDB CERN, 14 May 2008 David Kelsey STFC/RAL
EGI-InSPIRE RI EGI EGI-InSPIRE RI Establishing Identity in EGI the authentication trust fabric of the IGTF and EUGridPMA.
WLCG Authentication & Authorisation LHCOPN/LHCONE Rome, 29 April 2014 David Kelsey STFC/RAL.
Programme ›TERENA ›Overview of the middleware initiatives in the European Higher Education ›What is eduroam: the technology and how to set up eduroam ›eduroam-in-a-box:
Adding Distributed Trust Management to Shibboleth Srinivasan Iyer Sai Chaitanya.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Interoperability Shibboleth - gLite Christoph.
APGridPMA Update Eric Yen APGridPMA August, 2014.
INDIGO – DataCloud Security and Authorization in WP5 INFN RIA
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Security aspects (based on Romain Wartel’s.
A Study of Certification Authority Integration Model in a PKI Trust Federation on Distributed Infrastructures for Academic Research Eisaku SAKANE, Takeshi.
Update of APGridPMA Eric Yen 25 th EUGridPMA & IGTF All Hands Meeting KIT, Germany 7 May, 2012.
Introduction to AAI Services
Grids & PKI: TAGPMA & Bridges (Scott Rea – Dartmouth College) Internet2 Member Meeting, Dec 2006 PKI Implementers Workshop - Chicago, IL.
LCG Security Status and Issues
HellasGrid CA & euGridPMA
AAI in EGI Status and Evolution
Presentation transcript:

NRENs, Grids and Integrated AAI In Search For the Utopian Solution Christos Kanellopoulos AUTH/GRNET October 17 th, 2005 skanct at physics.auth.gr 2nd TERENA NREN-Grids Workshop

Outline ✔ NREN vs Grid?? ✔ Authentication Infrastructures ✔ EuGridPMA ✔ IGTF ✔ EduROAM ✔ Differences and Common Ground ✔ Authorization Infrastructures NRENs, Grids and Integrated AAI – In Search For the Utopian Solution Disclaimer: These are my personal views

NRENs vs Grids ✔ What is the Grid? ✔ “The flexible, secure, coordinated resource sharing among dynamic collections of individuals, institutions, and resources.” ✔ It is NOT just about computing and storage. It's a vision for the future of the Internet. Now let's get back to reality ✔ The goal is the same, but we are starting from different points NRENs, Grids and Integrated AAI – In Search For the Utopian Solution

Authentication Infrastructures in Europe ✔ ~2 Major authentication international federations across Europe ✔ EuGridPMA: Coordinate trust for access to distributed computing and storage resources ✔ EduRoam: Coordinate trust for access to network resources NRENs, Grids and Integrated AAI – In Search For the Utopian Solution

euGridPMA ✔ The EU DataGrid in 2000 needed a PKI for the test bed ✔ Both end-user and service/host PKI ✔ CACG (actually David Kelsey) had the task of creating this PKI ✔ for Grid Authentication only ✔ no support for long-term encryption or digital signatures ✔ Single CA was not considered acceptable ✔ Single point of attack or failure ✔ One CA per country, large region or international organization ✔ CA must have strong relationship with Ras ✔ Some pre-existing Cas ✔ A single hierarchy would have excluded existing CAs and was not convenient to support with existing software ✔ Coordinated group of peer CAs was most suitable choice NRENs, Grids and Integrated AAI – In Search For the Utopian Solution

euGridPMA More than 40 countries and regions ✔ Green: Accredited CAs ✔ Other Accredited CAs:  DoEGrids (US)  GridCanada  ASCCG (Taiwan)  ArmeSFO (Armenia)  CERN  Russia (“DataGrid”)  Israel (IUCC)  Pakistan  IHEP (China)  BalticGrid,  Turkey/ULAKBIM NRENs, Grids and Integrated AAI – In Search For the Utopian Solution

Extending Trust: IGTF – the International Grid Trust Federation ✔ common, global best practices for trust establishment ✔ better manageability and response of the PMAs NRENs, Grids and Integrated AAI – In Search For the Utopian Solution TAGPMA APGridPMA

Extending Trust: IGTF – Authentication Profiles NRENs, Grids and Integrated AAI – In Search For the Utopian Solution

eduRoam ✔ To provide National Research and Educational Networks (NRENs) users with secure Internet access at academic campuses (WLAN and wired) across Europe NRENs, Grids and Integrated AAI – In Search For the Utopian Solution

Differences EuGridPMA ✔ Access to “Grid” resources ✔ One central authority per country, region or international organization NRENs, Grids and Integrated AAI – In Search For the Utopian Solution EduRoam ✔ Access to Network resources ✔ Campus Authentication (mainly)

Common Ground ✔ Enable a common trust domain applicable to authentication of end-entities ✔ Policies for the authentication providers ✔ Authentication not bound to a specific method (both can leverage username/password or x509 authentication) NRENs, Grids and Integrated AAI – In Search For the Utopian Solution

Authentication Infrastructures in Europe ✔ What if I could use my “IGTF” certificate to have network connection at the “eduRoam enabled” institutes across the globe? ✔ What if I could use my eduRoam id to access the “grid enabled” resources as if I was at my institute from anywhere in the world ? NRENs, Grids and Integrated AAI – In Search For the Utopian Solution

Authorization Infrastructures in Europe ✔ Authorization is not as mature as authentication ✔ Various AAI solutions: ✔ A-Select ✔ FEIDE ✔ Liberty Alliance ✔ Papi ✔ Permis ✔ Shibboleth & GridShib ✔ In EGEE/LCG VOMS is being used as the authorization service, while in the NREN arena Shibboleth NRENs, Grids and Integrated AAI – In Search For the Utopian Solution

Authorization Infrastructures in Europe ✔ How do we get the role of the user? ✔ Pull vs Push ✔ Who defines the role of the user? ✔ What about users who have multiple roles perhaps under different organizations ? NRENs, Grids and Integrated AAI – In Search For the Utopian Solution

Authorization Infrastructures in Europe ✔ There has to be a harmonization in the attributes roles that are being used in the campuses. ✔ The Attribute Service has to be flexible. ✔ In the NREN world the campus is the central information point about the user. In the Grids world the role of the user is defined by the Virtual Organization ✔ We must not assume that there is always a central authority that handles the roles/attributes of the users. Management of attributes should be able to be delegated ✔ The Attribute Services have to speak a common language (SAML is here to stay) NRENs, Grids and Integrated AAI – In Search For the Utopian Solution

Conclusions ✔ Ther is still a long road for an integrated AAI ✔ We can not solve the problem all at once ✔ In “Authentication” we are getting closer! ✔ In the “Authorization” field, standardization is needed! (SAML and XACML might be the solution) NRENs, Grids and Integrated AAI – In Search For the Utopian Solution