VOPaaS Virtual Organisation Platform as a Service
|
|
|
- Natalie Lambert
- 10 years ago
- Views:
Transcription
1 VOPaaS Virtual Organisation Platform as a Service Marina Adomeit Task Leader, AMRES, Serbia Niels Van Dijk Technical Lead, SURFnet, The Netherlands FIM4R meeting Nov 30, 2015, Austria
2 About VOPaaS in GÉANT GÉANT project is Europe s leading collaboration on network and related infrastructure and services for the benefit of research and education. Majority of GÉANT members operate Identity Federations and GÉANT operates the edugain interfederation. GÉANT members also collaborate to design and deliver services. In order to support the uptake of federated technologies and enable more communities to use edugain, GÉANT initated a task offering hosted federation services. Federation as a Service - FaaS is service aimed to federation operators. Service offering is hosted federation metadata registry connected to edugain MDS. VO Platform as a Service VOPaaS offering is a simple, consistent way of offering and using federated services for virtual organisations, including group management, attribute authorities. 2
3 VO Platform as a Service Goal: Investigate the conditions that would allow GÉANT to provide services to support Virtual Organisations Focus on delivery of Technical services Out of scope: Technical development Policy & LOA development Activities: Gather requirements and priorities with/from communities Look at existing tools and technologies Look into delivery model Investigate business case & sustainability Operations and Market 3
4 Virtual Organisations and AAI Access to resources (or Services) often needs to be managed, and therefore requires authentication and authorization. When using Federated Authentication in R&E, the identity is managed at the Home Institution. The Identity provider (IdP), operated by the Home Institution, allows the authentication towards a Service Provider (SP). Identity Federations provide trust frameworks between Service Providers and Institutions. Interfederation, such as edugain, emerged because of the need to interconnect National identity federations. For international collaborations, federated AAI based on edugain looks like an extremely useful infrastructure to build on. 4
5 Virtual Organisations and AAI Authorization is about specifying access rights to a Service To be able to grant access, a Service needs information beyond Authentication In Identity Federations this information is often conveyed using attributes Often attributes from the Home Organisation alone are not enough: VO related Services need attribute information in the context of the VO VOs therefore need to be able to manage and provide attribute and group information towards Services, independently from the Home Organisation 5
6 Requirements for building on Federated AAI as a VO The FIM4R paper (April 2012) was one of the first to articulate collective requirements for using Federated AAI for VOs. Many VOs have chosen to build the AAI infrastructure using the national and edugain infrastructures. Identity Federations and Identity providers are however traditionally focused on Campus use cases, which introduces a number of challenges for VOs in leveraging Federated AAI. The VOPaaS has performed a survey among several small and large Pan- European VOs to (re-)validate the FIM4R requirements. From the results of this Survey, functional requirements were analyzed. A number of services were proposed to be put in place to support VOs on a Pan-European level. 6
7 VOPaaS Market Analysis Interviews and desk study conducted with: Umbrella CLASSe DARIAH CERN CLARIN Virtual Campus Hub ELIXIR GÉANT VAPIRE (Large neutron and photon facilities) (Shared IaaS) (Humanities) (High Energy Physics) (Humanities and social sciences) (elearning, Renewable Energy) (Life Sciences, Bioinformatics) (NREN collaboration). Broad NREN/federation participation: AMRES, CESNET, DFN/LRZ, GARR, IUCC, NIIF, RENATER, SUNET, SURFnet, SWITCH Market Analysis 7
8 VOpaas Market Analysis Results 8
9 Function requirements for VOPaaS Functional requirements identified Persistent Identifier - Allow the VO to identify the user even if (s)he changes IdP VO Membership Registry - To become members of the VO a certain workflow must be followed External Identities - Many VO users will not be in edugain Attribute Management - Attributes beyond the IdP are needed for VO roles and rights, or to provide extra context (e.g. ORCID, Grant number) Group Management - groups may also be used to define roles and rights (de)provisioning Identity, attributes and groups need to be provided to Services Service Proxy and Attribute Aggregation A centralised infrastructure to operate on behalf of the VO Service Providers 9
10 Deployment model Basic Services Operated by GÉANT Multi tenant service Also for VOs that are not legal entities Operated as a (set of) Services Advanced Services Operated by GÉANT on behalf of a VO Single tenant service Somebody a legal entity - must take responsibility for that data Operates as per VO applications on VM boxes 10
11 Basic Services VO Membership service registry for VO persistent Identifier VO specific Workflows for onboarding Limited set of attributes Accessible through edugain & TEIP Transparent External Identity proxy (TEIP) One persistent (SAML) IdP for many Guest Identity Providers, including: Social (Google, Twitter, Linkedin, Facebook) NREN operated & Commercial Guest IdPs (OpenIDP, UnitedID.org, eduid.se) egov (STORK) BankID Provides LOA: eidas by default, others upon request from SP Available and accessible through edugain 11
12 Advanced Services (advanced) Attribute Management - Whatever you can come up with (advanced) Group Management - Groups in groups, etc. Provisioning - For web and non-web resources, application specific connectors Service Proxy and Attribute Aggregation To have a central point for technology and policy Accessible through edugain & extidp May be delivered as a paid service 12
13 Tools Basic Services VO Membership service: COmanage Transparent External Identity Proxy (TEIP): SaToSa Advanced Services Attributes and Groups: HEXAA, PERUN and COmanage SP Proxy: OpenConext 13
14 VOPaaS membership registration functional design 14
15 VOPaaS TEIP functional design 15
16 VOPaaS Future 2015 Market Analysis Cost Benefit Analysis & Business Model Deploy pilot platform Q Run pilots with Basic Services, in collaboration with AARC Interested to have your VO participating in the pilot? Contact us: Support application integrations 2016 Production service for Basic Services Deploy Pilots for Advanced Services Possibly: pick up new services as developed within GEANT, AARC or others 16
17 Thank you This work is part of a project that has applied for funding from the European Union s Horizon 2020 research and innovation programme under Grant Agreement No (GN4-1). 17
Federated Identity Management Interest Group
1 Federated Identity Management Interest Group The FIM interest group (FIMig) is an international crossdomain interest group to work on all issues related to the use FIM for the implementation of AAIs
Collaboration in the Cloud. Niels van Dijk, SURFnet, [email protected] CAMP, Nov 15 2013, San Francisco
Collaboration in the Cloud Niels van Dijk, SURFnet, [email protected] CAMP, Nov 15 2013, San Francisco R&E SURF in and The SURFnet Netherlands: SURF and SURFnet National Research & Education Network
GÉANT IaaS suppliers meeting Towards Pan-European Cloud Services. Utrecht October 14 2015
GÉANT IaaS suppliers meeting Towards Pan-European Cloud Services Utrecht October 14 2015 Why and what TODAY More information about IaaS delivery through GÉANT Tender Provider GÉANT interaction Opportunity
GN3plus JRA3 T1 Attribute and Group management in the AAI environment
GN3plus JRA3 T1 Attribute and Group management in the AAI environment Maarten Kremers, SURFnet Internet2 Technology Exchange 2014, Indianapolis, IN October 29 th 2014 GÉANT (GN3plus) - vital to the EU
Licia Florio Project Development Officer [email protected] www.terena.org Identity Federations in Europe
APAN Conference Honolulu, Hawaii 24 January 2008 Licia Florio Project Development Officer [email protected] www.terena.org Identity Federations in Europe Outline Networking Organisations in Europe Requirements
Identity Management Systems for Collaborations and Virtual Organizations
Identity Management Systems for Collaborations and Virtual Organizations Topics Update on Internet identity IdM Systems for Virtual Organizations Goals Early Implementations Issues and Discussions Update
Three Case Studies in Access Management
Three Case Studies in Access Management IAM Online June 10, 2015-2 pm EDT Andy Morgan, Oregon State University Mandeep Saini, GÉANT Albert Wu, UCLA Moderator: Tom Barton, University of Chicago Fit for
CLOUD POWER. NREN collaboration in GÉANT @ STF
CLOUD POWER NREN collaboration in GÉANT to enable and facilitate the Research and Education community to use online services on a large scale, with the right conditions @ STF MARCH 24 Andres Steijaert
Federated Identity Management
Federated Identity Management SWITCHaai Team [email protected] Agenda 2 What is Federated Identity Management? What is a Federation? The SWITCHaai Federation Interfederation Evolution of Identity Management
Federated Identity Management for Research Communities (FIM4R)
Federated Identity Management for Research Communities (FIM4R) David Kelsey (STFC-RAL, UK) [email protected] Federations Virtual Day 19 Jun 2013 Who am I? Head of Particle Physics Computing at RAL
Federated Identity Management and Shibboleth. Noreen Hogan Asst. Director Enterprise Admin. Applications
Federated Identity Management and Shibboleth Noreen Hogan Asst. Director Enterprise Admin. Applications Federated Identity Management Management of digital identity/credentials (username/password) Access
TERENA Trusted Cloud Drive
SUCRE Workshop Open Source Clouds in the public sector 16-17 April, 2013 Poznan, Poland Peter Szegedi Project Development Officer [email protected] www.terena.org TERENA Trusted Cloud Drive Unleashing
AAI for Mobile Apps How mobile Apps can use SAML Authentication and Attributes. Lukas Hämmerle [email protected]
AAI for Mobile Apps How mobile Apps can use SAML Authentication and Attributes Lukas Hämmerle [email protected] Berne, 13. August 2014 Introduction App by University of St. Gallen Universities
Step-up-authetication as a service
Step-up-authetication as a service Pieter van der Meulen Technical Product Manager For more details see the report at: http://www.surfnet.nl/ Documents/rapport_Step-up_Authentication-as-a- Service_Architecture_and_Procedures_final.pdf
Development and deployment of integrated attribute based access control for collaboration
Development and deployment of integrated attribute based access control for collaboration Collaborations and Virtual Organizations IdM is a critical dimension of collaboration, crossing many applications
Toward the Clouds, Together!
Toward the Clouds, Together! Collaboration effort of European NRENs in Cloud Computing Branko Radojević, Deputy Director, CARNet/GEANT E-Infrastructure Autumn Workshops Chișinău Where do I come from? NRENs.000
Big Data in BioMedical Sciences. Steven Newhouse, Head of Technical Services, EMBL-EBI
Big Data in BioMedical Sciences Steven Newhouse, Head of Technical Services, EMBL-EBI Big Data for BioMedical Sciences EMBL-EBI: What we do and why? Challenges & Opportunities Infrastructure Requirements
The Case for NRENs John DYER
The Case for NRENs John DYER TF- MSP Meeting, Espoo, Finland 9/10 September 2015 Networks Services People www.geant.org The Case for NRENs Published January 2009 This presentation is dedicated to continuing
Federations 101. An Introduction to Federated Identity Management. Peter Gietz, Martin Haase
Authentication and Authorisation for Research and Collaboration Federations 101 An Introduction to Federated Identity Management Peter Gietz, Martin Haase AARC NA2 Task 2 - Outreach and Dissemination DAASI
GN3+ SA3T3 / Multi-Domain-VPN service: Collaboration of NREN s NOC
GN3+ SA3T3 / Multi-Domain-VPN service: Collaboration of NREN s NOC 10 th TF NOC meeting (Cambridge) Friday, 21 March 2014 Xavier Jeannin / RENATER, SA3T3 Task Leader Miguel Angel Sotos / RedIRIS Bojan
Federated Identity Management for Research Collaborations
Federated Identity Management for Research Collaborations Paper Type: Research paper Date of this version: 23 rd April 2012 Abstract Federated identity management (FIM) is an arrangement that can be made
CLOUD POWER. NREN collaboration in GÉANT
CLOUD POWER NREN collaboration in GÉANT to enable and facilitate the Research and Education community to use online services on a large scale, with the right conditions @ edupert MARCH 19 Andres Steijaert
UW System Identity & Access Management (IAM) Recommended Strategic Roadmap
UW System Identity & Access Management (IAM) Recommended Strategic Roadmap Fall 2015 ITMC (Rev 1/11) Our challenge CIOs charged IAM-TAG with recommending an IAM strategy that would: Establish an identity
Guideline on Implementing Cloud Identity and Access Management
CMSGu2013-05 Mauritian Computer Emergency Response Team CERT-MU SECURITY GUIDELINE 2011-02 Enhancing Cyber Security in Mauritius Guideline on Implementing Cloud Identity and Access Management National
INDIGO-DataCloud Wupi 4 (Resource Virtualization)
INDIGO-DataCloud Wupi 4 (Resource Virtualization) All stolen from Markus, Enol, Maciej, Giacionto and many others High level objective This work package is focusing on virtualizing local computing, storage
Introduc)on to STORK2.0 project
Introduc)on to STORK2.0 project AAI Workshop Brussels, April 2014 EUROPEAN EID CONTEXT FOR EGOVERNMENT NaKonal online services today with eid CENTRAL GOVERNMENT ONLINE SERVICES LOCAL GOVERNMENT ONLINE
Perun Modern Approach for User and Service Management
IST-Africa 2014 Conference Proceedings Paul Cunningham and Miriam Cunningham (Eds) IIMC International Information Management Corporation, 2014 ISBN: 978-1-905824-44-1 Perun Modern Approach for User and
TrustedX: eidas Platform
TrustedX: eidas Platform Identification, authentication and electronic signature platform for Web environments. Guarantees identity via adaptive authentication and the recognition of either corporate,
Provisioning and deprovisioning in an identity federation
Provisioning and deprovisioning in an identity federation Problem description and solution proposals 19.12.2008/[email protected] Contents 1. Description of the context... 2 2. Problem description...
OIX IDAP Alpha Project - Technical Findings
OIX IDAP Alpha Project - Technical Findings Warwickshire County Council - using a Federated UK Government ID in trusted Local Authority transactions. By Graham Dunnings and Ian Litton 1 Table of Contents
IGI Portal architecture and interaction with a CA- online
IGI Portal architecture and interaction with a CA- online Abstract In the framework of the Italian Grid Infrastructure, we are designing a web portal for the grid and cloud services provisioning. In following
Identity and Access Management for Federated Resource Sharing: Shibboleth Stories
Identity and Access Management for Federated Resource Sharing: Shibboleth Stories http://arch.doit.wisc.edu/keith/apan/ apanshib-060122-01.ppt Keith Hazelton ([email protected]) Sr. IT Architect,
Federated Authentication and Credential Translation in the EUDAT Collaborative Data Infrastructure
Federated Authentication and Credential Translation in the EUDAT Collaborative Data Infrastructure Ahmed Shiraz Memon (JSC - DE) Jens Jensen (STFC escience - UK) Ales Cernivec (XLAB - SL) Krzysztof Benedyczak
SURFconext, Cloud Integration for Higher Education and Research. Paul van Dijk, Product Manager SURFnet
SURFconext, Cloud Integration for Higher Education and Research Paul van Dijk, Product Manager SURFnet 1 SURF CyberInfra National Research & Education Network Commercial ICT Products & Services Scientific
Security in Federated e-infrastructure
Security in Federated e-infrastructure and Identity Management Boris Parák 2 Slávek Licehammer 1,2 1 Masaryk University 2 CESNET May 18, 2015 www.egi.eu EGI-Engage is co-funded by the Horizon 2020 Framework
Standardisation of eduroam Testing, Monitoring, Metrics and Support Tools
STANDARDISATION OF EDUROAM TESTING, MONITORING, METRICS AND SUPPORT TOOLS Page 1/16 20 January 2014 Standardisation of eduroam Testing, Monitoring, Metrics and Support Tools Neil Witheridge [email protected]
Agenda. NRENs, GARR and GEANT in a nutshell SDN Activities Conclusion. Mauro Campanella Internet Festival, Pisa 9 Oct 2015 2
Agenda NRENs, GARR and GEANT in a nutshell SDN Activities Conclusion 2 3 The Campus-NREN-GÉANT ecosystem CAMPUS networks NRENs GÉANT backbone. GÉANT Optical + switching platforms Multi-Domain environment
PRACTICAL IDENTITY AND ACCESS MANAGEMENT FOR CLOUD - A PRIMER ON THREE COMMON ADOPTION PATTERNS FOR CLOUD SECURITY
PRACTICAL IDENTITY AND ACCESS MANAGEMENT FOR CLOUD - A PRIMER ON THREE COMMON ADOPTION PATTERNS FOR CLOUD SECURITY Shane Weeden IBM Session ID: CLD-W01 Session Classification: Advanced Agenda Cloud security
MY1LOGIN SOLUTION BRIEF: PROVISIONING. Automated Provisioning of Users Access to Apps
MY1LOGIN SOLUTION BRIEF: PROVISIONING Automated Provisioning of Users Access to Apps MY1LOGIN SOLUTION BRIEF: PROVISIONING Automated Provisioning of Users Access to Apps The ability to centrally provision
The Top 5 Federated Single Sign-On Scenarios
The Top 5 Federated Single Sign-On Scenarios Table of Contents Executive Summary... 1 The Solution: Standards-Based Federation... 2 Service Provider Initiated SSO...3 Identity Provider Initiated SSO...3
Federated Identity Management
Federated Identity Management SWITCHaai Introduction Course Bern, 1. March 2013 Thomas Lenggenhager [email protected] Overview What is Federated Identity Management? What is a Federation? The SWITCHaai Federation
Federated Identity Management. Willem Elbers (MPI-TLA) EUDAT training
Federated Identity Management Willem Elbers (MPI-TLA) EUDAT training Date: 26 June 2012 Outline FIM and introduction to components Federation and metadata National Identity federations and inter federations
Разработка программного обеспечения промежуточного слоя. TERENA BASNET Workshop, 16-17 November 2009 Joost van Dijk - SURFnet
Разработка программного обеспечения промежуточного слоя TERENA BASNET Workshop, 16-17 November 2009 Joost van Dijk - SURFnet Contents - SURFnet Middleware Services department: - eduroam, SURFfederatie,
Lets get a federated identity. Intro to Federated Identity. Feide OpenIdP. Enter your email address. Do you have access to your email?
Lets get a feated identity Intro to Feated Identity EuroCAMP Training for APAN32 This work is licensed un a Creative Commons Attribution ShareAlike 3.0 Unported License. Do you have access to your email?
SURFfederatie - edugain. Opt-in Metadata Management for a Hub & Spoke Federation
SURFfederatie - edugain Opt-in Metadata Management for a Hub & Spoke Federation Content - History of SURFfederatie - Federation models - Functional view - Consequences of hub & spoke - edugain - Future
Single Sign On. SSO & ID Management for Web and Mobile Applications
Single Sign On and ID Management Single Sign On SSO & ID Management for Web and Mobile Applications Presenter: Manish Harsh Program Manager for Developer Marketing Platforms of NVIDIA (Visual Computing
Increase the Security of Your Box Account With Single Sign-On
A Box White Paper Increase the Security of Your Box Account With Single Sign-On Box s high level of security, 24x7 support and 99.9% uptime are critical for us. The biggest benefits are the reliability
Success Story. GÉANT Operations Centre Improves SLA Management Service and Efficiencies with Cloud-based Version of OTRS.
GÉANT Operations Centre Improves SLA Management Service and Efficiencies with Cloud-based Version of OTRS. & At a Glance Customer GÉANT OTRS Solution Managed OTRS Platinum Tickets per month 500 Appr. Staff
MPLS multi-domain services MD-VPN service
MPLS multi-domain services MD-VPN service Xavier Jeannin, RENATER Tomasz Szewczyk / PSNC Training and Workshops for advancing NRENs 8-11 Sept 2014 Chisinau, Moldova MPLS brief overview Original purpose:
EXTENDING SINGLE SIGN-ON TO AMAZON WEB SERVICES
pingidentity.com EXTENDING SINGLE SIGN-ON TO AMAZON WEB SERVICES Best practices for identity federation in AWS Table of Contents Executive Overview 3 Introduction: Identity and Access Management in Amazon
THE RESEARCH INFRASTRUCTURES IN FP7
29 October 2004 Working Document on THE RESEARCH INFRASTRUCTURES IN FP7 Introduction In the Commission s communication on the financial perspectives of the European Union for the period 2007-2013 1, the
Software Design Document SAMLv2 IDP Proxying
Software Design Document SAMLv2 IDP Proxying Federation Manager 7.5 Version 0.2 Please send comments to: [email protected] This document is subject to the following license: COMMON DEVELOPMENT AND
AA enabling a closed source legacy application
AA enabling a closed source legacy application Jan Du Caju ICT security officer K.U.Leuven Belgium AA enabling a closed source legacy application Introduction: context association K.U.Leuven Case: AA enabling
Trial of the Infinera PXM. Guy Roberts, Mian Usman
Trial of the Infinera PXM Guy Roberts, Mian Usman LHC Workshop Recap Rather than maintaining distinct networks, the LHC community should aim to unify its network infrastructure Traffic aggregation on few
A Federated Authorization and Authentication Infrastructure for Unified Single Sign On
A Federated Authorization and Authentication Infrastructure for Unified Single Sign On Sascha Neinert Computing Centre University of Stuttgart Allmandring 30a 70550 Stuttgart [email protected]
