RDA Report Working Meeting Session 5 IG Federated Identity Management. Presentations

Size: px
Start display at page:

Download "RDA Report Working Meeting Session 5 IG Federated Identity Management. Presentations"

Transcription

1 RDA Report Working Meeting Session 5 IG Federated Identity Management Notes by F VandenBoom Presentations The AARC project, report by Licia Florio by improving the interoperability of existing AAIs, defining a common policy framework that is accepted and implemented by all einfrastructures and by offering a diversified training package for different communities. Feedback on available deliverables is appreciated. The next meeting more details will be given. Presentation on the following work done: Trainings and outreach. There is lack of training for nonexperts and service providers. Policy work on what is needed. The working Party looked at security incidents on Fin fed infrastructure joint work with the sirtfi WG. A sustainable LoA framework. Looking at identity providers: Why do they need it, why and what do they need? The goal is to come up with framework. At a level which is implementable Architecture design Final version will have all requirements in one document and will lead to second analysis document on available technologies that people are using. Goal is to know what is available and what is missing. Main work now is focus on what to do with guest identities, and attribute authorities. The final outcome will provide a basis for pilot activities More detail of research: outputs of past activities plus AARC surveys amongst research communities, AARC interviews with research communities to translate these into use cases. End of the year goals is to have community supported requirements. Q&A Corporate not directly represented in user communities There is new stuff from various infrastructures and communities such as: Persistent and unique user identifiers User management identity info Integration with egovernment infrastructures Policy harmonization Best practices for terms and conditions. Next steps Continue with interviews

2 Analysis of available AA technologies Consultation with stakeholders Release work of guest identities, AA and TTS The THOR project, FIM and PIDs, by Tom Demeranville it will establish seamless integration between articles, data, and researchers across the research lifecycle. This will create a wealth of open resources and foster a sustainable international einfrastructure. THOR aims to establish interoperability, integrating services, build capacity and achieving sustainability 10 partners 2,5 years project looking at PID landscape to analyze gaps and to see where they can be integrated into existing or new systems. Outreach in the EU and beyond. Current activities: Delivering an output research document analyzing gaps where effort can be focused. ORCID is put into SURF FEDERATION and be available via EDUGAIN. This will allow institutional sign in, verified affiliation and attribute claims, and ORCHID ID as a federated attribute. ORCID attribute : Better for certain use cases Links authors across domains Persistent throughout career Can be solved for more info Current activities HAKA/ORCID ORCID as a complement to existing FIM infrastructure ORCID as a social ID or guest identity provider ORCID as a ID proxy? The future of PID s in FIM: Investigating options and use cases. Q&A Identity curation in ORCID: what about is there something missing to validate certain groups (homeless/dead people)? ORCHID is curated by the individual, who and curates what file is connected to his profile. The authority is the individual there is no other who decides if this linking is correct, authenticated. How does this work if dead? The system is as reliable as a resume or a form. EUDAT's B2ACCESS service and FIM integration by Johannes Reetz EUDAT offers common data services, supporting multiple research communities as well as individuals, through a geographically distributed, resilient network

3 connecting general purpose data centres and communityspecific data repositories. The aim is to deliver general data service for open access and supporting EC policies. Because there are many different communities of users: user credentials must be taken into account: there is no one fits all. Collaborate data infrastructure. There will be an integration of different operational services. Purpose of B2ACCESS Arbitrate authentication to EUDAT services. Use of external services but also own ID when people are not affiliated to an institution and also social ID s AI approach Using UNITY core identity management: user set care and group attribute management, authorization server. EUDAT services. Current state Integration o Identity providers o Integrated EUDAT service providers Groups and attributes o Management B2services o Documentation in October2015 level of assurance o Currently based on Provider used to log in o Social identity is low o Same from academic accounts = higher Finalizing documentation Identity providers o EDUGAIN o community Collaborations o especially integration with B2STAGE Collaboration with AARC, THOR,ORCID OpenStack FIM integration by CERN & Rackspace by Tim Bell OpenStack is a cloud operating system that controls large pools of compute, storage, and networking resources throughout a datacenter, all managed through a dashboard that gives administrators control while empowering their users to provision resources through a web interface. Current research: CERN Openlabs research on open design process Iterative design using open blueprints, Source code under apache 2 license. Continuous integration, Keystone authentication options, Password, Active directory, openidconnect, Kerberos In 2015 the project had companies support with public and private providers adoption.

4 Examples of potential use 1) Federation with a cloud provider such as Rackspace 2) o HORIZON2020 INDIGO dataclouds o CERN defines cloud project o WEB SSO o API/CLI Experiences Classic policy problems: What if user not signed up? Watch out for nonfederated services o who owns resources at the site? Traceability for ephemeral accounts Summary: Significant commercial interest and investment Easy to miss nonfederated services when deploying uses. Video s available online DARIAH by Peter Gietz The Digital Research Infrastructure for the Arts and Humanities, aims to enhance and support digitallyenabled research and teaching across the humanities and arts The mission is to develop infrastructure support, such as text grid Current figures 3000 DARIAH users and 180 federated users. Seems easier to create a DARIAH account instead of home IT department. 239 different user groups. Fully support of coco conduct Integrated in DFNAAI Strong will on sustainability infrastructure Integrating 0Auth2 for non web Tokens ORCID ID Cooperation s New DARIAH EU working group FIM4D and FIM4R Next meeting nov 30 th Pilot in GEANT 3 plus Anticipating in AARC FIM, CLARIN by Menzo Windhouwer CLARIN is the Common Language Resources and Technology Infrastructure, which aims to provide easy and sustainable access for scholars in the humanities and

5 social sciences to digital language data (in written, spoken, video or multimodal form), and advanced tools to discover, explore, exploit, annotate, analyse or combine them, wherever they are located. Language resources pilot progress A legal proxy where ERIC joins national identity federations Problem with OAuth2 bridge Solution: authorization service SAML bridge implementation in trial use cases looking at Authorization server Oauth client Oauth2 resource server Interaction between registries, tools and archives, tools and private workspaces. Future plan: ready for production, add more service providers and federations. Project Presentation from within the group Federated management photon and neutron in Europe Signed MLU between facilities participating umbrella platform Users are increasing Connected to EDUGAIN MOONSHOT part of GEANT one of the pilots and in AARC project FIM for research group Continues but within RDA just sharing info but during the FIM4R workshop in Vienna will go more into depth DISCUSSION Continue FIM interest group sessions? The initial motivation was to have interaction with people from outside Europe (3 in the room). Good for exposure and attracts interest from other groups FIM4 research open for global collaboration : RDA important research data activity for similar interoperable technologies then this group has reason of its own in this field Is there an interest in a working group that has any output on identity management? Intention umbrella FIM related activities, with THOR it could become more specific: Federated Entity Management: need for different systems that are interoperable. Note on the RDA Fabric group: a response that AI not existing on any level, but there are solutions that are growing. However far from general accepted federated authorization management.

6 Comments on the purpose of RDA It is about similar sharing of data, federated management is a first step. Authorization is very important, location not as important. More important is what you get out of coming here to RDA. You learn what are people doing and using. We are far way from single blueprint but at least you get info about what is happening. Seems that infrastructure includes corporate world but what about pharmaceutical? Interest in having access to open data and open services, may want to provide data themselves. In order to do that federated data management is needed. Commercial partners have been invited to give presentations but never regarded commercial solutions for adoption. Should we take special measures to accommodate commercial solution? Bring services on infrastructure both non and commercial world Many institutions have problems with integration. Proposal for an umbrella working group, Enough material such as ORCID as structure and others to make declaration on principles. Scope is federated entity registries, organizations and identities. With the Interest Group provide clarifications on other project outcomes such as the Data Fabricgroup document Overlap with other group coming from PID interest group? Where do they overlap? How do information items get from one source to another or other protocols and mechanisms? Has this scope be claimed? Same subject but two different approaches which one is the better one? Overview of possibilities working together and coming up with recommendations, not on software implementations.

Federated Identity Management Interest Group

Federated Identity Management Interest Group 1 Federated Identity Management Interest Group The FIM interest group (FIMig) is an international crossdomain interest group to work on all issues related to the use FIM for the implementation of AAIs

More information

Federated Authentication and Credential Translation in the EUDAT Collaborative Data Infrastructure

Federated Authentication and Credential Translation in the EUDAT Collaborative Data Infrastructure Federated Authentication and Credential Translation in the EUDAT Collaborative Data Infrastructure Ahmed Shiraz Memon (JSC - DE) Jens Jensen (STFC escience - UK) Ales Cernivec (XLAB - SL) Krzysztof Benedyczak

More information

VOPaaS Virtual Organisation Platform as a Service

VOPaaS Virtual Organisation Platform as a Service VOPaaS Virtual Organisation Platform as a Service Marina Adomeit Task Leader, AMRES, Serbia Niels Van Dijk Technical Lead, SURFnet, The Netherlands FIM4R meeting Nov 30, 2015, Austria About VOPaaS in GÉANT

More information

Research Data Alliance: Current Activities and Expected Impact. SGBD Workshop, May 2014 Herman Stehouwer

Research Data Alliance: Current Activities and Expected Impact. SGBD Workshop, May 2014 Herman Stehouwer Research Data Alliance: Current Activities and Expected Impact SGBD Workshop, May 2014 Herman Stehouwer The Vision 2 Researchers and innovators openly share data across technologies, disciplines, and countries

More information

Case Studies in Federated Identity Management for Research Communities

Case Studies in Federated Identity Management for Research Communities Case Studies in Federated Identity Management for Research Communities Authors/Affiliations Ann Harding, ann.harding@switch.ch +41 44 253 98 14 SWITCH/GN3plus Peter Gietz, peter.gietz@daasi.de DAASI International

More information

Federated Identity Management for Research Communities (FIM4R)

Federated Identity Management for Research Communities (FIM4R) Federated Identity Management for Research Communities (FIM4R) David Kelsey (STFC-RAL, UK) david.kelsey@stfc.ac.uk Federations Virtual Day 19 Jun 2013 Who am I? Head of Particle Physics Computing at RAL

More information

Federations 101. An Introduction to Federated Identity Management. Peter Gietz, Martin Haase

Federations 101. An Introduction to Federated Identity Management. Peter Gietz, Martin Haase Authentication and Authorisation for Research and Collaboration Federations 101 An Introduction to Federated Identity Management Peter Gietz, Martin Haase AARC NA2 Task 2 - Outreach and Dissemination DAASI

More information

Deliverable D9.2 Market Analysis for Virtual Organisation Platform as a Service (VOPaaS)

Deliverable D9.2 Market Analysis for Virtual Organisation Platform as a Service (VOPaaS) 19-11-2015 Contractual Date: 30-09-2015 Actual Date: 19-11-2015 Grant Agreement No.: 691567 Activity: SA5 Task Item: 4 Nature of Deliverable: R (Report) Dissemination Level: PU (Public) Lead Partner: AMRES

More information

INDIGO DataCloud. Technical Overview RIA-653549. Giacinto.Donvito@ba.infn.it. INFN-Bari

INDIGO DataCloud. Technical Overview RIA-653549. Giacinto.Donvito@ba.infn.it. INFN-Bari INDIGO DataCloud Technical Overview RIA-653549 Giacinto.Donvito@ba.infn.it INFN-Bari Agenda Gap analysis Goals Architecture WPs activities Conclusions 2 Gap Analysis Support federated identities and provide

More information

A Federated Authorization and Authentication Infrastructure for Unified Single Sign On

A Federated Authorization and Authentication Infrastructure for Unified Single Sign On A Federated Authorization and Authentication Infrastructure for Unified Single Sign On Sascha Neinert Computing Centre University of Stuttgart Allmandring 30a 70550 Stuttgart sascha.neinert@rus.uni-stuttgart.de

More information

EUDAT. Towards a pan-european Collaborative Data Infrastructure. Willem Elbers

EUDAT. Towards a pan-european Collaborative Data Infrastructure. Willem Elbers EUDAT Towards a pan-european Collaborative Data Infrastructure Willem Elbers EUDAT / MPI-TLA Focus meeting: Data repositories SURF, Utrecht March 3, 2014 Outline EUDAT project EUDAT services Summary and

More information

Adding Federated Identity Management to Openstack

Adding Federated Identity Management to Openstack Adding Federated Identity Management to Openstack David Chadwick d.w.chadwick@kent.ac.uk 5 April 2014 Cloud Computing Security and Identity Workshop, NMOC 1 OpenStack Large open source project to develop

More information

How To Build An Open Source Data Infrastructure

How To Build An Open Source Data Infrastructure EUDAT Collaborative Data Infrastructure Towards the convergence of Compute, Data, Knowledge and Scientific Instruments Giuseppe Fiameni CINECA www.eudat.eu EUDAT receives funding from the European Union's

More information

EUDAT Federated AAI TF (Authentication Authorization Infrastructure Task Force)

EUDAT Federated AAI TF (Authentication Authorization Infrastructure Task Force) EUDAT Federated AAI TF (Authentication Authorization Infrastructure Task Force) EUDAT WP5 Slides by Jens Jensen+AAITF Presented by Claudio Cacciari (c.cacciari@cineca.it) Date:2012/03/08 Outline Background

More information

Experiences in Supporting Service Providers and User Communities. Lukas Hämmerle, GÉANT/SWITCH AAI@eduHR Conference 26 November 2014

Experiences in Supporting Service Providers and User Communities. Lukas Hämmerle, GÉANT/SWITCH AAI@eduHR Conference 26 November 2014 Experiences in Supporting Service Providers and User Communities Lukas Hämmerle, GÉANT/SWITCH AAI@eduHR Conference 26 November 2014 Who am I! Work almost 10 years for SWITCH (Swiss NREN)! Mostly involved

More information

Cloud federation. Prelude to Hybrid Clouds. CHEP 2015 Okinawa, Japan. Marek Denis CERN Geneva, Switzerland

Cloud federation. Prelude to Hybrid Clouds. CHEP 2015 Okinawa, Japan. Marek Denis CERN Geneva, Switzerland Cloud federation CHEP 2015 Okinawa, Japan Prelude to Hybrid Clouds Marek Denis CERN Geneva, Switzerland Basic definitions OpenStack: An Open Source Cloud Managing System which allows implementors to: --

More information

managing SSO with shared credentials

managing SSO with shared credentials managing SSO with shared credentials Introduction to Single Sign On (SSO) All organizations, small and big alike, today have a bunch of applications that must be accessed by different employees throughout

More information

Big Data Challenges for e-science Infrastructure

Big Data Challenges for e-science Infrastructure Big Challenges for e-science Infrastructure Yuri Demchenko, SNE Group, University of Amsterdam AAA-Study Project COINFO2012 Conference 24-25 November 2012, Nanjing, China 23-25 November 2012, Nanjing Big

More information

Enabling a federated environment to support biomedical research. Gianmauro Cuccuru CRS4

Enabling a federated environment to support biomedical research. Gianmauro Cuccuru CRS4 Enabling a federated environment to support biomedical research Gianmauro Cuccuru CRS4 ELIXIR connects national bioinformatics centres and EMBL- EBI into a sustainable European infrastructure for biological

More information

Extend and Enhance AD FS

Extend and Enhance AD FS Extend and Enhance AD FS December 2013 Sponsored By Contents Extend and Enhance AD FS By Sean Deuby Introduction...2 Web Service SSO Architecture...3 AD FS Overview...5 Ping Identity Solutions...7 Synergy

More information

Adding Federated Identity Management to OpenStack

Adding Federated Identity Management to OpenStack Adding Federated Identity Management to OpenStack David Chadwick University of Kent 3 December 2012 University of Kent 1 Some Definitions What is Identity? A whole set of attributes that in combination

More information

Flexible Identity Federation

Flexible Identity Federation Flexible Identity Federation Quick start guide version 1.0.1 Publication history Date Description Revision 2015.09.23 initial release 1.0.0 2015.12.11 minor updates 1.0.1 Copyright Orange Business Services

More information

Title: A Client Middleware for Token-Based Unified Single Sign On to edugain

Title: A Client Middleware for Token-Based Unified Single Sign On to edugain Title: A Client Middleware for Token-Based Unified Single Sign On to edugain Sascha Neinert Computing Centre University of Stuttgart, Allmandring 30a, 70550 Stuttgart, Germany e-mail: sascha.neinert@rus.uni-stuttgart.de

More information

Licia Florio Project Development Officer licia@terena.org www.terena.org Identity Federations in Europe

Licia Florio Project Development Officer licia@terena.org www.terena.org Identity Federations in Europe APAN Conference Honolulu, Hawaii 24 January 2008 Licia Florio Project Development Officer licia@terena.org www.terena.org Identity Federations in Europe Outline Networking Organisations in Europe Requirements

More information

Service Interoperability

Service Interoperability Service Interoperability Multi-Modal Interoperability Concept (M 1.3.4.1) Version 12/05/2013 Work Package 1.3 Responsible Partner MPDL DARIAH-DE Aufbau von Forschungsinfrastrukturen für die e-humanities

More information

Onegini Token server / Web API Platform

Onegini Token server / Web API Platform Onegini Token server / Web API Platform Companies and users interact securely by sharing data between different applications The Onegini Token server is a complete solution for managing your customer s

More information

Entrust IdentityGuard Comprehensive

Entrust IdentityGuard Comprehensive Entrust IdentityGuard Comprehensive Entrust IdentityGuard Comprehensive is a five-day, hands-on overview of Entrust Course participants will gain experience planning, installing and configuring Entrust

More information

CLARIN: Common Language Resources and Technology Infrastructure

CLARIN: Common Language Resources and Technology Infrastructure CLARIN: Common Language Resources and Technology Infrastructure Tamás Váradi, Peter Wittenburg, Steven Krauwer, Martin Wynne, Kimmo Koskenniemi Hungarian Academy of Sciences (Budapest), MPI for Psycholinguistics

More information

Federated Identity Management. Willem Elbers (MPI-TLA) EUDAT training

Federated Identity Management. Willem Elbers (MPI-TLA) EUDAT training Federated Identity Management Willem Elbers (MPI-TLA) EUDAT training Date: 26 June 2012 Outline FIM and introduction to components Federation and metadata National Identity federations and inter federations

More information

Cloud Computing for Architects

Cloud Computing for Architects Cloud Computing for Architects This four day, hands-on boot camp begins with an examination of the Cloud Computing concept, the structure and key characteristics of Clouds, and takes a look under the hood

More information

Federated Identity Management for the EUDAT Data e-infrastructure

Federated Identity Management for the EUDAT Data e-infrastructure Federated Identity Management for the EUDAT Data e-infrastructure Principled promoting of persistent personal principals: particular practical perspectives Jens Jensen, STFC EUDAT AAI TF DPConline workshop

More information

Virtual Datacenter or Virtualization in the datacenter. (OpenStack) Larry Rudolph

Virtual Datacenter or Virtualization in the datacenter. (OpenStack) Larry Rudolph Virtual Datacenter or Virtualization in the datacenter (OpenStack)! Larry Rudolph A merge of several public presentations Rackspace & NASA started it off, and OpenStack has grown dramatically All possible

More information

GridPP36 Security Report

GridPP36 Security Report GridPP36 Security Report Ian Neilson GridPP Security Officer 12/04/2016 Gridpp36, Pitlochry Slide Security Report Operational Security Policy Updates Collaborations & Projects Future Work ARGUS Ban Tests

More information

CERN, Information Technology Department alberto.pace@cern.ch

CERN, Information Technology Department alberto.pace@cern.ch Identity Management Alberto Pace CERN, Information Technology Department alberto.pace@cern.ch Computer Security The present of computer security Bugs, Vulnerabilities, Known exploits, Patches Desktop Management

More information

Agenda. Federation using ADFS and Extensibility options. Office 365 Identity overview. Federation and Synchronization

Agenda. Federation using ADFS and Extensibility options. Office 365 Identity overview. Federation and Synchronization Agenda Office 365 Identity overview 1 Federation and Synchronization Federation using ADFS and Extensibility options 2 3 What s New in Azure AD? Cloud Business App - Overview 4 Identity Management is

More information

INDIGO-DataCloud Wupi 4 (Resource Virtualization)

INDIGO-DataCloud Wupi 4 (Resource Virtualization) INDIGO-DataCloud Wupi 4 (Resource Virtualization) All stolen from Markus, Enol, Maciej, Giacionto and many others High level objective This work package is focusing on virtualizing local computing, storage

More information

The challenge of managing research data. Axel Berg

The challenge of managing research data. Axel Berg The challenge of managing research data Axel Berg Context The data deluge cannot be stopped Without adequate data management: - the ever-growing amounts and complexity of data will be non-controllable

More information

System Administrators, engineers and consultants who will plan and manage OpenStack-based environments.

System Administrators, engineers and consultants who will plan and manage OpenStack-based environments. OpenStack Foundations (HP-H6C68) Course Overview This three day course assists administrators and users to configure, manage, and use the OpenStack cloud services platform. An architectural overview ensures

More information

ABFAB and OpenStack(in the Cloud)

ABFAB and OpenStack(in the Cloud) ABFAB and OpenStack(in the Cloud) David W Chadwick University of Kent 1 Authentication in OpenStack Keystone User Trust Relationship Swift/Glance etc. 2 Federated Authnwith External IdPs External IdP User

More information

Identity and Access Management PI-1 Demo. December 2, 2014 Tuesday 10:00 A.M. 6 Story Street

Identity and Access Management PI-1 Demo. December 2, 2014 Tuesday 10:00 A.M. 6 Story Street Identity and Access Management PI-1 Demo December 2, 2014 Tuesday 10:00 A.M. 6 Story Street Agenda Meeting Purpose and Intended Outcomes (5 min) PI-1 Business Objectives (5 min) Demo: User Data From the

More information

AAI for Mobile Apps How mobile Apps can use SAML Authentication and Attributes. Lukas Hämmerle lukas.haemmerle@switch.ch

AAI for Mobile Apps How mobile Apps can use SAML Authentication and Attributes. Lukas Hämmerle lukas.haemmerle@switch.ch AAI for Mobile Apps How mobile Apps can use SAML Authentication and Attributes Lukas Hämmerle lukas.haemmerle@switch.ch Berne, 13. August 2014 Introduction App by University of St. Gallen Universities

More information

EUDAT Infrastructure and Service Support

EUDAT Infrastructure and Service Support EUDAT Infrastructure and Service Support Achievements and Current Practice Johannes Reetz 2 nd EUDAT User Forum London, 11-12 March 2013 Topics Status of the Infrastructure (month 16) Operations and Operational

More information

SharePoint 2013 Business Connectivity Services Hybrid Overview

SharePoint 2013 Business Connectivity Services Hybrid Overview SharePoint 2013 Business Connectivity Services Hybrid Overview Christopher J Fox Microsoft Corporation November 2012 Applies to: SharePoint 2013, SharePoint Online Summary: A hybrid SharePoint environment

More information

Globus Auth. Steve Tuecke. The University of Chicago

Globus Auth. Steve Tuecke. The University of Chicago Globus Auth Enabling an extensible, integrated ecosystem of services and applications for the research and education community. Steve Tuecke The University of Chicago Cloud has transformed how platforms

More information

TIB 2.0 Administration Functions Overview

TIB 2.0 Administration Functions Overview TIB 2.0 Administration Functions Overview Table of Contents 1. INTRODUCTION 4 1.1. Purpose/Background 4 1.2. Definitions, Acronyms and Abbreviations 4 2. OVERVIEW 5 2.1. Overall Process Map 5 3. ADMINISTRATOR

More information

Big Data in BioMedical Sciences. Steven Newhouse, Head of Technical Services, EMBL-EBI

Big Data in BioMedical Sciences. Steven Newhouse, Head of Technical Services, EMBL-EBI Big Data in BioMedical Sciences Steven Newhouse, Head of Technical Services, EMBL-EBI Big Data for BioMedical Sciences EMBL-EBI: What we do and why? Challenges & Opportunities Infrastructure Requirements

More information

TrustedX: eidas Platform

TrustedX: eidas Platform TrustedX: eidas Platform Identification, authentication and electronic signature platform for Web environments. Guarantees identity via adaptive authentication and the recognition of either corporate,

More information

Cloud Computing using

Cloud Computing using Cloud Computing using Summary of Content Introduction of Cloud Computing Cloud Computing vs. Server Virtualization Cloud Computing Components Stack Public vs. Private Clouds Open Source Software for Private

More information

1 What is Cloud Computing?... 2 2 Cloud Infrastructures... 2 2.1 OpenStack... 2 2.2 Amazon EC2... 4 3 CAMF... 5 3.1 Cloud Application Management

1 What is Cloud Computing?... 2 2 Cloud Infrastructures... 2 2.1 OpenStack... 2 2.2 Amazon EC2... 4 3 CAMF... 5 3.1 Cloud Application Management 1 What is Cloud Computing?... 2 2 Cloud Infrastructures... 2 2.1 OpenStack... 2 2.2 Amazon EC2... 4 3 CAMF... 5 3.1 Cloud Application Management Frameworks... 5 3.2 CAMF Framework for Eclipse... 5 3.2.1

More information

EFFECTS+ Clustering of Trust and Security Research Projects, Identifying Results, Impact and Future Research Roadmap Topics

EFFECTS+ Clustering of Trust and Security Research Projects, Identifying Results, Impact and Future Research Roadmap Topics EFFECTS+ Clustering of Trust and Security Research Projects, Identifying Results, Impact and Future Research Roadmap Topics Frances CLEARY 1, Keith HOWKER 2, Fabio MASSACCI 3, Nick WAINWRIGHT 4, Nick PAPANIKOLAOU

More information

The Challenges of Web single sign-on

The Challenges of Web single sign-on Serge Vereecke Security Architect IBM Security Services serge_vereecke@be.ibm.com The Challenges of Web single sign-on GSE Event September 7, 2012 Agenda Single sign-on technology Why single sign-on Challenges

More information

EUDAT. Towards a pan-european Collaborative Data Infrastructure

EUDAT. Towards a pan-european Collaborative Data Infrastructure EUDAT Towards a pan-european Collaborative Data Infrastructure Damien Lecarpentier CSC-IT Center for Science, Finland EISCAT User Meeting, Uppsala,6 May 2013 2 Exponential growth Data trends Zettabytes

More information

Single Sign-On: Reviewing the Field

Single Sign-On: Reviewing the Field Outline Michael Grundmann Erhard Pointl Johannes Kepler University Linz January 16, 2009 Outline 1 Why Single Sign-On? 2 3 Criteria Categorization 4 Overview shibboleth 5 Outline Why Single Sign-On? Why

More information

OpenStack Introduction. November 4, 2015

OpenStack Introduction. November 4, 2015 OpenStack Introduction November 4, 2015 Application Platforms Undergoing A Major Shift What is OpenStack Open Source Cloud Software Launched by NASA and Rackspace in 2010 Massively scalable Managed by

More information

APIs The Next Hacker Target Or a Business and Security Opportunity?

APIs The Next Hacker Target Or a Business and Security Opportunity? APIs The Next Hacker Target Or a Business and Security Opportunity? SESSION ID: SEC-T07 Tim Mather VP, CISO Cadence Design Systems @mather_tim Why Should You Care About APIs? Amazon Web Services EC2 alone

More information

Federated single sign-on (SSO) and identity management. Secure mobile access. Social identity integration. Automated user provisioning.

Federated single sign-on (SSO) and identity management. Secure mobile access. Social identity integration. Automated user provisioning. PingFederate We went with PingFederate because it s based on standards like SAML, which are important for a secure implementation. John Davidson Senior Product Manager, Opower PingFederate is the leading

More information

Horizon 2020. Research e-infrastructures Excellence in Science Work Programme 2016-17. Wim Jansen. DG CONNECT European Commission

Horizon 2020. Research e-infrastructures Excellence in Science Work Programme 2016-17. Wim Jansen. DG CONNECT European Commission Horizon 2020 Research e-infrastructures Excellence in Science Work Programme 2016-17 Wim Jansen DG CONNECT European Commission 1 Before we start The material here presented has been compiled with great

More information

Big Data Standardisation in Industry and Research

Big Data Standardisation in Industry and Research Big Data Standardisation in Industry and Research EuroCloud Symposium ICS Track: Standards for Big Data in the Cloud 15 October 2013, Luxembourg Yuri Demchenko System and Network Engineering Group, University

More information

Enterprise Access Control Patterns For REST and Web APIs

Enterprise Access Control Patterns For REST and Web APIs Enterprise Access Control Patterns For REST and Web APIs Francois Lascelles Layer 7 Technologies Session ID: STAR-402 Session Classification: intermediate Today s enterprise API drivers IAAS/PAAS distributed

More information

SINGLE & SAME SIGN-ON ASPECTS

SINGLE & SAME SIGN-ON ASPECTS SINGLE & SAME SIGN-ON ASPECTS OF AZURE ACTIVE DIRECTORY Harold Baele Senior ICT Trainer JULY 2, 2015 SLIDE 1 TRAINER INFO Harold Baele MCT at RealDolmen Education Harold.baele@realdolmen.com - @hbaele

More information

An Introduction to OpenStack and its use of KVM. Daniel P. Berrangé <berrange@redhat.com>

An Introduction to OpenStack and its use of KVM. Daniel P. Berrangé <berrange@redhat.com> An Introduction to OpenStack and its use of KVM Daniel P. Berrangé About me Contributor to multiple virt projects Libvirt Developer / Architect 8 years OpenStack contributor 1 year

More information

Single Sign On. SSO & ID Management for Web and Mobile Applications

Single Sign On. SSO & ID Management for Web and Mobile Applications Single Sign On and ID Management Single Sign On SSO & ID Management for Web and Mobile Applications Presenter: Manish Harsh Program Manager for Developer Marketing Platforms of NVIDIA (Visual Computing

More information

Update on Internet Identity and Scalable Access Control. Ken Klingenstein, kjk@internet2.edu

Update on Internet Identity and Scalable Access Control. Ken Klingenstein, kjk@internet2.edu Update on Internet Identity and Scalable Access Control Ken Klingenstein, kjk@internet2.edu Topics Identity Federal update InCommon and edugain Social2SAML gateways and IdPoLR Federated incident handling

More information

GÉANT IaaS suppliers meeting Towards Pan-European Cloud Services. Utrecht October 14 2015

GÉANT IaaS suppliers meeting Towards Pan-European Cloud Services. Utrecht October 14 2015 GÉANT IaaS suppliers meeting Towards Pan-European Cloud Services Utrecht October 14 2015 Why and what TODAY More information about IaaS delivery through GÉANT Tender Provider GÉANT interaction Opportunity

More information

The Knowledge Sharing Infrastructure KSI. Steven Krauwer

The Knowledge Sharing Infrastructure KSI. Steven Krauwer The Knowledge Sharing Infrastructure KSI Steven Krauwer 1 Why a KSI? Building or using a complex installation requires specialized skills and expertise. CLARIN is no exception. CLARIN is populated with

More information

In 2014, the Research Data group @ Purdue University

In 2014, the Research Data group @ Purdue University EDITOR S SUMMARY At the 2015 ASIS&T Research Data Access and Preservation (RDAP) Summit, panelists from Research Data @ Purdue University Libraries discussed the organizational structure intended to promote

More information

SECURITY AND REGULATORY COMPLIANCE OVERVIEW

SECURITY AND REGULATORY COMPLIANCE OVERVIEW Powering Cloud IT SECURITY AND REGULATORY COMPLIANCE OVERVIEW BetterCloud for Office 365 Executive Summary BetterCloud provides critical insights, automated management, and intelligent data security for

More information

IMPORTANT PROJECT OF COMMON EUROPEAN INTEREST (IPCEI)

IMPORTANT PROJECT OF COMMON EUROPEAN INTEREST (IPCEI) IMPORTANT PROJECT OF COMMON EUROPEAN INTEREST (IPCEI) ON HIGH PERFORMANCE COMPUTING AND BIG DATA ENABLED APPLICATIONS (IPCEI-HPC-BDA) European Strategic Positioning Paper Luxembourg, France, Italy (& Spain)

More information

Checklist for a Data Management Plan draft

Checklist for a Data Management Plan draft Checklist for a Data Management Plan draft The Consortium Partners involved in data creation and analysis are kindly asked to fill out the form in order to provide information for each datasets that will

More information

The EGI Federated Cloud e-infrastructure

The EGI Federated Cloud e-infrastructure The EGI Federated Cloud e-infrastructure Enol Fernández 1,2, Diego Scardaci 1,3, Álvaro López 2 1 EGI.eu, 2 IFCA (CSIC-UC), 3 INFN-Catania www.egi.eu EGI-Engage is co-funded by the Horizon 2020 Framework

More information

HOL9449 Access Management: Secure web, mobile and cloud access

HOL9449 Access Management: Secure web, mobile and cloud access HOL9449 Access Management: Secure web, mobile and cloud access Kanishk Mahajan Principal Product Manager, Oracle September, 2014 Copyright 2014, Oracle and/or its affiliates. All rights reserved. Oracle

More information

cloud functionality: advantages and Disadvantages

cloud functionality: advantages and Disadvantages Whitepaper RED HAT JOINS THE OPENSTACK COMMUNITY IN DEVELOPING AN OPEN SOURCE, PRIVATE CLOUD PLATFORM Introduction: CLOUD COMPUTING AND The Private Cloud cloud functionality: advantages and Disadvantages

More information

Federated Identity Management for Research Collaborations

Federated Identity Management for Research Collaborations Federated Identity Management for Research Collaborations Paper Type: Research paper Date of this version: 23 rd April 2012 Abstract Federated identity management (FIM) is an arrangement that can be made

More information

Shared Services Canada (SSC)

Shared Services Canada (SSC) Shared Services Canada (SSC) Cloud Computing Architecture Identity, Credential & Access Architecture Framework Advisory Committee Transformation, Service Strategy and Design August 29, 2013 1 Agenda TIME

More information

IEEE Standards Association (IEEE-SA)

IEEE Standards Association (IEEE-SA) IEEE Standards Association (IEEE-SA) NetFutures Conference Brussels, Belgium April 2016 Dr. Konstantinos Karachalios Managing Director IEEE Standards Association About us Global Markets, Global Standards

More information

OpenStack Awareness Session

OpenStack Awareness Session OpenStack Awareness Session Affan A. Syed Director Engineering, PLUMgrid Inc. Pakistan Telecommunication Authority, Oct 20 th, 2015 PLUMgrid s Mission Deliver comprehensive virtual networking solutions

More information

EXTENDING SINGLE SIGN-ON TO AMAZON WEB SERVICES

EXTENDING SINGLE SIGN-ON TO AMAZON WEB SERVICES pingidentity.com EXTENDING SINGLE SIGN-ON TO AMAZON WEB SERVICES Best practices for identity federation in AWS Table of Contents Executive Overview 3 Introduction: Identity and Access Management in Amazon

More information

OPENIAM ACCESS MANAGER. Web Access Management made Easy

OPENIAM ACCESS MANAGER. Web Access Management made Easy OPENIAM ACCESS MANAGER Web Access Management made Easy TABLE OF CONTENTS Introduction... 3 OpenIAM Access Manager Overview... 4 Access Gateway... 4 Authentication... 5 Authorization... 5 Role Based Access

More information

The UK Access Management Federation

The UK Access Management Federation Connecting People to Resources The UK Access Management Federation Nicole Harris Programme Manager Joint Information Systems Committee 19/10/2006 Slide 1 Federations within the UK: Unique Issues The need

More information

EGI Federated Cloud, a building block for the Open Science Commons

EGI Federated Cloud, a building block for the Open Science Commons EGI Federated Cloud, a building block for the Open Science Commons Yannick LEGRÉ Director, EGI.eu www.egi.eu EGI-Engage is co-funded by the Horizon 2020 Framework Programme of the European Union under

More information

Summary Report Report # 1. Security Challenges of Cross-Border Use of Cloud Services under Special Consideration of ENISA s Contributions

Summary Report Report # 1. Security Challenges of Cross-Border Use of Cloud Services under Special Consideration of ENISA s Contributions Summary Report Report # 1 Security Challenges of Cross-Border Use of Cloud Services under Special Consideration of ENISA s Contributions COINS Summer School 2015 on Could Security Prepared by: Nabeel Ali

More information

Identity Implementation Guide

Identity Implementation Guide Identity Implementation Guide Version 37.0, Summer 16 @salesforcedocs Last updated: May 26, 2016 Copyright 2000 2016 salesforce.com, inc. All rights reserved. Salesforce is a registered trademark of salesforce.com,

More information

Interaction with other IT projects: EUDAT2020, VLDATA, ENVRI PLUS,

Interaction with other IT projects: EUDAT2020, VLDATA, ENVRI PLUS, Interaction with other IT projects: EUDAT2020, VLDATA, ENVRI PLUS, A. Spinuso, L. Trani, A. Strollo and D. Bailo EPOS PP final meeting, Rome, 22-24 October 2014 OUTLINE WG1 and the EIDA use case A modular

More information

Cloud and Big Data Standardisation

Cloud and Big Data Standardisation Cloud and Big Data Standardisation EuroCloud Symposium ICS Track: Standards for Big Data in the Cloud 15 October 2013, Luxembourg Yuri Demchenko System and Network Engineering Group, University of Amsterdam

More information

QliqDIRECT Active Directory Guide

QliqDIRECT Active Directory Guide QliqDIRECT Active Directory Guide QliqDIRECT is a Windows Service with Active Directory Interface. QliqDIRECT resides in your network/server and communicates with Qliq cloud servers securely. QliqDIRECT

More information

e-infrastructures: a digital game changer

e-infrastructures: a digital game changer e-infrastructures: a digital game changer Pisa, 14 July 2015 Carlos Morais Pires European Commission e-infrastructures, DG CNECT.C1 Author s views do not commit the European Commission summary 1/ Policy

More information

VMware Identity Manager Administration

VMware Identity Manager Administration VMware Identity Manager Administration VMware Identity Manager 2.6 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new

More information

Workspaces Concept and functional aspects

Workspaces Concept and functional aspects Mitglied der Helmholtz-Gemeinschaft Workspaces Concept and functional aspects A You-tube for science inspired by the High Level Expert Group Report on Scientific Data 21.09.2010 Morris Riedel, Peter Wittenburg,

More information

GN3plus JRA3 T1 Attribute and Group management in the AAI environment

GN3plus JRA3 T1 Attribute and Group management in the AAI environment GN3plus JRA3 T1 Attribute and Group management in the AAI environment Maarten Kremers, SURFnet Internet2 Technology Exchange 2014, Indianapolis, IN October 29 th 2014 GÉANT (GN3plus) - vital to the EU

More information

Copyright Pivotal Software Inc, 2013-2015 1 of 10

Copyright Pivotal Software Inc, 2013-2015 1 of 10 Table of Contents Table of Contents Getting Started with Pivotal Single Sign-On Adding Users to a Single Sign-On Service Plan Administering Pivotal Single Sign-On Choosing an Application Type 1 2 5 7 10

More information

Secure Your Enterprise with Usher Mobile Identity

Secure Your Enterprise with Usher Mobile Identity Secure Your Enterprise with Usher Mobile Identity Yong Qiao, Vice President of Software Engineering & Chief Security Architect, MicroStrategy Agenda Introduction to Usher Unlock the enterprise Dematerialize

More information

Agenda. How to configure

Agenda. How to configure dlaw@esri.com Agenda Strongly Recommend: Knowledge of ArcGIS Server and Portal for ArcGIS Security in the context of ArcGIS Server/Portal for ArcGIS Access Authentication Authorization: securing web services

More information

How To Compare Cloud Computing To Cloud Platforms And Cloud Computing

How To Compare Cloud Computing To Cloud Platforms And Cloud Computing Volume 3, Issue 11, November 2013 ISSN: 2277 128X International Journal of Advanced Research in Computer Science and Software Engineering Research Paper Available online at: www.ijarcsse.com Cloud Platforms

More information

Online Identity Attribute Exchange 2013-2014 Initiatives

Online Identity Attribute Exchange 2013-2014 Initiatives Online Identity Attribute Exchange 2013-2014 Initiatives Agenda Overview AXN Services Framework Demonstration NSTIC Pilots Summary ABAC Services Attribute Exchange Network Page 2 AXN - Enabling IT & Other

More information

USING FEDERATED AUTHENTICATION WITH M-FILES

USING FEDERATED AUTHENTICATION WITH M-FILES M-FILES CORPORATION USING FEDERATED AUTHENTICATION WITH M-FILES VERSION 1.0 Abstract This article provides an overview of federated identity management and an introduction on using federated authentication

More information

Federation Proxy for Cross Domain Identity Federation

Federation Proxy for Cross Domain Identity Federation Proxy for Cross Domain Identity Makoto Hatakeyama NEC Corporation, Common Platform Software Res. Lab. 1753, Shimonumabe, Nakahara-Ku, Kawasaki, Kanagawa 211-8666, Japan +81-44-431-7663 m-hatake@ax.jp.nec.com

More information

Care Navigation Council. Nenick Vu Care Navigation Council Director

Care Navigation Council. Nenick Vu Care Navigation Council Director Care Navigation Council Nenick Vu Care Navigation Council Director Care Navigation Council The Challenge With the passage of the Affordable Care Act, Medi-Cal coverage for all legally present low income

More information

ODIN ORCID and DATACITE Interoperability Network Title

ODIN ORCID and DATACITE Interoperability Network Title ODIN ORCID and DATACITE Interoperability Network Title This project has received funding from the European Union's Seventh Framework Programme for research, technological development and demonstration

More information

European Data Infrastructure - EUDAT Data Services & Tools

European Data Infrastructure - EUDAT Data Services & Tools European Data Infrastructure - EUDAT Data Services & Tools Dr. Ing. Morris Riedel Research Group Leader, Juelich Supercomputing Centre Adjunct Associated Professor, University of iceland BDEC2015, 2015-01-28

More information

A Conceptual Model of Practitioner Authentication Prior to Providing Telemedicine Services in Developing Countries

A Conceptual Model of Practitioner Authentication Prior to Providing Telemedicine Services in Developing Countries A Conceptual Model of Practitioner Authentication Prior to Providing Telemedicine Services in Developing Countries Leonie Spoerer, Yashik Singh and Maurice Mars Dept of TeleHealth, University of KwaZulu-Natal

More information