GN3plus JRA3 T1 Attribute and Group management in the AAI environment
|
|
|
- Elmer Black
- 10 years ago
- Views:
Transcription
1 GN3plus JRA3 T1 Attribute and Group management in the AAI environment Maarten Kremers, SURFnet Internet2 Technology Exchange 2014, Indianapolis, IN October 29 th 2014
2 GÉANT (GN3plus) - vital to the EU s e-infrastructure strategy Key Facts GN3plus Start date April Duration 24 months Total budget 84,283,018 EC contribution 41,800,000 Participants Project Partners: 38 NRENs, DANTE, TERENA, NORDUnet (representing 5 Nordic countries)! GN3plus: extension and expansion to 3rd term of the successful GÉANT networking project, vital to the EU s e-infrastructure strategy.! GÉANT vision: to become the unified European Communications Commons - driving knowledge creation as the global hub for research networking excellence! GÉANT Mission: to deliver world-class services with the highest levels of operational excellence! Co-funded: by the EU and Europe s NRENs 2
3 GN3plus - Innovation through collaboration for delivery of advanced networking services! Building the GÉANT eco-system through development and delivery of a world-class networking service portfolio:! Flexible connectivity options & test-bed facilities! Performance tools & expertise! Advanced AAI, cloud and mobility services! Collaborative research into state-of-the-art technology! network architectures - mobility, cloud, sensor, scientifc content delivery, high-speed mobile! identity and trust technologies! paradigm shifts in service provisioning and management! influencing global standards development! Open Calls to widen the scope and agility for innovation Delivering innovative services to end users, their projects and institutions across Europe and beyond: secure access to the network and resources they need, when and where they want it. 3
4 Europe s 100Gbps Network - e-infrastructure for the data deluge! Latest transmission and switching technology! Routers with 100Gbps capability! Optical transmission platform designed to provide 500Gbps super-channels! 12,000km of dark fibre! Over 100,000km of leased capacity (including transatlantic connections)! 28 main sites covering European footprint 4
5 GÉANT Global Connectivity - at the heart of global research networking GÉANT connects 65 countries outside of Europe, reaching all continents through international partners 5
6 Delivering world-class services to R&E communities JRA1: Network Architectures for Horizon 2020 JRA2: Technology Testing for Specific Service Applications JRA3: Identity & Trust Technologies for GÉANT Services SA1: Core Backbone Services SA2: Testbeds as a Service SA3: Network Service Delivery SA4: Network Support Services SA5: Application Services SA7: Support to Clouds SA6: Service Management & Operations NA1: Management NA2: Communications & Promotion NA3: Status & Trends NA4: International & Business Devpt 6
7 Collaboration 7
8 What s already there? Is getting more and more members! Opt-in by default gaining momentum Code of Conduct / Entity Category 8
9 Federation in Country A Federation A Federation D Federation B Service Providers Federation C Identity Providers 9
10 Federation A Federation D A A A Federation B Federation C 10
11 ? Federation A s for collaboration A A Federation D? A A Federation C Federation B? Groups 11
12 Federation A VO1 s Federation D Federation B VO2 s Federation C 12
13 What more to expect?! Bring your own Identity Social Identity, Trust frameworks Institution as AA Lifelong Learning, Author Identification Persistent ID, Researcher ID AuthZ in a federated and heterogeneous environment Loosening relation between ID and Attributes à Group Providers and AA s Separating AuthN & AuthZ User in Control 13
14 About JRA3-T1 GN3plus Project Joint Research Activity 3 à Identity and Trust Technologies Task 1 à Attributes and Groups in the cross institution environment SURFnet, CARNet, DFN, BADW-LRZ, GARR, NORDUnet, PSNC 14
15 Topics Group Management across organisations (using Grouper) Group Protocol (VOOT) AA: What s out there Studentness / Simple Validation Service 15
16 Group Management across organisations Use of centralised group management at the federation level for authorisation purposes Authorisation information a delegated to a specific system Leveraging Attributes Authorities using tools like Grouper 16
17 Group Management across organisations Proof of Concept using Grouper and 3 s Grouper as SAML AA implementation guide & Feasiblity report on the set-up available +organisational+context 17
18 Virtual Organisation Orthogonal Technology (VOOT) VOOT Use Cases VOOT specification v1 Finalised draft, gathering review comments VOOT Standardisation Engaging with IETF (SCIM WG) VOOT very close to SCIM (re)work to close the gap 18
19 VOOT Protocol (High-level) Information about me {BASE}/me! The groups that I am member of {BASE}/me/Groups! List of members of a group {BASE}/Groups/{GROUPID}/members! The role for a given combination of user and group. {BASE}/Roles/{GROUPID}/{USERID}! Querying for public groups {BASE}/Groups?search={SEARCH-TERM}! 19
20 AA: What is out there There are many kind of tools to support Collaboration Each having its own distinct strengths 20
21 AA: What is out there Heterogeneous environments Both Organisational and Technical Draft White paper together with HEXAA and PERUN on the problem space in the heterogeneous environment Fields for cooperation and standardization Creating an overview (end Q4 2014) 21
22 Simple Validation Service (inacademia.org) Validate Studentness Added value for services who collects there own attributes Usecases in the (non) educational world: discounts SimpleValidationService+Home 22
23 Simple Validation Service (inacademia.org) 23
24 More information: (Federated login possible! )
25 Thank you! Maarten Kremers
Toward the Clouds, Together!
Toward the Clouds, Together! Collaboration effort of European NRENs in Cloud Computing Branko Radojević, Deputy Director, CARNet/GEANT E-Infrastructure Autumn Workshops Chișinău Where do I come from? NRENs.000
SA7 IaaS procurement
SA7 IaaS procurement TF-CPR, 17 March 2015, Amsterdam Michel Wets [email protected] 1 Collaborate, to enable and facilitate our community STRATEGY STANDARDS to use online services on a large scale,
GN3+ SA3T3 / Multi-Domain-VPN service: Collaboration of NREN s NOC
GN3+ SA3T3 / Multi-Domain-VPN service: Collaboration of NREN s NOC 10 th TF NOC meeting (Cambridge) Friday, 21 March 2014 Xavier Jeannin / RENATER, SA3T3 Task Leader Miguel Angel Sotos / RedIRIS Bojan
VOPaaS Virtual Organisation Platform as a Service
VOPaaS Virtual Organisation Platform as a Service Marina Adomeit Task Leader, AMRES, Serbia Niels Van Dijk Technical Lead, SURFnet, The Netherlands FIM4R meeting Nov 30, 2015, Austria About VOPaaS in GÉANT
Strategic approach to cloud computing deployment
Strategic approach to cloud computing deployment Slavko Gajin, (GN3plus, SA7T1) Datacenter IaaS workshop 2014 11-12. September, 2014 Cloud and NRENs Cloud is the latest big thing affecting NREN users Do
Agenda. NRENs, GARR and GEANT in a nutshell SDN Activities Conclusion. Mauro Campanella Internet Festival, Pisa 9 Oct 2015 2
Agenda NRENs, GARR and GEANT in a nutshell SDN Activities Conclusion 2 3 The Campus-NREN-GÉANT ecosystem CAMPUS networks NRENs GÉANT backbone. GÉANT Optical + switching platforms Multi-Domain environment
GÉANT IaaS suppliers meeting Towards Pan-European Cloud Services. Utrecht October 14 2015
GÉANT IaaS suppliers meeting Towards Pan-European Cloud Services Utrecht October 14 2015 Why and what TODAY More information about IaaS delivery through GÉANT Tender Provider GÉANT interaction Opportunity
Licia Florio Project Development Officer [email protected] www.terena.org Identity Federations in Europe
APAN Conference Honolulu, Hawaii 24 January 2008 Licia Florio Project Development Officer [email protected] www.terena.org Identity Federations in Europe Outline Networking Organisations in Europe Requirements
Introduction to perfsonar
Introduction to perfsonar Loukik Kudarimoti, DANTE 27 th September, 2006 SEEREN2 Summer School, Heraklion Overview of this talk Answers to some basic questions The need for Multi-domain monitoring What
The GÉANT Network & GN3
The GÉANT Network & GN3 Tom Fryer, DANTE CLARA-TEC San José, Costa Rica Tuesday, 11 th August 2009 What is GÉANT? The pan-european research and education backbone network A high-capacity internet reserved
The FEDERICA Project: creating cloud infrastructures
The FEDERICA Project: creating cloud infrastructures Mauro Campanella Consortium GARR, Via dei Tizii 6, 00185 Roma, Italy [email protected] Abstract. FEDERICA is a European project started in January
GN3+ JRA1 Network Architectures for Horizon 2020
GN3 JRA1 Future Network Task 1 and 2 GN3+ JRA1 Network Architectures for Horizon 2020 Tony Breach, NORDUnet A/S Copenhagen 20 November 2012 Background and Objective Joint Research Activity 1 Future Network
GÉANT Open Service Description. High Performance Interconnectivity to Support Advanced Research
GÉANT Open Service Description High Performance Interconnectivity to Support Advanced Research Issue Date: 20 July 2015 GÉANT Open Exchange Overview Facilitating collaboration has always been the cornerstone
Security in Federated e-infrastructure
Security in Federated e-infrastructure and Identity Management Boris Parák 2 Slávek Licehammer 1,2 1 Masaryk University 2 CESNET May 18, 2015 www.egi.eu EGI-Engage is co-funded by the Horizon 2020 Framework
9360/15 FMA/AFG/cb 1 DG G 3 C
Council of the European Union Brussels, 29 May 2015 (OR. en) 9360/15 OUTCOME OF PROCEEDINGS From: To: Council Delegations RECH 183 TELECOM 134 COMPET 288 IND 92 No. prev. doc.: 8970/15 RECH 141 TELECOM
QoS Unterstützung in der neuen Generation von Weitverkehrsnetzen und erste Erfahrungen im europaweiten Einsatz
QoS Unterstützung in der neuen Generation von Weitverkehrsnetzen und erste Erfahrungen im europaweiten Einsatz QUASAR Quality-of-Service Architectures 16. DFN-Arbeitstagung über Kommunikationsnetze Düsseldorf
Connected College Gives Online Learning a Boost in Hertford. Europe s fastest education network takes revenue and collaboration into the cloud
Connected College Gives Online Learning a Boost in Hertford Europe s fastest education network takes revenue and collaboration into the cloud Connected College Gives Online Learning a Boost in Hertford
Federation of trouble ticketing systems
Federation of trouble ticketing systems Pavle Vuletić, AMRES, Jovana Vuleta-Radoičić, University of Belgrade, Dimitrios Kalogeras, GRNET/ NTUA 8th TF-NOC meeting 28 May 2013 Motivation! This work is one
Collaboration in the Cloud. Niels van Dijk, SURFnet, [email protected] CAMP, Nov 15 2013, San Francisco
Collaboration in the Cloud Niels van Dijk, SURFnet, [email protected] CAMP, Nov 15 2013, San Francisco R&E SURF in and The SURFnet Netherlands: SURF and SURFnet National Research & Education Network
The Case for NRENs John DYER
The Case for NRENs John DYER TF- MSP Meeting, Espoo, Finland 9/10 September 2015 Networks Services People www.geant.org The Case for NRENs Published January 2009 This presentation is dedicated to continuing
Trial of the Infinera PXM. Guy Roberts, Mian Usman
Trial of the Infinera PXM Guy Roberts, Mian Usman LHC Workshop Recap Rather than maintaining distinct networks, the LHC community should aim to unify its network infrastructure Traffic aggregation on few
8970/15 FMA/AFG/cb 1 DG G 3 C
Council of the European Union Brussels, 19 May 2015 (OR. en) 8970/15 NOTE RECH 141 TELECOM 119 COMPET 228 IND 80 From: Permanent Representatives Committee (Part 1) To: Council No. prev. doc.: 8583/15 RECH
GLIF End to end architecture Green paper
GLIF End to end architecture Green paper Bill, Inder, Erik-Jan GLIF Tech Honolulu, HI, USA 17 Jan 2013 Green Paper EC uses the concept of a green paper: A green paper released by the European Commission
Open Cloud exchange (OCX)
Open Cloud exchange (OCX) Draft Proposal and Progress GN3plus JRA1 Task 2 - Network Architectures for Cloud Services Yuri Demchenko SNE Group, University of Amsterdam 10 October 2013, GN3plus Symposium,
GÉANT2. Otto Kreiter Network Engineering & Planning, DANTE
2 Otto Kreiter Network Engineering & Planning, DANTE Today Connecting 33 European countries and 29 NRENs Backbone capacities from 10Gb/s to 34Mb/s Backbone based on Juniper M-series routers Services Best
Service Quality Management for multidomain network services. Pavle Vuletić, AMRES edupert videoconference, 20 July 2015
Service Quality Management for multidomain network services Pavle Vuletić, AMRES edupert videoconference, 20 July 2015 What is Service Quality Management? Resource Performance Management (RPM) provides
Quantum Telecommunications Networks. Dr Tim Whitley MD, Research and Innovation, BT
Quantum Telecommunications Networks Dr Tim Whitley MD, Research and Innovation, BT BT has a long history of innovation including significant optical transmission firsts World Firsts 1846: Telecommunications
The NREN cloud strategy should be aligned with the European and national policies, but also with the strategies of the member institutions.
4 External influences PESTLE Analysis A PESTLE analysis is a useful tool to support the investigation and decision process relating to cloud services. PESTLE in general covers Political, Economic, Social,
Infinera waves on a Ciena light system
Infinera waves on a Ciena light system Guy Roberts, GEANT Association Terena Architects workshop, 12 Nov 2014 Fibre sharing Field Trial Background GÉANT Telia Sonera fibre will not be renewed. Looking
DREAMER and GN4-JRA2 on GTS
GTS Tech+Futures Workshop (Copenhagen) GTS Tech+Futures Workshop (Copenhagen) DREAMER and GN4-JRA2 on GTS CNIT Research Unit of Rome University of Rome Tor Vergata Outline DREAMER (Distributed REsilient
Network performance monitoring Insight into perfsonar
Network performance monitoring Insight into perfsonar Szymon Trocha, Poznań Supercomputing and Networking Center E-infrastructure Autumn Workshops, Chisinau, Moldova 9 September 2014 Agenda! Network performance
GÉANT for HEAnet clients
GÉANT for HEAnet clients Guy Roberts GÉANT CTO Office HEAnet National Conference 12 th November 2015 Global R+E connectivity for Ireland HEAnet + GÉANT provide access for Irish R+E users to the world s
DELIVERABLE. Grant Agreement number: 325091 Europeana Cloud: Unlocking Europe s Research via The Cloud
DELIVERABLE Project Acronym: Grant Agreement number: 325091 Project Title: Europeana Cloud Europeana Cloud: Unlocking Europe s Research via The Cloud D5.3 Europeana Cloud Access and Reuse Framework (originally:
MPLS multi-domain services MD-VPN service
MPLS multi-domain services MD-VPN service Xavier Jeannin, RENATER Tomasz Szewczyk / PSNC Training and Workshops for advancing NRENs 8-11 Sept 2014 Chisinau, Moldova MPLS brief overview Original purpose:
PCP and PPP trends and user stories in Europe
PCP and PPP trends and user stories in Europe Sara Garavelli, Trust-IT Services Shareholder & Project Manager & PICSE - Procurement Innovation for Cloud Services in Europe [email protected]
PIONIER the national fibre optic network for new generation services Artur Binczewski, Maciej Stroiński Poznań Supercomputing and Networking Center
PIONIER the national fibre optic network for new generation services Artur Binczewski, Maciej Stroiński Poznań Supercomputing and Networking Center e-irg Workshop October 12-13, 2011; Poznań, Poland 18th
EUK-02-2016: South Korea: IoT joint research
HORIZON 2020 WP 2016-17 EUK-02-2016: South Korea: IoT joint research DG CONNECT/DG AGRI/DG MOVE/DG RTD European Commission RIA EUK-02-2016: South Korea: IoT joint research Challenge: IoT has moved from
VoIP Network Status in Portuguese R&E
Best Practice Document Produced by the Portuguese CBP Working Group (DBPC 201) Authors: N. Gonçalves (FCCN), C. Friaças (FCCN) April 2015 GÉANT Association 2015. All rights reserved. Document No: GN3-DBPC-201
CLOUD POWER. NREN collaboration in GÉANT @ STF
CLOUD POWER NREN collaboration in GÉANT to enable and facilitate the Research and Education community to use online services on a large scale, with the right conditions @ STF MARCH 24 Andres Steijaert
Lightpath Planning and Monitoring
Lightpath Planning and Monitoring Ronald van der Pol 1, Andree Toonk 2 1 SARA, Kruislaan 415, Amsterdam, 1098 SJ, The Netherlands Tel: +31205928000, Fax: +31206683167, Email: [email protected] 2 SARA, Kruislaan
Section 1: Network monitoring based on flow measurement techniques
Section 1: Network monitoring based on flow measurement techniques This research is performed within the scope of the SURFnet Research on Networking (RON) project (Activity 1.2 - Measurement Scenarios).
Text Analytics and Big Data
Text Analytics and Big Data META-FORUM 2012 Brussels, 20 th June 2012 Atos Research & Innovation 1 Table of Contents 1. Atos and why we are here 2. Examples 3. BIG: Big Data Public Private Forum 2 2 Atos:
Carrier Class Transport Network Technologies: Summary of Initial Research
Carrier Class Transport Network Technologies: Summary of Initial Research This document is a summary of the JRA1 Task 1 Carrier Class Transport Network Technologies deliverable [DJ1.1.1], which presents
Hybrid Optical and Packet Infrastructure (HOPI) Project
Hybrid Optical and Packet Infrastructure (HOPI) Project Heather Boyles Director, International Relations, Internet2 Rick Summerhill Associate Director, Backbone Network Infrastructure, Internet2 TERENA
Sofware Engineering, Services and Cloud Computing
Work Programme 2013 Objective ICT-2013.1.2: Sofware Engineering, Services and Cloud Computing DG CONNECT Unit E2: Software and Service, Cloud Target Outcomes Delivering services in an effective, efficient
DANCERT RFC2350 Description Date: 10-10-2014 Dissemination Level:
10-10-2014 Date: 10-10-2014 Dissemination Level: Owner: Authors: Public DANCERT DANTE Document Revision History Version Date Description of change Person 1.0 10-10-14 First version issued Jan Kohlrausch
Intelligent Data Center Solutions
Intelligent Data Center Solutions Panduit s Unified Physical Infrastructure (UPI): a Guiding Vision A unified approach to physical and logical systems architecture is imperative for solutions to fully
How can the Future Internet enable Smart Energy?
How can the Future Internet enable Smart Energy? FINSENY overview presentation on achieved results Prepared by the FINSENY PMT April 2013 Outline Motivation and basic requirements FI-PPP approach FINSENY
Title: A Client Middleware for Token-Based Unified Single Sign On to edugain
Title: A Client Middleware for Token-Based Unified Single Sign On to edugain Sascha Neinert Computing Centre University of Stuttgart, Allmandring 30a, 70550 Stuttgart, Germany e-mail: [email protected]
1 Executive Summary... 3. 2 Document Structure... 5. 3 Business Context... 6
Contents 1 Executive Summary... 3 2 Document Structure... 5 3 Business Context... 6 4 Strategic Response... 8 4.1 Platform... 8 4.2 Network... 10 4.3 Unified Communications... 11 5 Implementation status...
Workprogramme 2014-15
Workprogramme 2014-15 e-infrastructures DCH-RP final conference 22 September 2014 Wim Jansen einfrastructure DG CONNECT European Commission DEVELOPMENT AND DEPLOYMENT OF E-INFRASTRUCTURES AND SERVICES
Next Generation Networks Convergence, evolution and roadmaps
Next Generation Networks Convergence, evolution and roadmaps Dr. Sathya Rao,Telscom Consulting, Berne [email protected] NGN Applications Requirement IP Everywhere The Internet Protocol is becoming pervasive
Indian NERN: ERNET. Presented by : Meharban Singh, ERNET India
Indian NERN: ERNET Presented by : Meharban Singh, ERNET India Presentation Outline ERNET India Introduction Networks established by ERNET India ERNET Network for Indian Grid GARUDA Network DAE - LHC grid
SICSA SDN Workshop Event Report
SICSA SDN Workshop Event Report Summary: 1. The workshop was held successfully on 19 September 2013 at the Informatics Forum within the School of Informatics, University of Edinburgh. 2. The event has
Board of Member States ERN implementation strategies
Board of Member States ERN implementation strategies January 2016 As a result of discussions at the Board of Member States (BoMS) meeting in Lisbon on 7 October 2015, the BoMS set up a Strategy Working
Zen Internet Case Study
Zen Internet Case Study About Zen Internet Zen Internet is an independent Internet Service Provider (ISP) that offers a full range of data, voice, and hosting services to businesses and residential users
perfsonar MDM updates for LHCONE: VRF monitoring, updated web UI, VM images
perfsonar MDM updates for LHCONE: VRF monitoring, updated web UI, VM images Domenico Vicinanza DANTE, Cambridge, UK perfsonar MDM Product Manager [email protected] LHCONE Meeting Oslo 20-21
Emerging Software Defined Networking & Open APIs Ecosystem
Emerging Software Defined Networking & Open APIs Ecosystem VISIT SNE STUDENTS, 18 MAART 2015 Ronald van der Pol [email protected] Content Emerging open hardware & open APIs in networking Software
ICT 6: Cloud computing
computing Jorge GASÓS Software and Services, Cloud Unit DG Connect [email protected] Cloud computing in previous WPs FP7 ICT Work Programmes (Calls 1, 5, 8, 10) Total investment in the software,
Three Case Studies in Access Management
Three Case Studies in Access Management IAM Online June 10, 2015-2 pm EDT Andy Morgan, Oregon State University Mandeep Saini, GÉANT Albert Wu, UCLA Moderator: Tom Barton, University of Chicago Fit for
THE RESEARCH INFRASTRUCTURES IN FP7
29 October 2004 Working Document on THE RESEARCH INFRASTRUCTURES IN FP7 Introduction In the Commission s communication on the financial perspectives of the European Union for the period 2007-2013 1, the
BT 21CN Network IPv6 Transformation
BT 21CN Network IPv6 Transformation Mircea Pisica IP and Data Architect 21CN, Global Networks & Computing Infrastructure BT Innovate and Design 14 Dec 2010 Ghent Belgium Agenda BT 21CN Overview IPV6 on
RNP Experiences and Expectations in Future Internet R&D
RNP Experiences and Expectations in Future Internet R&D CPqD, Campinas 23 September 2009 Michael Stanton [email protected] Director of Innovation Rede Nacional de Ensino e Pesquisa - RNP 2009 RNP Introduction
The world is going digital
The world is going digital World is going mobile New data is being created continuously > 80% of mobile subscriptions will be for mobile broadband by the end of 2019 48 hours of video are uploaded to YouTube
