Federated Identity Management for Research Communities (FIM4R)

Size: px
Start display at page:

Download "Federated Identity Management for Research Communities (FIM4R)"

Transcription

1 Federated Identity Management for Research Communities (FIM4R) David Kelsey (STFC-RAL, UK) Federations Virtual Day 19 Jun 2013

2 Who am I? Head of Particle Physics Computing at RAL in the United Kingdom Lead many Grid Security activities in EGI, WLCG and UK GridPP Both policy development and security operations Member of IGTF TAGPMA and EUGridPMA representing WLCG (as relying party) A representative of WLCG on FIM4R activities 19 Jun 13 FIM4R, Kelsey 2

3 Outline FIM4R what is it? Why do we want to federate? Status and plans Working with REFEDs, edugain, Geant3+ Lessons learned 19 Jun 13 FIM4R, Kelsey 3

4 Introduction FIM4R Federated Identity Management for Research Collaborations An ad-hoc activity that started 2 years ago in Europe To explore and document a joint vision and our common requirements for FIM And describe issues that make progress difficult Includes: Climate Science, Earth Sciences, ESA, High Energy Physics, Social Sciences & Humanities, Life Sciences, Neutron & Photon Facilities, WeNMR And open to any others who wish to join 19 Jun 13 FIM4R, Kelsey 4

5 Why federate? Separate authentication and authorisation Identification done by home institute Community manages authorisation Ease of use User single sign-on Ease of management 19 Jun 13 FIM4R, Kelsey 5

6 Workshops and Paper 5 workshops to date link to Mar 2013 agenda (and links therein) April 2012: We prepared a paper that documents use cases, common requirements, a common vision and recommendations Paper: CERN-OPEN : 19 Jun 13 FIM4R, Kelsey 6

7 Common vision statement A common policy and trust framework for Identity Management based on existing structures and federations either presently in use by or available to the communities. This framework must provide researchers with unique electronic identities authenticated in multiple administrative domains and across national boundaries that can be used together with community defined attributes to authorize access to digital resources 19 Jun 13 FIM4R, Kelsey 7

8 Common Requirements User friendliness Many users use infrequently Browser and non-browser federated access Bridging between communities Multiple technologies and translators Translation will often need to be dynamic Open standards and sustainable licenses For interoperability and sustainability Different Levels of Assurance When credentials are translated, LoA provenance to be preserved Authorisation under community and/or facility control Externally managed IdPs cannot fulfil this role Well defined semantically harmonised attributes For interoperable authorisation Likely to be very difficult to achieve! 19 Jun 13 FIM4R, Kelsey 8

9 Requirements (2) Flexible and scalable IdP attribute release policy Different communities and different SPs need different attributes Negotiate with IdF not all IdPs for scaling Attributes must be able to cross national borders Data protection/privacy considerations Attribute aggregation for authorisation Privacy and data protection to be addressed with communitywide individual identities We need to identify individuals E.g. ethical committees can require names, addresses, supervisors to grant access 19 Jun 13 FIM4R, Kelsey 9

10 Pilot Projects 19 Jun 13 FIM4R, Kelsey 10

11 Addressing e-researchers Requirements Licia Florio, TERENA REFEDS Meeting 2 June 2013

12 FIM4R Paper FIM Paper highlighted some of the issues that hinder the usage of federated access in the e- Research community: Contains use-cases Present common requirements There is common consensus to work towards increased use of Federated Identity Management within the escience communities: However there are a number of use-cases that are not well (or at all) supported by the ID Feds

13 Roadmap for collaboration REFEDS/eduGAIN produced a document to address FIM4R issues: Provides an initial list of prioritised requirements (thanks also to Bob Jones & co.) Addresses some perceived issues Presents proposals to solve some of the challenges

14 Approach The roadmap IS a joint work ID Fed and e- Researchers: Identify key projects within the e-research community that REFEDS/GÉANT can liaise with Funding: edugain and GN3plus have dedicated budget to carry out some work and do some pilots REFEDS can offer a limited budget Participating e-research projects may use some of their funding?

15 The Proposals Selection of areas presented at the FIM4R Workshop: Federated access for non-web applications Not really in scope for REFEDS Guests IdPs Controversial topic: some people are in favour, some other are against Community managed attribute authorities Work is happening in the GN3+ project But maybe also in scope for REFEDS Motivating IdPs to release attributes Lots in the REFEDS plan (entity categories, LoA, CoC, etc.,)

16 Lessons learned Federating is not easy! Policy often more difficult than technical issues Many issues Attribute release, scalability of agreements, levels of assurance, non-web applications, need an IdP for the homeless, merge attributes, Very useful to work together Pilot projects are good for focussing on issues You are very welcome to join FIM4R 19 Jun 13 FIM4R, Kelsey 16

17 Next steps More work on pilot projects Work with REFEDs/Geant/EduGAIN on agreed Roadmap issues Next FIM4R meeting 30 Sep 3 October 2013 CSC, Finland With VAMPS and REFEDs meetings All welcome! 19 Jun 13 FIM4R, Kelsey 17

18 More info FIM4R (see this and links therein) REFEDs VAMP 19 Jun 13 FIM4R, Kelsey 18

19 Questions? 19 Jun 13 FIM4R, Kelsey 19

Federated Identity Management Interest Group

Federated Identity Management Interest Group 1 Federated Identity Management Interest Group The FIM interest group (FIMig) is an international crossdomain interest group to work on all issues related to the use FIM for the implementation of AAIs

More information

Licia Florio Project Development Officer [email protected] www.terena.org Identity Federations in Europe

Licia Florio Project Development Officer licia@terena.org www.terena.org Identity Federations in Europe APAN Conference Honolulu, Hawaii 24 January 2008 Licia Florio Project Development Officer [email protected] www.terena.org Identity Federations in Europe Outline Networking Organisations in Europe Requirements

More information

Federated Identity Management for Research Collaborations

Federated Identity Management for Research Collaborations Federated Identity Management for Research Collaborations Paper Type: Research paper Date of this version: 23 rd April 2012 Abstract Federated identity management (FIM) is an arrangement that can be made

More information

VOPaaS Virtual Organisation Platform as a Service

VOPaaS Virtual Organisation Platform as a Service VOPaaS Virtual Organisation Platform as a Service Marina Adomeit Task Leader, AMRES, Serbia Niels Van Dijk Technical Lead, SURFnet, The Netherlands FIM4R meeting Nov 30, 2015, Austria About VOPaaS in GÉANT

More information

Federated Authentication and Credential Translation in the EUDAT Collaborative Data Infrastructure

Federated Authentication and Credential Translation in the EUDAT Collaborative Data Infrastructure Federated Authentication and Credential Translation in the EUDAT Collaborative Data Infrastructure Ahmed Shiraz Memon (JSC - DE) Jens Jensen (STFC escience - UK) Ales Cernivec (XLAB - SL) Krzysztof Benedyczak

More information

A cross-platform model for secure Electronic Health Record communication

A cross-platform model for secure Electronic Health Record communication International Journal of Medical Informatics (2004) 73, 291 295 A cross-platform model for secure Electronic Health Record communication Pekka Ruotsalainen National Research and Development Centre for

More information

Procurement Innovation for Cloud Services in Europe

Procurement Innovation for Cloud Services in Europe Procurement Innovation for Cloud Services in Europe CERN 14 May 2014 Bob Jones (CERN) This document produced by Members of the Helix Nebula consortium is licensed under a Creative Commons Attribution 3.0

More information

Federated Identity Management

Federated Identity Management Federated Identity Management SWITCHaai Team [email protected] Agenda 2 What is Federated Identity Management? What is a Federation? The SWITCHaai Federation Interfederation Evolution of Identity Management

More information

A Federated Authorization and Authentication Infrastructure for Unified Single Sign On

A Federated Authorization and Authentication Infrastructure for Unified Single Sign On A Federated Authorization and Authentication Infrastructure for Unified Single Sign On Sascha Neinert Computing Centre University of Stuttgart Allmandring 30a 70550 Stuttgart [email protected]

More information

Scientific Cloud Computing Infrastructure for Europe Strategic Plan. Bob Jones,

Scientific Cloud Computing Infrastructure for Europe Strategic Plan. Bob Jones, Scientific Cloud Computing Infrastructure for Europe Strategic Plan Bob Jones, IT department, CERN Origin of the initiative Conceived by ESA as a prospective for providing cloud services to space sector

More information

Federations 101. An Introduction to Federated Identity Management. Peter Gietz, Martin Haase

Federations 101. An Introduction to Federated Identity Management. Peter Gietz, Martin Haase Authentication and Authorisation for Research and Collaboration Federations 101 An Introduction to Federated Identity Management Peter Gietz, Martin Haase AARC NA2 Task 2 - Outreach and Dissemination DAASI

More information

Collaboration in the Cloud. Niels van Dijk, SURFnet, [email protected] CAMP, Nov 15 2013, San Francisco

Collaboration in the Cloud. Niels van Dijk, SURFnet, niels.vandijk@surfnet.nl CAMP, Nov 15 2013, San Francisco Collaboration in the Cloud Niels van Dijk, SURFnet, [email protected] CAMP, Nov 15 2013, San Francisco R&E SURF in and The SURFnet Netherlands: SURF and SURFnet National Research & Education Network

More information

Board of Member States ERN implementation strategies

Board of Member States ERN implementation strategies Board of Member States ERN implementation strategies January 2016 As a result of discussions at the Board of Member States (BoMS) meeting in Lisbon on 7 October 2015, the BoMS set up a Strategy Working

More information

ELIXIR.SI elearning platform - EeLP

ELIXIR.SI elearning platform - EeLP ELIXIR.SI elearning platform - EeLP Brane Leskošek, Jure Dimec, Domen Soklič, Aleš Maver, Jan Jona Javoršek, Jure Kranjc, Peter Juvan ELIXIR.SI, Faculty of Medicine Ljubljana, University Medical Centre,

More information

RealMe. Technology Solution Overview. Version 1.0 Final September 2012. Authors: Mick Clarke & Steffen Sorensen

RealMe. Technology Solution Overview. Version 1.0 Final September 2012. Authors: Mick Clarke & Steffen Sorensen RealMe Technology Solution Overview Version 1.0 Final September 2012 Authors: Mick Clarke & Steffen Sorensen 1 What is RealMe? RealMe is a product that offers identity services for people to use and manage

More information

Federated Identity Management. Willem Elbers (MPI-TLA) EUDAT training

Federated Identity Management. Willem Elbers (MPI-TLA) EUDAT training Federated Identity Management Willem Elbers (MPI-TLA) EUDAT training Date: 26 June 2012 Outline FIM and introduction to components Federation and metadata National Identity federations and inter federations

More information

Title: A Client Middleware for Token-Based Unified Single Sign On to edugain

Title: A Client Middleware for Token-Based Unified Single Sign On to edugain Title: A Client Middleware for Token-Based Unified Single Sign On to edugain Sascha Neinert Computing Centre University of Stuttgart, Allmandring 30a, 70550 Stuttgart, Germany e-mail: [email protected]

More information

ArmeSFo EUGridPMA initiative for implementation of PKI in NATO Partner and Mediterranean Dialogue Countries

ArmeSFo EUGridPMA initiative for implementation of PKI in NATO Partner and Mediterranean Dialogue Countries ArmeSFo EUGridPMA initiative for implementation of PKI in NATO Partner and Mediterranean Dialogue Countries Ara Grigoryan 1, David Groep 2, Arsen Hayrapetyan 1 1 Armenian e-science Foundation, 49 Komitas

More information

Разработка программного обеспечения промежуточного слоя. TERENA BASNET Workshop, 16-17 November 2009 Joost van Dijk - SURFnet

Разработка программного обеспечения промежуточного слоя. TERENA BASNET Workshop, 16-17 November 2009 Joost van Dijk - SURFnet Разработка программного обеспечения промежуточного слоя TERENA BASNET Workshop, 16-17 November 2009 Joost van Dijk - SURFnet Contents - SURFnet Middleware Services department: - eduroam, SURFfederatie,

More information

Can We Reconstruct How Identity is Managed on the Internet?

Can We Reconstruct How Identity is Managed on the Internet? Can We Reconstruct How Identity is Managed on the Internet? Merritt Maxim February 29, 2012 Session ID: STAR 202 Session Classification: Intermediate Session abstract Session Learning Objectives: Understand

More information

Building blocks for establishing federation with organizations like ESA

Building blocks for establishing federation with organizations like ESA Building blocks for establishing federation with organizations like ESA ESA Single Sign-on & OGC Authentication Standard A. Baldi ESA: [email protected] M. Leonardi RHEA: [email protected] Helsinki

More information

AAI for Mobile Apps How mobile Apps can use SAML Authentication and Attributes. Lukas Hämmerle [email protected]

AAI for Mobile Apps How mobile Apps can use SAML Authentication and Attributes. Lukas Hämmerle lukas.haemmerle@switch.ch AAI for Mobile Apps How mobile Apps can use SAML Authentication and Attributes Lukas Hämmerle [email protected] Berne, 13. August 2014 Introduction App by University of St. Gallen Universities

More information

Adding Federated Identity Management to Openstack

Adding Federated Identity Management to Openstack Adding Federated Identity Management to Openstack David Chadwick [email protected] 5 April 2014 Cloud Computing Security and Identity Workshop, NMOC 1 OpenStack Large open source project to develop

More information

Mobile TV: The time to act is now

Mobile TV: The time to act is now SPEECH/07/154 Viviane Reding Member of the European Commission responsible for Information Society and Media Mobile TV: The time to act is now Mobile TV Conference, International CeBIT Summit Hannover,

More information

Office of the Chief Information Officer Department of Energy Identity, Credential, and Access Management (ICAM)

Office of the Chief Information Officer Department of Energy Identity, Credential, and Access Management (ICAM) Department of Energy Identity, Credential, and Access Management (ICAM) Cyber Security Training Conference Tuesday, May 18, 2010 1 Announcement LACS Birds-of-a-Feather Session Logistics Wednesday, May

More information

Bob Jones Technical Director [email protected]

Bob Jones Technical Director bob.jones@cern.ch Bob Jones Technical Director [email protected] CERN - August 2003 EGEE is proposed as a project to be funded by the European Union under contract IST-2003-508833 EGEE Goal & Strategy Goal: Create a wide

More information

PROTECT YOUR WORLD. Identity Management Solutions and Services

PROTECT YOUR WORLD. Identity Management Solutions and Services PROTECT YOUR WORLD Identity Management Solutions and Services Discussion Points Security and Compliance Challenges Identity Management Architecture CSC Identity Management Offerings Lessons Learned and

More information

Workprogramme 2014-15

Workprogramme 2014-15 Workprogramme 2014-15 e-infrastructures DCH-RP final conference 22 September 2014 Wim Jansen einfrastructure DG CONNECT European Commission DEVELOPMENT AND DEPLOYMENT OF E-INFRASTRUCTURES AND SERVICES

More information

e-irg workshop Dublin 22-23 May 2013 Track 1: Coordination of e-infrastructures

e-irg workshop Dublin 22-23 May 2013 Track 1: Coordination of e-infrastructures e-irg workshop Dublin 22-23 May 2013 Track 1: Coordination of e-infrastructures Rossend Llurba e-irgsp3 Track 1 2 sessions Session 1 (Chair: Lajos Balint) 4 presentations Bob Jones Stephen Moffat Sandra

More information

ABFAB and OpenStack(in the Cloud)

ABFAB and OpenStack(in the Cloud) ABFAB and OpenStack(in the Cloud) David W Chadwick University of Kent 1 Authentication in OpenStack Keystone User Trust Relationship Swift/Glance etc. 2 Federated Authnwith External IdPs External IdP User

More information

Digital signature and e-government: legal framework and opportunities. Raúl Rubio Baker & McKenzie

Digital signature and e-government: legal framework and opportunities. Raúl Rubio Baker & McKenzie Digital signature and e-government: legal framework and opportunities Raúl Rubio Baker & McKenzie e-government concept Utilization of Information and Communication Technologies (ICTs) to improve and/or

More information

Position Paper e-payments

Position Paper e-payments Position Paper e-payments 10 Recommendations for a Stronger e-payments Landscape in Europe www.ecommerce-europe.eu POSITION PAPER 3 Introduction: Ecommerce Europe Ecommerce Europe (www.ecommerce-europe.eu)

More information

Federated Identity Management

Federated Identity Management Federated Identity Management SWITCHaai Introduction Course Bern, 1. March 2013 Thomas Lenggenhager [email protected] Overview What is Federated Identity Management? What is a Federation? The SWITCHaai Federation

More information

A Shibboleth View of Federated Identity. Steven Carmody Brown Univ./Internet2 March 6, 2007 Giornata AA - GARR

A Shibboleth View of Federated Identity. Steven Carmody Brown Univ./Internet2 March 6, 2007 Giornata AA - GARR A Shibboleth View of Federated Identity Steven Carmody Brown Univ./Internet2 March 6, 2007 Giornata AA - GARR Short Section Title Agenda Assumptions and Trends Identity Management and Shibboleth Shibboleth

More information

Social Return on Investment (SROI)

Social Return on Investment (SROI) Social Return on Investment (SROI) Measuring your wider impact helps you understand and promote your real value. nef consulting realises the consultancy potential of nef s (new economics foundation) twenty-year

More information

On the Application of Trust and Reputation Management and User-centric Techniques for Identity Management Systems

On the Application of Trust and Reputation Management and User-centric Techniques for Identity Management Systems On the Application of Trust and Reputation Management and User-centric Techniques for Identity Management Systems Ginés Dólera Tormo Security Group NEC Laboratories Europe Email: [email protected]

More information

The Case for NRENs John DYER

The Case for NRENs John DYER The Case for NRENs John DYER TF- MSP Meeting, Espoo, Finland 9/10 September 2015 Networks Services People www.geant.org The Case for NRENs Published January 2009 This presentation is dedicated to continuing

More information

8970/15 FMA/AFG/cb 1 DG G 3 C

8970/15 FMA/AFG/cb 1 DG G 3 C Council of the European Union Brussels, 19 May 2015 (OR. en) 8970/15 NOTE RECH 141 TELECOM 119 COMPET 228 IND 80 From: Permanent Representatives Committee (Part 1) To: Council No. prev. doc.: 8583/15 RECH

More information

Building next generation consortium services. Part 3: The National Metadata Repository, Discovery Service Finna, and the New Library System

Building next generation consortium services. Part 3: The National Metadata Repository, Discovery Service Finna, and the New Library System Building next generation consortium services Part 3: The National Metadata Repository, Discovery Service Finna, and the New Library System Kristiina Hormia-Poutanen, Director of Library Network Services

More information

Logout in Single Sign-on Systems

Logout in Single Sign-on Systems Logout in Single Sign-on Systems Sanna Suoranta, Asko Tontti, Joonas Ruuskanen, Tuomas Aura IFIP IDMAN, London, UK, 8-9.4.2013 Logout in Single Sign-on Systems Motivation Single sign-on (SSO) systems SSO

More information

IoT-03-2017 R&I on IoT integration and platforms INTERNET OF THINGS FOCUS AREA

IoT-03-2017 R&I on IoT integration and platforms INTERNET OF THINGS FOCUS AREA HORIZON 2020 WP 2016-17 IoT-03-2017 R&I on IoT integration and platforms INTERNET OF THINGS DG CONNECT European Commission Internet of Things As enabler of a future hyper-connected society, the Internet

More information

GÉANT IaaS suppliers meeting Towards Pan-European Cloud Services. Utrecht October 14 2015

GÉANT IaaS suppliers meeting Towards Pan-European Cloud Services. Utrecht October 14 2015 GÉANT IaaS suppliers meeting Towards Pan-European Cloud Services Utrecht October 14 2015 Why and what TODAY More information about IaaS delivery through GÉANT Tender Provider GÉANT interaction Opportunity

More information

EXTENDING SINGLE SIGN-ON TO AMAZON WEB SERVICES

EXTENDING SINGLE SIGN-ON TO AMAZON WEB SERVICES pingidentity.com EXTENDING SINGLE SIGN-ON TO AMAZON WEB SERVICES Best practices for identity federation in AWS Table of Contents Executive Overview 3 Introduction: Identity and Access Management in Amazon

More information

Procurement Innovation for Cloud Services in Europe

Procurement Innovation for Cloud Services in Europe Procurement Innovation for Cloud Services in Europe Author: Bob Jones (CERN) on behalf of the PICSE consortium www.picse.eu/ @PICSEPROCURE Focus: cloud service procurement and the Digital Single Market

More information

ROADMAP. A Pan-European framework for electronic identification, authentication and signature

ROADMAP. A Pan-European framework for electronic identification, authentication and signature TITLE OF THE INITIATIVE ROADMAP A Pan-European framework for electronic identification, authentication and signature TYPE OF INITIATIVE CWP Non-CWP Implementing act/delegated act LEAD DG RESPONSIBLE UNIT

More information

TIB 2.0 Administration Functions Overview

TIB 2.0 Administration Functions Overview TIB 2.0 Administration Functions Overview Table of Contents 1. INTRODUCTION 4 1.1. Purpose/Background 4 1.2. Definitions, Acronyms and Abbreviations 4 2. OVERVIEW 5 2.1. Overall Process Map 5 3. ADMINISTRATOR

More information

Procurement Innovation for Cloud Services in Europe - PICSE

Procurement Innovation for Cloud Services in Europe - PICSE Procurement Innovation for Cloud Services in Europe - PICSE Sara Garavelli, Trust-IT Services [email protected] ICT Proposer s Day, 9 October 2014, Florence, Italy 1 The road to PICSE Cloud

More information

PROPOSAL TO DEVELOP AN EMPLOYEE ENGAGEMENT PROGRAMME

PROPOSAL TO DEVELOP AN EMPLOYEE ENGAGEMENT PROGRAMME PROPOSAL TO DEVELOP AN EMPLOYEE ENGAGEMENT PROGRAMME DEFINITIONS OF ENGAGEMENT The concept of employee engagement has received growing interest recently, with a range of research into what engagement is

More information

9360/15 FMA/AFG/cb 1 DG G 3 C

9360/15 FMA/AFG/cb 1 DG G 3 C Council of the European Union Brussels, 29 May 2015 (OR. en) 9360/15 OUTCOME OF PROCEEDINGS From: To: Council Delegations RECH 183 TELECOM 134 COMPET 288 IND 92 No. prev. doc.: 8970/15 RECH 141 TELECOM

More information

The Scottish Wide Area Network Programme

The Scottish Wide Area Network Programme The Scottish Wide Area Network Release: Issued Version: 1.0 Date: 16/03/2015 Author: Andy Williamson Manager Owner: Anne Moises SRO Client: Board Version: Issued 1.0 Page 1 of 8 16/04/2015 Document Location

More information

SAML and OAUTH comparison

SAML and OAUTH comparison SAML and OAUTH comparison DevConf 2014, Brno JBoss by Red Hat Peter Škopek, [email protected], twitter: @pskopek Feb 7, 2014 Abstract SAML and OAuth are one of the most used protocols/standards for single

More information

EFFECTS+ Clustering of Trust and Security Research Projects, Identifying Results, Impact and Future Research Roadmap Topics

EFFECTS+ Clustering of Trust and Security Research Projects, Identifying Results, Impact and Future Research Roadmap Topics EFFECTS+ Clustering of Trust and Security Research Projects, Identifying Results, Impact and Future Research Roadmap Topics Frances CLEARY 1, Keith HOWKER 2, Fabio MASSACCI 3, Nick WAINWRIGHT 4, Nick PAPANIKOLAOU

More information

Banks as bridges: Investment in a sustainable and climate-friendly economic system

Banks as bridges: Investment in a sustainable and climate-friendly economic system Banks as bridges: Investment in a sustainable and climate-friendly economic system Matthew Arndt, Head of division Environment, Climate and Social Office 18/01/2013 1 Who we are Breakdown of the EIB s

More information