CAS s IDP system and resources in Education Cloud



Similar documents
Integrating Multi-Factor Authentication into Your Campus Identity Management System

Network Information Center, University of Chinese Academy of Sciences Dr. Zha Daren

Configuring Single Sign-on from the VMware Identity Manager Service to WebEx

The increasing popularity of mobile devices is rapidly changing how and where we

HOL9449 Access Management: Secure web, mobile and cloud access

Configuring Single Sign-on from the VMware Identity Manager Service to AirWatch Applications

Masdar Institute Single Sign-On: Standards-based Identity Federation. John Mikhael ICT Department

Authentication Integration

TRUST AND IDENTITY EXCHANGE TALK

Flexible Identity Federation

SAML SSO Configuration

Configuring Single Sign-on from the VMware Identity Manager Service to ServiceNow

IMPLEMENTING SINGLE SIGN- ON USING SAML 2.0 ON JUNIPER NETWORKS MAG SERIES JUNOS PULSE GATEWAYS

Authentication Methods

Alex Wong Senior Manager - Product Management Bruce Ong Director - Product Management

ESA EO Identify Management

OPENIAM ACCESS MANAGER. Web Access Management made Easy

Vidder PrecisionAccess

Step-by-Step guide for SSO from MS Sharepoint 2010 to SAP EP 7.0x

API-Security Gateway Dirk Krafzig

OpenAM All-In-One solution to securely manage access to digital enterprise and customer services, anytime and anywhere.

SAP HANA Cloud Portal Overview and Scenarios

Canadian Access Federation: Trust Assertion Document (TAD)

Easy as 1-2-3: The Steps to XE. Mark Hoye Services Portfolio Consultant

Integration Guide. SafeNet Authentication Service. Using SAS as an Identity Provider for Tableau Server

My Stuff Everywhere Your Content On Any Screen

Federated Identity Management Checklist

Configuring Single Sign-on from the VMware Identity Manager Service to Amazon Web Services

Federation Proxy for Cross Domain Identity Federation

Integration Guide. SafeNet Authentication Service. Using SAS as an Identity Provider for Salesforce

The Password Problem Will Only Get Worse

Agenda. How to configure

Keeping access control while moving to the cloud. Presented by Zdenek Nejedly Computing & Communications Services University of Guelph

How to Provide Secure Single Sign-On and Identity-Based Access Control for Cloud Applications

Using etoken for SSL Web Authentication. SSL V3.0 Overview

Using Shibboleth for Single Sign- On

TrustedX: eidas Platform

Canadian Access Federation: Trust Assertion Document (TAD)

Single Sign On at Colorado State. Ron Splittgerber

Multi-factor Authentication Considerations for InCommon Silver. Mary Dunker Virginia Tech InCommon Confab April 26, 2012

Mobile Identity and Edge Security Forum Sentry Security Gateway. Jason Macy CTO, Forum Systems

How To Use Saml 2.0 Single Sign On With Qualysguard

PRIVACY AWARE ACCESS CONTROL FOR CLOUD-BASED DATA PLATFORMS

How to create a SP and a IDP which are visible across tenant space via Config files in IS

Development and deployment of integrated attribute based access control for collaboration

Evaluation of different Open Source Identity management Systems

Can We Reconstruct How Identity is Managed on the Internet?

SAP NetWeaver Fiori. For more information, see "Creating and enabling a trusted provider for Centrify" on page

SAML and OAUTH comparison

Shibboleth N-Tier Support. Chad La Joie

Glinda Cummings World Wide Tivoli Security Product Manager

A Survey on Cloud Security Issues and Techniques

IBM Tivoli Federated Identity Manager

Issues in federated identity management

Secure the Web: OpenSSO

Applying Cryptography as a Service to Mobile Applications

WHITEPAPER. SECUREAUTH 2-FACTOR AS A SERVICE 2FaaS

SAP Single Sign-On 2.0 Overview Presentation

InCommon Affiliates Webinar Three Case Studies with Unicon September 18, 2013

This chapter describes how to use the Junos Pulse Secure Access Service in a SAML single sign-on deployment. It includes the following sections:

Dell One Identity Cloud Access Manager How to Develop OpenID Connect Apps

WHITEPAPER SECUREAUTH AND CAC HSPD-12 AUTHENTICATION TO WEB, NETWORK, AND CLOUD RESOURCES

NCSU SSO. Case Study

Configuring Parature Self-Service Portal

Identity. Provide. ...to Office 365 & Beyond

Introduction to CERNET+ IPv6 Cloud Services Platform Initiative

Security Yokogawa Users Group Conference & Exhibition Copyright Yokogawa Electric Corporation Sept. 9-11, 2014 Houston, TX - 1 -

Administering Jive Mobile Apps

UNIVERSITY OF COLORADO Procurement Service Center INTENT TO SOLE SOURCE PROCUREMENT CU-JL SS. Single Sign-On (SSO) Solution

CHAPTER 1 INTRODUCTION

Federated Identity Management Solutions

UW System Identity & Access Management (IAM) Recommended Strategic Roadmap

Identity Management in Liferay Overview and Best Practices. Liferay Portal 6.0 EE

Beyond passwords: Protect the mobile enterprise with smarter security solutions

Integrity measurements for stronger cloud-based authentication

Entitlements Access Management for Software Developers

Enterprise & Vertical Reporting. Challenges and Solutions

Protect Everything: Networks, Applications and Cloud Services

Computer Systems Security 2013/2014. Single Sign-On. Bruno Maia Pedro Borges

RedIRIS Identity Service

Federated Identity: Leveraging Shibboleth to Access On and Off Campus Resources

Single Sign On. SSO & ID Management for Web and Mobile Applications

Zendesk SSO with Cloud Secure using MobileIron MDM Server and Okta

INUVIKA OPEN VIRTUAL DESKTOP FOUNDATION SERVER

SSO Plugin. Case study: Integrating with Ping Federate. J System Solutions. Version 4.0

Federated single sign-on (SSO) and identity management. Secure mobile access. Social identity integration. Automated user provisioning.

Single Sign On for ShareFile with NetScaler. Deployment Guide

Single Sign On (SSO) Implementation Manual. For Connect 5 & MyConnect Sites

SD Departmental Meeting November 28 th, Ale de Vries Product Manager ScienceDirect Elsevier

Open Source Identity Integration with OpenSSO

Adding Federated Identity Management to OpenStack

Crypho Security Whitepaper

An overview of configuring WebEx for single sign-on. To configure the WebEx application for single-sign on from the cloud service (an overview)

Get a Whiff of WIF Windows Identity Foundation. Keith Brown

Enabling Federation and Web-Single Sign-On in Heterogeneous Landscapes with the Identity Provider and Security Token Service Supplied by SAP NetWeaver

Configuring. Moodle. Chapter 82

IGI Portal architecture and interaction with a CA- online

Access Management Analysis of some available solutions

2014 IBM Corporation

Information Security Group Active-client based identity management

Transcription:

CAS s IDP system and resources in Education Cloud DAREN ZHA CANS2015, Chengdu

Outline CAS s IDP system and Education Cloud introduction Problems of interoperation A interoperation plan

CAS s Education Cloud and users Headquarter ERP OA Email Education Cloud apps Admission Course selection On-line courses Institute Institute App App App App App App

SOME SERVICES IN EDUCATION CLOUD Edu Analysis Self Learning E-Learning Platform Digital Course

CAS s IDP system A cloud based identity management system which provides services to applications and users Identity management (100+ institutes, 100,000+users) Single sign on (100+ application,include public services and private applications) Authentication and authorization Certification authority service

CHARACTERISTIC Fast deployment Cloud based Obey security regulations Obey security regulations of Public Security and Cryptographic Management Low cost for investment and maintenance No need to buy or develop new software User privacy protection User s private information only disclose to trusted applications Multi factor Authentication Usb key password onetime password Multi Level security policy Define multiple policy, application can choose appropriate policy

System development Neither commercial or open source solutions is used, All software is developed by ourselves using C++ Using Chinese cryptographic algorithms Design a light-weight single sign on protocol

APPLICATION MODE CAS public services CSTNET services Education Cloud services National Science Library services... Institute app Institute OA Institute portal... CAS s IDP CAS critical app External services Other universities services Public services... CAS ARP system CAS email system...

The detail of CAS s Education Cloud(up to 2015.6) User amount:189,000 Active user in past one year:71,038 Visits in past one year:14,678,591 Num. of App:81 Course site:16,809 Video course:1349 Num. of Dissertation:184,916

THE SCOPE OF APPLICATION(BY 2015) Most institutes of CAS 100+ institutes 100,000+ users 100+ applicat ions and services Cover most critical applicatio n

Outline CAS s IDP system and Education Cloud introduction Problems of interoperation A interoperation plan

Problems of interoperation Algorithm Protocol Security concern Service provider configuration Motivation

Problem1: Algorithm To obey the regulation of cryptographic management authority, CAS s IDP system uses Chinese cryptographic algorithm SM2(signature algorithm) and SM3(Hash algorithm) Most IDPs and service providers use common algorithm such as RSA, SHA1.

Problem2: Protocol To achieve low processing delay and high scalability, CAS s IDP system uses a selfdesigned light weight protocol. InCommon uses standard protocol SAML. Although the two protocols have similar flow and data, the data formats are different

Problem3: Security Concern If federated identity is achieved between CAS and InCommon, how to prevent accidental authentication or authorization faults, and how to mitigate the impact of these faults. The problem is complicate, because, CAS and InCommon have different security policies and how to map the policies need to be solved first.

Problem4: Service provider configuration All service providers join InCommon need to install shibboleth and maintain the metadata It is not practical for many CAS s applications to make that configuration Apply and maintain the metadata will be a big workload for operations staff

Problem5: motivation Why users use the federated identity service? What is good for them? Users adopt federated identity service only if it provide more desired applications and convenient user experience CAS s Education Cloud can supply some interesting education resources From InCommen?

Outline CAS s IDP system and Education Cloud introduction Problems of interoperation A interoperation plan

interoperation plan IDP IDP SP CAS IDP SP SP SP SP Identity Federatio n Gateway CAS IDP CAS APP InCommon CAS APP CAS APP CAS APP

Identity Federation Gateway Act as both IDP and SP Support SAML and our light-weight protocol(may support OAuth or other protocol) Support different algorithms, SM2/RSA/SM3/SHA1 Support security policy mapping between CAS and InCommon Support strict and fine grained access control Provide detailed identity federation audit information

Interoperation flow(cas user access InCommon SP) Redirect the request to the gateway 3 The Gateway provide a Handle to SP SP 5 CAS The Gateway get a token CAS IDP which provide the user s Identity and attributes The SP request user ttributes from the gateway 6 Handle Attribute Identity Federatio n Gateway 4 Token User Access InCommon SP 2 InCommon 1 CA SI DP User Log in to CAS IDP

Interoperation flow(incommon user access CAS APP) The Gateway act as SP and use the standard InCmmon procedure to get The handle and attribute Of the user ID P 4 Handle The Gateway generate a Identity federation token To CAS IDP Redirect The request to Gateway Attribute 3 Redirect The request to CAS IDP Identity Federatio n Gateway 2 5 Token CAS IDP The CAS IDP generate A token to app, which Will open the access to The user User Access CAS APP 1 AP P

Motivation CAS and PKU Open excellent course in MOOC services,historical dissertation and other education resources to each other Provide CAS s high performance computing service to PKU scientist CAS and InCommon MOOC? More education service? To be discussed

Thank YOU