AAI in Swiss Higher Education Ueli Kienholz, <kienholz@switch.ch> 2006 SWITCH
Without AAI University A Student Admin Web Mail e-learning Tedious user registration at all resources Unreliable and outdated user data at resources Different login processes Library B e-journals Literature DB Many different passwords Many resources not protected due to difficulties University C Research DB Often IP-based authorization e-learning Costly implementation of inter-institutional access User Administration Authentication Authorization Resource Credentials 2
With AAI University A AAI Student Admin Web Mail e-learning No user registration and user data maintenance at resource needed Single login process for the users Library B e-journals Many new resources available for the users University C Literature DB Research DB e-learning Enlarged user communities for resources Authorization independent of location Efficient implementation of inter-institutional access User Administration Authentication Authorization Resource Credentials 3
SWITCHaai Project Timeline 2001 2002 2003 2004 2005 2006 2007 Study Pilot Implementation Operation Architecture Evaluation -> Shibboleth Study, Planning 4
Shibboleth Open Source Developed by Internet2 Federated Approach Privacy National deployment projects in the US, UK and Finland, growing interest in other European countries For web resources only - as a first step Based on SAML Cooperations with Liberty Alliance Cooperations with Content Providers (e-journals) http://shibboleth.internet2.edu/ 5
Demo (Try it yourself) http://www.switch.ch/aai -> Live Demo -> demo resource http://www.switch.ch/aai/demo/demo_live.html 6
Demo https://kelut.switch.ch/aai/viewer.php 7
Single Sign On Home Org Credentials 4 5 3 WAYF 2 1 6 Demo Resource 9 wayf.switch.ch kelut.switch.ch 8 7 10 E-Learning Resource dokeos.unige.ch https://dokeos.unige.ch/aai/login.php 8
SWITCHaai Building Blocks Interoperation Organisational Framework Identity Providers (Home Orgs) Service Providers (Resources) Central Services Funding 9
Identity Providers (Home Orgs) in SWITCHaai Coverage: 130 000 Users (> 2/3 of all) In Swiss Higher Education Université de Genève Université de Neuchâtel EPFL HES-SO Universität Basel Université de Lausanne University Hospital Zürich Pädagogische Hochschule Bern Université de Fribourg Universität Zürich Universität Bern SWITCH Zürcher Hochschule Winterthur Universität St. Gallen ETH Zürich Universität Luzern Fachhochschule Zentralschweiz SUPSI USI Operational Getting ready Identity Providers 10
Types of Service Providers e-learning OLAT@UniZH WebCT@ETHZ DOIT@USZ Moodle AD Learn & Co Vista@SVC VITELS@UniBE dokeos@unige ILIAS@ETHZ Blackboard libraries ScienceDirect EZproxy@ETHBib other web applications econf-portal@switch Twiki@SWITCH Web-SMS@SWITCH CompiCampus@ETHZ IS-Academia commercial SwissLex Bundesgericht 16 000 active users 79 resources Cablecom eshops Service Providers 11
Organisational Framework SWITCH acts as SWITCHaai Federation Service Provider Federation membership based on signed service agreements Organisation 12
Authorization Attributes Personal Group Membership Unique Identifier Surname Given name Home Organization Name Home Organization Type Affiliation (student, staff, ) Implementation of Attributes Mandatory Recommended or optional E-mail Address(es) Phone number(s) Preferred language Date of birth Gender Study branch Study level Staff category Group membership Organization Path Organizational Unit Path Based on eduperson Attributes Schweizerisches Hochschulinformationssystem (SHIS) NO username, password Interoperation Attribute Specification: http://www.switch.ch/aai/docs/aai_attr_specs.pdf 13
Access Control Example: DOIT DOIT: Dermatology Online with Interactive Technology Resource Identity Provider Access Rule: HomeOrg = UniZH UniBE UniL Affiliation = Student StudyBranch = Medicine StudyLevel = 20 Universität Zürich Universität Bern Universtié de Lausanne Service Providers 14
Central AAI-Services Strategy & Marketing International Contacts Support, Consulting, Training Providing Federation-specific Files and Configuration Guides Operating WAYF (Where Are You From Server) Test-HomeOrg and Test-Resource Tools (AAIportal, Resource Registry) Virtual Home Organization Jump Start Service Central Services 15
Questions? Q & A http://www.switch.ch/aai aai@switch.ch 16