A(nother) view on federation issues

Slides:



Advertisements
Similar presentations
Using PHINMS and Web-Services for Interoperability The findings and conclusions in this presentation are those of the author and do not necessarily represent.
Advertisements

The Next Generation Grid Kostas Tserpes, NTUA Beijing, 22 of June 2005.
GT 4 Security Goals & Plans Sam Meder
OOI-CI–Ragouzis– Ocean Observatories Initiative Cyberinfrastructure Component CI Design Workshop October 2007.
Federated Digital Rights Management Mairéad Martin The University of Tennessee TERENA General Assembly Meeting Prague, CZ October 24, 2002.
© 2007 Cisco Systems, Inc. All rights reserved.Cisco Public University of the Future 1 TF-Mobility future Klaas Wierenga
Supporting education and research E-learning tools, standards and systems Sarah Porter Head of Development, JISC.
Diego R. Lopez Middleware & identity Along the winding way.
Dorian Grid Identity Management and Federation Dialogue Workshop II Edinburgh, Scotland February 9-10, 2006 Stephen Langella Department.
Connect. Communicate. Collaborate The eduGAIN Way Diego R. Lopez - RedIRIS.
T Network Application Frameworks and XML Service Federation Sasu Tarkoma.
Beispielbild Shibboleth, a potential security framework for EDIT Lutz Suhrbier AG Netzbasierte Informationssysteme (
Directories and PKI Keith Hazelton Senior IT Architect, UW-Madison PKI Summit, Snowmass, 9-Aug-01.
Helsinki Institute of Physics (HIP) Liberty Alliance Overview of the Liberty Alliance Architecture Helsinki Institute of Physics (HIP), May 9 th.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Interoperability Shibboleth - gLite Christoph.
High-quality Internet for higher education and research AAI from the NREN perspective Schiphol, October 17, 2005
A survey based analysis on training opportunities Dr. Jūratė Kuprienė Framing the digital curation curriculum International Conference Florence, Italy.
Identity Management: A Technical Perspective Richard Cissée DAI-Labor; Technische Universität Berlin
Connect. Communicate. Collaborate Federation Interoperability Made Possible By Design: eduGAIN Diego R. Lopez (RedIRIS)
Semantic Web Technologies Research Topics and Projects discussion Brief Readings Discussion Research Presentations.
W HAT IS I NTEROPERABILITY ? ( AND HOW DO WE MEASURE IT ?) INSPIRE Conference 2011 Edinburgh, UK.
Shibboleth Update Eleventh Federal & Higher Education PKI Coordination Meeting (Fed/Ed Thursday, June 16, 2005.
Conference name Company name INFSOM-RI Speaker name The ETICS Job management architecture EGEE ‘08 Istanbul, September 25 th 2008 Valerio Venturi.
NSDL & Access Management David Millman Columbia University Jan ‘02.
Diego R. Lopez, RedIRIS JRES2005, Marseille On eduGAIN and the Coming GÉANT Middleware Infrastructure.
Diego R. Lopez, RedIRIS TF-EMC2, Umea SIR, FedSSH and more to come…
© 2004 IBM Corporation ICSOC2004 Panel Discussion: Grid Systems: What is needed from web service standards? Jeffrey Frey IBM.
Shibboleth & Federated Identity A Change of Mindset University of Texas Health Science Center at Houston Barry Ribbeck
Adding Distributed Trust Management to Shibboleth Srinivasan Iyer Sai Chaitanya.
Gridshib-intro-dec051 GridShib An Introduction Tom Scavo NCSA.
Workshop on Security for Web Services. Amsterdam, April 2010 Applying SAML to Identity Data Exchange.
AAI Interconnection with an European style Diego R. Lopez RedIRIS.
Connect. Communicate. Collaborate Applying eduGAIN to network operations The perfSONAR case Diego R. Lopez (RedIRIS) Maurizio Molina (DANTE)
Data Grids, Digital Libraries and Persistent Archives: An Integrated Approach to Publishing, Sharing and Archiving Data. Written By: R. Moore, A. Rajasekar,
UNICORE and Argus integration Krzysztof Benedyczak ICM / UNICORE Security PT.
Access Policy - Federation March 23, 2016
Bob Jones EGEE Technical Director
GEOSS Federated Single Sign-On
Stop Those Prying Eyes Getting to Your Data
Applying eduGAIN to network operations The perfSONAR case
LIGO Identity and Access Management
The Policy Puzzle Many groups and (proposed) policies, but leaving many open issues AARC “NA3” is tackling a sub-set of these “Levels of Assurance” –
Shibboleth Roadmap
Federation Systems, ADFS, & Shibboleth 2.0
Grid Security.
OMG, Another Simple, Lightweight Authentication Service???
First steps in federation peering: eduGAIN and eduroam
Ian Bird GDB Meeting CERN 9 September 2003
The GEMBus Architecture and Core Components
Federation peering à la European The eduGAIN way
A New Era in Critical Communications
CLARIN Federated Identity Vision
Introduction How to combine and use services in different security domains? How to take into account privacy aspects? How to enable single sign on (SSO)
Adding Distributed Trust Management to Shibboleth
State of e-Authentication in Higher Education Bernie Gleason
Federation peering à la European The eduGAIN way
Sophia Lafferty-hess | research data manager
VSA Integration with Apache
The DAMe’s First Steps: eduroam and NAS-SAML
Federated Digital Rights Management
Tim Bornholtz Director of Technology Services
A Funders Perspective Maria Uhle Co-Chair, Belmont Forum Directorates for Geosciences, US National Science Foundation.
It Is All about Identity (Whatever the Sphere)
SAMANVITHA RAMAYANAM 18TH FEBRUARY 2010 CPE 691
ARCHITECTURE OVERVIEW
Design Yaodong Bi.
WS Standards – WS-* Specifications
The Attribute and the ecosystem
Introduction to SOA Part II: SOA in the enterprise
Grid Computing Software Interface
Presentation transcript:

A(nother) view on federation issues

Has become common place And federations are (or soon will be) in bloom The F... word Has become common place And not only in AC space And federations are (or soon will be) in bloom This raises/reformulates additional issues Reconciling base technologies Agreeing on trust mechanisms Aligning on schemas Reaching applications Coordinating metadata

SAML is the commonly agreed lingua franca for identity data exchange The L... word SAML is the commonly agreed lingua franca for identity data exchange But unconquered kingdoms exist Most of the Grid territory BS infrastructures MS and its strategy WS are still most unexplored Rebellions arise Lightweight identity protocols And even civil wars Migration paths from 1.1 to 2.0

Moving towards conformance In the protocol and profile forest, conformance must be at least assessed Reference implementations Testing facilities Practical, hybrid approaches deserve to be explored Identify minimal properties to be preserved Let it happen

But it is not clear whether infrastructure should follow the two above The T... word Another common understanding is the use of public key techniques in building trust But it is not clear whether infrastructure should follow the two above Current federation software uses different kind of metadata structures to exchange public keys But this poses maintenance problems And many existing federations are based on PKI But convergence seems the only path

Possibilities to merge Merging the two paths Possibilities to merge Extensions can include references to Attribute Authorities X.509 certificate <=> SAML AuthN assertion X.509 AC <=> SAML Attr assertion Pieces are already around And approaches like PMAs and TACAR can play a key role

Schemas constitute the core of federation data exchange The D... word Schemas constitute the core of federation data exchange But even the simplest agreement is lengthy and complicated Even inside relatively small, tightly coupled groups And recurrent discussions about the nature of data arise New communities always try to bring their own parlance And privacy constraints must be stated once again

Concentrate on data usage Getting out of the cave Concentrate on data usage The common entitlement value for general license access in ShibEnable Decouple attributes the SCHAC way From specific ontologies From local dialectal forms Do not fear some redundancy As long as a canonical representation exists

We are still far for reaching even half of the current applications The A... word We are still far for reaching even half of the current applications Talking just about the Web-based ones And there is a lot of dark matter around there Simply legacy I-do-it-my-way-and-no-other-possible Commercial providers not willing to risk And a great number of non-Web natural niches To be filled asap

Keys for pervasiveness Try to keep as close to applications as possible Speaking their own language Try to go beyond the Web cage Keeping usability Exploring WS is specially relevant Pave the migration way A mixed solution is far better than no solution Proxy when no other choice exists

A federation is defined by its metadata The C... word A federation is defined by its metadata Metadata distribution is a key issue And directly related to the trust establishment process Current methods simply do not scale Growth requires additional features Dynamic publication Location Service composition And many potential metadata is still in an implicit state Another case of middleware dark matter

Making interoperation possible Metadata distribution is essential Repositories and location protocols Registries and naming schemas Gatewaying and proxying are going to stay for a long time To reach all the moving targets around And policies are still to be defined Many things to think about As we are still at the very beginning