Resource Entitlement Management System Manne Miettinen Mikael Linden Janne Lauros CSC – IT Center for Science.

Slides:



Advertisements
Similar presentations
Lousy Introduction into SWITCHaai
Advertisements

Federation management A mess? Nordunet Conference Mikael Linden CSC, the Finnish IT Center for Science.
Open Grid Forum 19 January 31, 2007 Chapel Hill, NC Stephen Langella Ohio State University Grid Authentication and Authorization with.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
KC-ROLO Project Kidderminster College Repository Of Learning Objects Graham Mason & Ed Beddows.
5/25/2015 AEB/Yleisesittely Roaming network access using Shibboleth in University of Helsinki Fall 2004 Internet2 Member Meeting 29th of September, 2004.
Federated Identity Management for Research Communities (FIM4R) David Kelsey (STFC-RAL) EGI TF, AAI workshop 19 Sep 2012.
Kalmar Union Mikael Linden CSC, the Finnish IT Center for Science.
CSC – Tieteen tietotekniikan keskus Oy CSC – IT Center for Science Ltd. The Language Bank of Finland User Authentication and Authorization Service
Information Resources and Communications University of California, Office of the President UCTrust Implementation Experiences David Walker, UCOP Albert.
CSC Grid Activities Arto Teräs HIP Research Seminar February 18th 2005.
May 17, 2005 E-sign Web Forms replace Paper Forms Presented by: Bob Schneider Western Washington University.
Campus Management Portal and Online Higher Education Cardean Learning Group.
European Life Sciences Infrastructure for Biological Information ELIXIR FI for BBMRI IT Morris FIMM and THL Tommi Nyrönen.
CASE: Haka federation EuroCAMP, 3-5 April, 2006 CSC, the Finnish IT Center for Science
Identity Management Practical Issues Associated with Sharing Federated Services UT System Identity Management Federation William A. Weems The University.
2005 © SWITCH Perspectives of Integrating AAI with Grid in EGEE-2 Christoph Witzig Amsterdam, October 17, 2005.
Update Finland TF-EMC Mikael Linden CSC, the Finnish IT Center for Science.
HAKA project HAKA User administration inside Finnish Higher Education Institutes results from the KATO project Barbro Sjöblom EDS 2003 Uppsala.
Shibboleth in Finnish Higher Education Organisations E-ICOLC 2005 Poznan, Poland.
Middleware Support for Virtual Organizations Internet 2 Fall 2006 Member Meeting Chicago, Illinois Stephen Langella Department of.
Neil Witheridge APAN29 Sydney February 2010 ARCS Authorisation Services Neil Witheridge Manager, ARCS Authorisation Services APAN29, Sydney, February 2010.
Kalmar Union, a Conferedation of Nordic Identity Federations TNC2009 Mikael Linden, CSC Andreas Solberg, UNINETT.
European Life Sciences Infrastructure for Biological Information Life science community update for the 7 th Federated Identity Management.
10/25/2015 AEB/Yleisesittely Organising Federated Identity in Finnish Higher Education TNC2005 Mikael Linden June 8th, 2005.
Campus Identity Management Requirements (=IAP) REFEDs meeting Mikael Linden,
Annual survey of CARNet member institutions Barbara Kolarek.
Oracle Application Server Portal: Advanced Content Management for Custom Integration John Dunne (Deputy CTO, HPHC) Anton Nielsen (Technical Director,
Resource Entitlement Management System Mikael Linden CSC – IT Center for Science.
Federations round table Haka federation of Finland EuroCAMP Mikael Linden CSC, the Finnish IT Center for Science.
Identity Management Practical Issues Associated with Sharing Federated Services William A. Weems The University of Texas Health Science Center at Houston.
Proposal of interface between GUS + Call Center and Experiments GDB Meeting – Klaus-Peter Mickel GridKa Karlsruhe.
Federations, the Data Protection Directive and WP29 TF-EMC2 Mikael Linden, CSC, the Finnish IT Center for Science.
Authentication and Authorisation for Research and Collaboration Peter Solagna Milano, AARC General meeting Current status and plans.
European Life Sciences Infrastructure for Biological Information ELIXIR and Identity Management 2 nd Workshop on Federated Identity.
/ 8 FEIDHE Electronic Identification in Finnish Higher Education Janne Kanner FEIDHE Electronic Identification in Finnish Higher Education.
Clain update TF-EMC Mikael Linden, CSC.
EResearchers Requirements ELIXIR AAI Workshop Presenter: Mikael Linden (ELIXIR AAI-TF)
Licensing in a European Perspective - case Finnish National Consortium ELAG 2001, Prague Kristiina Hormia-Poutanen.
KC-ROLO Project Kidderminster College Repository Of Learning Objects Graham Mason & Ed Beddows.
The DEER Distributed European Electronic Resource Dr Suzanne Keene Francesca Monti University College London.
b2access.eudat.eu B2ACCESS The simple and secure authorisation and authentication platform of EUDAT This work is licensed under the Creative.
Shibboleth Use at the National e-Science Centre Hub Glasgow at collaborating institutions in the Shibboleth federation depending.
Tutorial on Science Gateways, Roma, Riccardo Rotondo Introduction on Science Gateway Understanding access and functionalities.
Open Science and Research – Services for Research Data Management © 2014 OKM ATT 2014–2017 initiative Licenced under.
Case Studies in Federated Identity Management for Research Communities Ann Harding, SWITCH/GN3plus Peter Gietz, DAASI International GmbH/DARIAH Tommi Nyro.
Connect communicate collaborate Case Studies in Federated Identity Management for Research Communities Ann Harding, SWITCH/GN3plus Peter Gietz, DAASI International.
B2access.eudat.eu B2ACCESS User Training How to register with B2ACCESS Version 1 February 2016 This work is licensed under the Creative Commons.
Designing Identity Federation Policy, the right way Marina Vermezović, Academic Network of Serbia TNC2013 conference 4 May 2013.
European Life Sciences Infrastructure for Biological Information European Life Sciences Infrastructure for Biological Information.
European Life Sciences Infrastructure for Biological Information European Life Sciences Infrastructure for Biological Information.
ORCID consortium in Finland Hanna-Mari Puuska orcid.org/ April 22nd, 2016.
National Center for Supercomputing Applications University of Illinois at Urbana-Champaign This material is based upon work supported by the National Science.
Resource Entitlement Management System Timo Mustonen, CSC – IT Center for Science.
Innovation through participation Data Protection Code of Conduct (DP CoC) TNC2013 conference, 4 June 2013 Mikael Linden, CSC – IT Center for Science
Towards integrating European research information
Accessing the VI-SEEM infrastructure
Head of Publishing, University of Jyväskylä
© 2015 OKM ATT 2014–2017 initiative 
Extending Authentication to Members of Social Networks
Case Studies in Federated Identity Management for Research Communities
Research data finder Etsin
ELIXIR Safeguarding the results of life science research in Europe
Common Authentication and Authorisation Service for Life Science Research Mikael Linden, ELIXIR Finland.
EDDI12 – Bergen, Norway Toni Sissala
Resource Entitlement Management System
Resource Entitlement Management System
Research Information =Descriptive infromation, metadata, on e.g. publications, research data, projects, researchers, research groups and organizations.
GEANT Data protection Code of Conduct 2.0 REFEDS meeting 16 June 2019
Check-in Identity and Access Management solution that makes it easy to secure access to services and resources.
Presentation transcript:

Resource Entitlement Management System Manne Miettinen Mikael Linden Janne Lauros CSC – IT Center for Science

Affaire Tournesol

Background CSC is a non-profit state company –ICT services for research groups & higher education institutes –Wide co-operation with universities and research institutes (incl. Statistics Finland) CSC has operated the Finnish academic identity federation, Haka, since 2005 –Switzerland and Finland are the European pioneers in federated identity

Identity federation Polytechnic C Research Institute B University A Local user accounts Service 1 e.g. Library portal Service 2 Learning management system (LMS) Local user accounts

Haka – the federation of Finnish HE Haka federation of the Finnish higher education Service ProviderIdentity Provider (Home university) National Library portal Institutiona Library Management Systems Learning Management System (Moodle etc) ASP/SaaS services in university administration U of Turku U of Helsink etc UAS of Turk U of Tamper UAS of Hels  Identity Provider maintains the end user’s identities (identifiers, roles and other attributes)  Identity Provider authenticates an end user  Identity Provider release end user’s attributes to the service provider  Based on the attributes, the Service Provider decides what kind of services the user is authorised to use IdP CSC’s services to researchers (HPC, grids) SP

Relying on the REMS access rights Identity Provider Service Provider Identity Provider Service Provider REMS Attribute Provider REMS IdP proxy attributes attributes + entitlements attributes entitlements (a) External attribute provider(b) IdP proxy (c) Or a custom REMS integration

Identity Federations in Europe

Federated identity + workflow = REMS Basic idea of REMS is to –replace paper based application process with an automated tool –build on top of federated identity to avoid unnecessary and error prone manual maintenance work of user information

Resource entitlement management system (REMS) Access to research datasets 0. Fully public access 1. Researcher has a role/group membership –IdP managed/VO-managed 2. Researcher commits to datasets’ licence terms 3. Researcher fills in and submits an application - Dataset owner approves/rejects Or any combination of 1, 2 and 3.

Principal investigator Applicant Research group Members of the application The REMS concept Metadata on dataset 1&2 Dataset 1 Dataset 2 DAC 1 Approver DAC 2 Approver REMS Workflow Reports Entitlements IdP SP 1. Apply for access 4. Approve 5. Access 3. Circulate to approver 2. Commit to licence terms

CASE: Finnish Social Science Data Archive

CASE: process for applying access to the Nordic Control Database

Benefits of REMS Reduces throughput times of the application process Provides easier reporting/audit tools for owners of the resource and the applicant Increases information security also by relying on end users’ home institutions usernames/passwords and federated authentication

The REMS implementation Created originally in the ELIXIR ESFRI project –Academy of Finland and Ministry of Education and Culture via CSC) e.g. NOT EU FP7, EMBL etc. ELIXIR Finland hosted at CSC offers REMS as a service for biomedical data hosting services in ELIXIR Discipline-independent A Java portlet on Liferay, using Vaadin framework Open source (LGPL)

Work-in-progress Development UI improvements, vulnerability tests, documentation, publish the code, bug fixes and feature requests Operations maintenance, support, helpdesk Deployment new: FSD, TTA, LBR extend: EGA, biobanking

REMS DEMO

REMS = TAAS? 1.Accredited institution = Identity federation? 2.Requestor’s affiliation = Identity federeration (affiliation = ”faculty”) 3.Application must be approved = REMS

Links REMS Identity federation