BoF: Federated Identity Management for Researchers David Kelsey (STFC-RAL) TNC2014, Dublin 20 May 2014.

Slides:



Advertisements
Similar presentations
Federated Identity Management for Research Communities: FIM 4 R CSC, Helsinki 2 nd October 2013 Bob Jones, CERN.
Advertisements

Federated Identity Management for Researchers – A quick overview from GÉANT BoF TNC May 2014 Dublin.
Innovation through participation GÉANT Data Protection Code of Conduct (DP CoC) FIM for research collaboration workshop Mikael Linden,
Federated Identity Management for Research Communities (FIM4R) David Kelsey (STFC-RAL) EGI TF, AAI workshop 19 Sep 2012.
WLCG Security TEG, risks and Identity Management David Kelsey GridPP28, Manchester 18 Apr 2012.
Credential Provider Operational Practices Statement CAMP Shibboleth June 29, 2004 David Wasley.
FIM-ig Federated Identity Management Interest Group.
Security Incident Response Trust Framework for Federated Identity (Sir-T-Fi) David Kelsey (STFC-RAL) REFEDS, Indianapolis 26 Oct 2014 and now abbreviated.
Trust and Security for FIM (Sirtfi/SCI) David Kelsey (STFC-RAL) FIM4R at CERN 4 Feb 2015.
Federated Identity Management in New Zealand Sat Mandri Service Manager TNC15 REFEDs Meeting, 14 th June 2015.
Authentication and Authorization in a federated environment Jules Wolfrat (SARA)
AARC Overview Licia Florio, David Groep 21 Jan 2015 presented by David Groep, Nikhef.
The ReFEDS/GÉANT Code of Conduct (CoC) An Approach to Compliance with the EU Data Protection Directive Steve Carmody April 23, 2012.
Sirtfi David Kelsey (STFC-RAL) REFEDS at TNC15 14 June 2015.
Climate Sciences: Use Case and Vision Summary Philip Kershaw CEDA, RAL Space, STFC.
Federated Identity Management for HEP David Kelsey WLCG GDB 9 May 2012.
Connect communicate collaborate GÉANT3plus Enabling Users Pilots Lukas Hämmerle Task Leader "Enabling Users"
Belnet Federation Belnet – Loriau Nicolas Brussels – 12 th of June 2014.
Authentication and Authorisation for Research and Collaboration Licia Florio (GÉANT) Christos Kanellopoulos (GRNET) Service orientation.
Federated Identity Management for Research Communities (FIM4R) David Kelsey (STFC-RAL) EGI CF, FIM workshop 11 Apr 2013.
7 th FIM 4 R meeting April 2014 ESRIN Frascati.
EResearchers Requirements the IGTF model of interoperable global trust and with a view towards FIM4R AAI Workshop Presenter: David Groep, Nikhef.
Federated Identity Management for Research Collaborations Bob Jones, CERN Daan Broeder, Max-Planck Institute for Psycholinguistics David Kelsey, Particle.
Authentication and Authorisation for Research and Collaboration Licia Florio REFEDS Meeting The AARC Project I2 Technology Exchange.
Authentication and Authorisation for Research and Collaboration Licia Florio AARC Workshop The AARC Project Brussels, 26 October.
Authentication and Authorisation for Research and Collaboration David Kelsey AARC AHM Milan And mechanisms NA3 Task 4 – Scalable.
Authentication and Authorisation for Research and Collaboration Peter Solagna Milano, AARC General meeting Current status and plans.
Federated Identity Management for HEP David Kelsey STFC – RAL Nijmegen workshop 22 June 2012.
Federated Identity Management for HEP David Kelsey HEPiX, IHEP Beijing 18 Oct 2012.
Authentication and Authorisation for Research and Collaboration Christos Kanellopoulos Open Day Event: Towards the European Open.
WLCG Authentication & Authorisation LHCOPN/LHCONE Rome, 29 April 2014 David Kelsey STFC/RAL.
Federated Identity Management for Scientific Collaborations The Common Vision David Kelsey (STFC) 3 Nov 2011.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
Networks ∙ Services ∙ People Thomas Bärecke Journée Fédération, Paris Collaboration européenne GÉANT SA5 03/07/2015 SA5 T5 team
Federated Identity Management How do we proceed? Bob Jones, CERN.
Research Community Requirements Ann Harding, SWITCH Cambridge July 2014.
Authentication and Authorisation for Research and Collaboration Taipei Taiwan Authentication and Authorisation for Research and.
Authentication and Authorisation for Research and Collaboration Licia Florio REFEDS Meeting AARC and AARC2 Vienna, 1 st December.
Case Studies in Federated Identity Management for Research Communities Ann Harding, SWITCH/GN3plus Peter Gietz, DAASI International GmbH/DARIAH Tommi Nyro.
Connect communicate collaborate Case Studies in Federated Identity Management for Research Communities Ann Harding, SWITCH/GN3plus Peter Gietz, DAASI International.
David Groep Nikhef Amsterdam PDP & Grid AARC Authentication and Authorisation for Research and Collaboration an impression of the road ahead.
Federated Identity Management for Research Communities: FIM4R PSI workshop objectives Bob Jones, CERN.
Networks ∙ Services ∙ People Licia Florio TNC, Lisbon Consuming identities across e- Infrastructures 16 June 2015 PDO GÈANT.
Authentication and Authorisation for Research and Collaboration Licia Florio AARC CORBEL Workshop The AARC Project Paris, 31 May.
Authentication and Authorisation for Research and Collaboration Christos Kanellopoulos David Groep 9 th FIM4R Meeting The AARC Project.
Authentication and Authorisation for Research and Collaboration David Kelsey AARC AHM Utrecht NA3 Task 4 – Scalable Policy Negotiation.
Authentication and Authorisation for Research and Collaboration AARC/CORBEL Workshop for Life Sciences AAI AARC Draft Blueprint.
Authentication and Authorisation for Research and Collaboration Licia Florio IGTF Meeting The AARC Project Amsterdam, 8 September.
Research Community Requirements (FIM4R) David Kelsey (STFC-RAL) VAMP Workshop 6 Sep 2012.
SCI & Sirtfi David Kelsey (STFC-RAL) EGI Conference, Lisbon 19 May 2015.
Security Incident Response Trust Framework for Federated Identity (Sir-T-Fi) David Kelsey (STFC-RAL) REFEDS, Indianapolis 26 Oct 2014.
Welcome to 11th FIM4R 11th Meeting, Montréal September 2017
WLCG Update Hannah Short, CERN Computer Security.
Boosting AAI for research and collaboration
The Policy Puzzle Many groups and (proposed) policies, but leaving many open issues AARC “NA3” is tackling a sub-set of these “Levels of Assurance” –
EGI Updates Check-in Matthew Viljoen – EGI Foundation
AARC Update What’s been happening in AARC which matters for GÉANT
User Community Driven Development in Trust and Identity
Case Studies in Federated Identity Management for Research Communities
Federated Identity Management for Researchers (FIM4R)
Federated Identity Interest Group
EGI Security Policy Update
Update on FIM4R David Kelsey
Boosting AAI for research and collaboration
Federated Identity Management for Scientific Collaborations
The AARC Project Licia Florio (GÉANT) Christos Kanellopoulos (GRNET)
The AARC Project Licia Florio AARC Coordinator GÉANT
AARC Blueprint Architecture and Pilots
AAI Architectures – current and future
FIM4R Requirements where GN3+ (SA5) is Active and Involved (9/2013)
Presentation transcript:

BoF: Federated Identity Management for Researchers David Kelsey (STFC-RAL) TNC2014, Dublin 20 May 2014

Background There has been growing collaboration between Research Communities and Federations Good progress being made –Requirements documented by FIM4R –Joint pilot projects underway –work being done in REFEDS/GEANT/eduGAIN A response to the Horizon 2020 AAI call is being worked on 20 May 14FIM for Researchers, Kelsey2

Aims of BoF Share information on recent work/future plans Where are we with planning a submission to the H2020 AAI call? Encourage ongoing discussions between Research Communities and Federations No full presentations - this has been done before at TNC & REFEDS & FIM4R 20 May 14FIM for Researchers, Kelsey3

Speakers User Communities FIM4R pilot projects –Ann Harding/SWITCH AAI in Dariah –Peter Gietz/DAASI International GmbH Federations and Providers REFEDS/Geant/eduGAIN –Licia Florio/TERENA EUDAT (remote) –Jens Jensen/STFC IGTF evolution –David Groep/Nikhef Other input FIM and Security/Trust –Romain Wartel/CERN Evolution of IdM architecture –Bob Cowles/BrightLite Information Security FIM4R news –David Kelsey/STFC AAI H2020 plans –Licia Florio/TERENA 20 May 14FIM for Researchers, Kelsey4

FIM4R Update 20 May 14FIM for Researchers, Kelsey5

Federated IdM for Research (FIM4R) Includes photon & neutron facilities, social science & humanities, high energy physics, climate science, life sciences and ESA Aim: define common vision, requirements and best practices Vision and requirements paper published 20 May 14FIM for Researchers, Kelsey6

FIM4R Update Workshops started in June 2011 (CERN) Most recent (7 th ) was hosted by ESRIN in Frascati –23-24 April 2014 – 20 May 14FIM for Researchers, Kelsey7

7 th FIM 4 R meeting summary (slides of Bob Jones/CERN) April 2014 ESRIN Frascati

Meeting agenda Agenda page online with material: A written summary of this event will be produced FIM for Researchers, Kelsey20 May 149

The FIM 4 R Vision A common policy and trust framework for Identity Management based on existing structures and federations either presently in use by or available to the communities. This framework must provide researchers with unique electronic identities authenticated in multiple administrative domains and across national boundaries that can be used together with community defined attributes to authorize access to digital resources. FIM for Researchers, Kelsey Still valid though we may think to extend: lifetime of unique electronic identities to cover whole career of a researcher Common policy and trust framework also includes operations authorize access to digital resources may imply legal constraints Being able to estimate the cost of transition to FIM may be an indication of maturity 20 May 1410

Prioritisation of FIM 4 R requirements User friendliness (high) – Support for citizen scientists and researchers without formal association to research labs or univ Homeless-IdP tested in pilots Browser & non-browser federated access (high) Testing in Pilots Bridging communities (medium) – Bridging is a central issue with an efficient mapping of the respective attributes Not tested in Pilots Multiple technologies with translators including dynamic issue of credentials (medium) Testing in Pilots Implementations based on open stds and sustainable with compatible licenses (high) OpenID & SAML can interop. Different Levels of Assurance with provenance (high) – Credentials need to include the provenance of the level under which it was issued Testing in Pilots Authorisation under community and/or facility control (high) Testing in Pilots FIM for Researchers, Kelsey20 May 1411

Prioritisation of FIM 4 R requirements Well defined semantically harmonised attributes (medium) Limited success with subset of eduPerson but believe it is better to aim for consistency within a community Flexible and scalable IdP attribute release policy (medium) – Bi-lateral negotiations between all SPs and all IdPs is not a scalable solution Not Yet  Attributes must be able to cross national borders (high) – Data protection considerations must allow this to happen. Not Yet  Attribute aggregation for authorisation (medium) – Attributes need to be aggregated from different sources of authority including federated IdPs and community-based attribute authorities. Works for Active Directory Federation Services Privacy and data protection addressed with community-wide individual ids (medium) Testing in Pilots FIM for Researchers, Kelsey20 May 1412

Actions from this meeting As input for Terena H2020 AAI & GN4 proposals: – Each research community to provide by a short list of key commercial Service Providers (including cloud services) they would like to see integrated with eduGAIN [Deadline: end May] FIM for Researchers, Kelsey20 May 1413

Actions from this meeting (II) Consensus among FIM4R communities that: - Sufficient level of operation security is essential for inter-fed production services - Lack of minimal requirements for eduGAIN IdPs/SPs poses unacceptable risks - FIM4R should leverage the current practices based on existing efforts & expertise - The SCI work is relevant and could perhaps be extended to incorporate FIM Proposal: - FIM4R to jointly propose common operational security requirements for IdPs/SPs Action: - Romain/Dave to circulate the latest version of the SCI paper [mid May] - Romain/Dave to compose + propose a draft document: [end June] - Based on the SCI paper - In collaboration with Geant/eduGAIN (Leif Nixon/Leif Johansson) - FIM4R communities to give feedback and eventually endorse document Following the approach of the original FIM4R paper [feedback end August] FIM for Researchers, Kelsey20 May 1414

Actions from this meeting (III) Formulate RDA Working Group focused on extension of FIM4R pilots to USA partners and adoption of minimal set of security operations requirements for IdPs Schedule next FIM4R meeting in Amsterdam to coincide with RDA 4 th plenary (22-24 Sept 2014) [discuss common operational security requirements for IdPs/SPs] FIM for Researchers, Kelsey20 May 1415