1 The Partnership Challenge Higher education’s missions are realized in increasingly global, collaborative, online relationships –Higher educations’ digital.

Slides:



Advertisements
Similar presentations
The Art of Federations. Topics Federations of what… Federated identity versus federations Federations in other sectors – business, gov, ad hoc R&E Federations.
Advertisements

National Institutes of Health U.S. Department of Health and Human Services The PEPH Resource Center: A New, More Convenient Login.
1 Leveraging Your Existing Campus Systems to Access Resource Partners: Federated Identity Management and Tales of Campus Participation EDUCAUSE 2006 October.
1 The Challenges of Creating an Identity Management Infrastructure for the University of California David Walker Karl Heins Office of the President University.
HATHITRUST A Shared Digital Repository HathiTrust current work, challenges, and opportunities for public libraries Creating a Blueprint for a National.
HATHITRUST A Shared Digital Repository HathiTrust: A Second Life for Library Collections Jeremy York Exploring Humanities Cyberinfrastructure April 30,
Federated Access: Identity Management and Access to Protected Resources Renée Woodten Frost Associate Director, Middleware & Security
Federations in Texas Barry Ribbeck University of Texas Health Science Center at Houston.
HATHITRUST A Shared Digital Repository A Preservation Infrastructure Built to Last: Preservation, Community, and HathiTrust UNESCO Memory of the World.
David L. Wasley Information Resources & Communications Office of the President University of California Directories and PKI Basic Components of Middleware.
Some Frontier Issues from the Wild, Wild West Ken Klingenstein.
1 eAuthentication in Higher Education Tim Bornholtz Session #47.
Information Resources and Communications University of California, Office of the President Current Identity Management Initiatives at UC & Beyond: UCTrust.
Information Resources and Communications University of California, Office of the President UCTrust Implementation Experiences David Walker, UCOP Albert.
InCommon and Federated Identity Management 1
The Business of Identity Management Barry R. Ribbeck Director Systems Architecture & Infrastructure Rice University
EAuthentication in Higher Education Tim Bornholtz Session 58.
InCommon Policy Conference April Uses  In order to encourage and facilitate legal music programs, a number of universities have contracted with.
Lightning Round of Innovative Work and Projects Copyright Joann Martyn, Joyce Esterman, Tracy Mitrano, Mark D. Strandskov, Tobias Nownes, Jacques Du Plessis,
Collaboration & InCommon EDUCAUSE Midwest Regional Conference March 21, 2005 Carrie E. Regenstein UW-Madison.
1 Update on the InCommon Federation, Higher Education’s Community of Trust EDUCAUSE 2005 October 19 10:30am-11:20am.
Updates on Shib, a bit of InCommon and International Federations.
1 Leveraging Your Existing Campus Systems to Access Resource Partners: Federated Identity Management and Tales of Campus Participation Clair Goldsmith,
HATHITRUST A Shared Digital Repository HathiTrust Past, Present, and Future A Brief Introduction.
Federations and Security: A Multi-level Marketing Scheme Ken Klingenstein Director, Internet2 Middleware and Security.
CILogon and InCommon: Technical Update Jim Basney This material is based upon work supported by the National Science Foundation under grant numbers
HATHITRUST A Shared Digital Repository HathiTrust: Putting Research in Context HTRC UnCamp September 10, 2012 John Wilkin, Executive Director, HathiTrust.
The InCommon Federation The U.S. Access and Identity Management Federation
IAMOhio: OARnet’s Trusted Identity Federation Internet2 Fall Member Meeting 2012 Philadelphia, PA Mark Beadles Program Manager, IAMOhio Federation
1 The InCommon Federation John Krienke Internet2 Spring Member Meeting Tuesday, April 25, 2006.
The Rise of Federations…Almost Everywhere. Topics Federation Basics Drivers Components International and pulic sector developments InCommon and its uses.
Federations: success brings new challenges Ken Klingenstein Director, Internet2 Middleware and Security.
Single Sign-On Multiple Benefits via Alaska K20 Identity Federation 20 May 2011 BTOP Partner Meeting Anchorage, Alaska 20 May 2011 BTOP Partner Meeting.
Exploring InCommon Getting Started with InCommon: Creating Your Roadmap.
Internet2 – InCommon and Box Marla Meehl Colorado CIO 11/1/11.
InCommon, other federations, the attribute ecosystem, and some killer apps needing guns…
Identity Federations: Here and Now Renée Shuey Penn State and InCommon.
HATHITRUST A Shared Digital Repository HathiTrust and TRAC DigitalPreservation 2012 July 25, 2012 Jeremy York, Project Librarian, HathiTrust.
1 InCommon Identity & Access Management Federation John Krienke Operations Manager, InCommon Assistant Director, Internet2
Federations 101 John Krienke Internet2 Fall 2006 Internet2 Member Meeting.
HATHITRUST A Shared Digital Repository HathiTrust and the Future of Research Libraries American Antiquarian Society March 31, 2012 Jeremy York, Project.
Internet2: building and using an advanced network environment for research, teaching and learning APRU CIO Forum, 23 March 2007 Heather Boyles,
The InCommon Federation The U.S. Access and Identity Management Federation
State of e-Authentication in Higher Education August 20, 2004.
E-Authentication in Higher Education April 23, 2007.
University of Washington Identity and Access Management IEEAF – RENU Network Design Workshop Seattle - 29 Nov 2007 Lori Stevens, Director, Distributed.
HATHITRUST A Shared Digital Repository Institution Uses of HathiTrust Jeremy York University of Maine May 24, 2013.
Shibboleth: Molecules, Music, and Middleware. Outline ● Terms ● Problem statement ● Solution space – Shibboleth and Federations ● Description of Shibboleth.
Federated Identity Management at NIH…NIH Login and Beyond Debbie Bucci September 2009.
1 E-Authentication and Web Services Charlie Miller, RIHEAA.
E-Authentication & Authorization Presentation to the EA2 Task Force March 6, 2007.
AAI in Europe ++ Ken Klingenstein Director, Internet2 Middleware and Security.
Transforming Government Federal e-Authentication Initiative David Temoshok Director, Identity Policy and Management GSA Office of Governmentwide Policy.
Project Presentation to: The Electronic Access Partnership July 13, 2006 Presented by: Tim Cameron, Meteor Project Manager The.
University of Washington Collaboration: Identity and Access Management Lori Stevens University of Washington October 2007.
Identity Federations: Here and Now David L. Wasley Thomas Lenggenhager Peter Alterman John Krienke.
Federations: The New Infrastructure Speaker Name Here Date Here Speaker Name Here Date Here.
Identity Management, Federating Identities, and Federations November 21, 2006 Kevin Morooney Jeff Kuhns Renee Shuey.
InCommon® for Collaboration Institute for Computer Policy and Law May 2005 Renee Shuey Penn State Andrea Beesing Cornell David Wasley Internet 2.
HATHITRUST A Shared Digital Repository HathiTrust Large Digital Libraries: Beyond Google Books Modern Language Association January 5, 2012 Jeremy York,
INTRODUCTION: THE FIRST TRY InCommon eduGAIN Policy and Community Working Group.
NMI-EDIT and Rice University Federated Identity Management: Managing Access to Resources in Texas Barry Ribbeck Director System Architecture and Infrastructure.
SEPARATE ACCOUNTS FOR PROSPECTS? WHAT A HEADACHE! Ann West Assistant Director, InCommon Assurance and Community Internet2 at Michigan Tech.
HathiTrust: A valuable and visionary Partnership.
Tom Barton, Senior Director for Integration, University of Chicago
Faculty Salary Study Comparison to AAU Data Exchange Institutions
John O’Keefe Director of Academic Technology & Network Services
Shibboleth as Attribute Delivery for Authorization
Updates on Shib, a bit of InCommon and International Federations
Presentation transcript:

1 The Partnership Challenge Higher education’s missions are realized in increasingly global, collaborative, online relationships –Higher educations’ digital collections, data, and resources –External services and resource partners How many relationships do you manage? How much time is spent on the differing, one-off requirements for each partner? How much risk do these one-off implementations bring to your network, to the control of private data?

2 The Partnership Solution Wouldn’t it be great if we could: developed and implemented solutions that efficiently use our existing information infrastructures securely and safely InCommon economizes the time and resources that otherwise would be spent on the differing “one off” requirements for each individual partner deal with each partner in the same way; saving time and reducing risk InCommon maximizes security and privacy of personally identifiable/sensitive information richer, easier to use, safer online experience for Penn State students, faculty, and staff.” securely and safely in such a way that we maintain control over the release of personal information for people This is what federations are created to do

3 Identity Management Federations aka Access Management Federations A definition of Federation: A collaboration of independent entities that give up a certain degree of autonomy to a central authority in pursuit of a common set of goals. Identity Management Federations set common policies, technical interoperability criteria, and provide central services to establish and maintain trust (Central Authority) Identity Management Federations enable scalable, trustworthy, secure online partnerships (Common Goals)

4 Attributes: Anonymous ID, Staff, Student, … Online Resource Federated Access in 30 seconds Home Institution Metadata, certificates, common attributes & meaning, federation registration authority, Shibboleth, pinch of magic 4. If attributes are acceptable, access is granted! 3. Authorization: Privacy- preserving exchange of agreed upon attributes 2. Federation-based Trust exchange to verify partners and locations 1. Authentication: Single- Sign-On to existing Home Institution

5 The Value of InCommon Broadly Put Identity Providers (Home Institutions) control user accounts and the release of personal information Online services get to focus maintaining online resources – and standards-based access controls to them – and not on user account management Partners can quickly and securely deploy new collaborations and service relationships

6 The Value of InCommon Finely Put Governance by a Representative Steering Committee –Formulates policy and shared direction –Ensures services meet business needs with appropriate security levels and legal requirements –Establishes and communicate scalable operational standards and practices –Establishes a common set of attributes and definitions Legal Agreement –Basic Responsibilities, Official Signatory and Establishment of Trust, Conflict and Dispute Resolution, Basic Protections Trust “Notary” –InCommon verifies the identity of organizations and their delegated officers; Trusted Metadata –InCommon verifies & aggregates security information for each participant’s servers, systems, and support contacts Certificate Authority –InCommon issues server certificates to Participants for secure communications Standards for Policies and Practices –How high is the bar? Right now, each Participant decides. Participants self-declare their practices to other Participants Technical Interoperability (Technical Advisory Committee) –InCommon defines shared attributes, standards (SAML), software (Shibboleth)

7 Internet2 InCommon Governance Federation Operator & Business Office Federation Operator & Business Office Technical Advisory Committee Technical Advisory Committee Nominations Committee Nominations Committee Steering Committee Representative of Higher Ed & its Partners Steering Committee Representative of Higher Ed & its Partners Direction Candidate Approvals Advice

8 45 Current InCommon Participants Case Western Reserve University Clemson University Cornell University Dartmouth Duke University Florida State University Georgetown University Indiana University Miami University Michigan State University New York University Ohio University Penn State University Stanford University Stony Brook University SUNY Buffalo Texas A&M University The Ohio State University The University of Chicago The Johns Hopkins University University of Alabama at Birmingham Uniuversity of California, Davis University of California, Irvine University of California, Los Angeles University of California, Merced University of California, Office of the President University of California, Riverside University of California, San Diego University of Maryland University of Maryland Baltimore County University of Maryland, Baltimore University of Rochester University of Southern California University of Virginia University of Washington University of Wisconsin - Madison Cdigix EBSCO Publishing Elsevier ScienceDirect Houston Academy of Medicine - Texas Medical Center Library Internet2 JSTOR Napster, LLC OCLC OhioLink - The Ohio Library & Information Network ProtectNetwork RefWorks, LLC Symplicity Corporation Thomson Learning, Inc. Turnitin WebAssign NEXT? U.S. eAuthentication Federation and Agencies: –NSF (FastLane, …) –NIH (Grants Administration, …) –Dept. of Education (Student Financial Aid, …) Federations within the InCommon Federation –University Systems –Coalitions of Universities organized around Networks, Grids, others… Higher Education (36) Sponsored Partners (15)