14-Nov-05 JISC Core Middleware Meeting 1 Middleware Initiatives in Australia Alex Reid Director, eResearch/Middleware, AARNet.

Slides:



Advertisements
Similar presentations
Linking research & learning technologies through standards June Handle Workshop Towards a National Persistent Identifier Infrastructure Handle.
Advertisements

Kento Aida, Tokyo Institute of Technology Grid Working Group Meeting Aug. 27 th, 2003 Tokyo Institute of Technology Kento Aida.
September, 2005What IHE Delivers 1 Key Image Notes Evidence Documents Simple Image & Numeric Report Access to Radiology Information IHE Vendors Workshop.
Lousy Introduction into SWITCHaai
MICS4 Survey Design Workshop Multiple Indicator Cluster Surveys Survey Design Workshop MICS4 Technical Assistance.
ASYCUDA Overview … a summary of the objectives of ASYCUDA implementation projects and features of the software for the Customs computer system.
Cario, April, 18th 2005 Dr. Roland M. Wagner SDI NRW Joint Project 2004: Identification of enhanced SDI elements Dr. Roland M. Wagner
© Copyright International Telecommunication Union (ITU). All Rights Reserved page - 1 Alexander NTOKO Project Manager, ITU Electronic Commerce.
ActionDescription 1Decisions about planning and managing the coast are governed by general legal instruments. 2Sectoral stakeholders meet on an ad hoc.
What is valorisation ? Growth €
The Managing Authority –Keystone of the Control System
An open source approach for grids Bob Jones CERN EU DataGrid Project Deputy Project Leader EU EGEE Designated Technical Director
Grid Initiatives for e-Science virtual communities in Europe and Latin America The VRC-driven GISELA Science Gateway Diego Scardaci.
© ITU Telecommunication Development Bureau (BDT) – E-Strategy Unit.. Page - 1 Seminar on Standardization and ICT Development for the Information.
1 ABCs of PKI TAG Presentation 18 th May 2004 Paul Butler.
Public B2B Exchanges and Support Services
1 NECOBELAC Project WORK PACKAGE 3 Cross-national advocacy infrastructure.
Joint Information Systems Committee 01/04/2014 | | Slide 1 Connecting People to Resources The JISC Access Management Strategy Nicole Harris Programme Manager.
PERSEUS : Portal-enabled Resources via Shibbolized End-user Security 16 May 2005JISC Core Middleware Programme Meeting, Loughborough 1 PERSEUS Project.
Joint Information Systems Committee 01/04/2014 | slide 1 Support e-Research at JISC Access Management and Security Joint Information Systems CommitteeSupporting.
Supporting further and higher education The JISC FAIR Programme and International E-theses Developments.
Next Generation Athens Services Ed Zedlewski UK e-Science Town Meeting, London, 11 April 2005.
Collection-level description & collection management: tool for the trade or information trade-off? Collection Description Focus Workshop 4 Newcastle, 8.
UKOLN is supported by: JISC Information Environment update Repositories and Preservation Programme meeting, October 24-25, 2006 Rachel Heery UKOLN
Collection-level description & the Information Landscape: users evaluate strategies for resource discovery Collection Description Focus Workshop 5 Cambridge,
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
Multiple Indicator Cluster Surveys Survey Design Workshop MICS Technical Assistance MICS Survey Design Workshop.
Access management: challenges and approaches James Dalziel Adjunct Professor and Director Macquarie E-learning Centre of Excellence
Introducing the Macquarie E-learning Centre of Excellence (MELCOE) James Dalziel Adjunct Professor and Director
Korkeakoulujen arviointineuvosto — Rådet för utvärdering av högskolorna — The Finnish Higher Education Evaluation Council (FINHEEC) eLearning and Virtual.
European Clearing-House Mechanism Portal Toolkit Expert Group Meeting
- 1 - Defense Security Service Background: During the Fall of 2012 Defense Security Service will be integrating ISFD with the Identity Management (IdM)
The Internet2 NET+ Services Program Jerry Grochow Interim Vice President CSG January, 2012.
Access management for repositories: challenges and approaches for MAMS James Dalziel Professor of Learning Technology and Director, Macquarie E-Learning.
Implementing Shibboleth-based Virtual Organisations and VO Federations using IAMSuite (including AAF update) James Dalziel & Alan Lin Professor of Learning.
Copyright AARNet Australia’s e-Research Infrastructure IGRID - 27 September 2005 George McLaughlin International Developments, AARNet Enhancing Global.
Joint Information Systems Committee 19/05/2015 | | Slide 1 Connecting People to Resources The UK Access Management Federation Nicole Harris Programme Manager.
Joint Information Systems Committee 19/05/2015 | | Slide 1 Voyage of the UK JISC Federation: Shibbolising the UK’s Research, Higher and Further Education.
An Overview of eResearch Activities in Australia Paul Davis, GrangeNet Jane Hunter, Uni of Qld.
David L. Wasley Information Resources & Communications Office of the President University of California Directories and PKI Basic Components of Middleware.
Alex Reid, AARNet Australia Middleware Update; 16-Oct-06 Middleware in Australia - Update TF-ECM2 Malaga 16-Oct-06 Alex Reid Director, eResearch/Middleware.
16/3/2015 META ACCESS MANAGEMENT SYSTEM Implementing Authorised Access Dr. Erik Vullings MAMS Programme Manager
Thee-Framework for Education & Research The e-Framework for Education & Research an Overview TEN Competence, Jan 2007 Bill Olivier,
Copyright JNT Association 20051OptionalCopyright JNT Association 2007 Overview of the UK Access Management Federation Josh Howlett.
1 The Australian Partnership for Sustainable Repositories Margaret Henty Digital Futures Industry Briefing November 8, 2006.
Australian Partnership for Sustainable Repositories AUSTRALIAN PARTNERSHIP FOR SUSTAINABLE REPOSITORIES Caul Meeting 2005/2 Brisbane 15.
Geoff Payne ARROW Project Manager 1 April Genesis Monash University information management perspective Desire to integrate initiatives such as electronic.
Introduction to Secure Messaging The Open Group Messaging Forum April 30, 2003.
Australian Access Federation and other Middleware Initiatives Presented at TF-EMC2, Prague 4 Sep 2007 Patty McMillan, The University of Queensland.
Federated Identity Management for HEP David Kelsey WLCG GDB 9 May 2012.
1 EAP and EAI Alignment: FiXs Pilot Project December 14, 2005 David Temoshok Director, Identity Policy and Management GSA Office of Governmentwide Policy.
Towards a European network for digital preservation Ideas for a proposal Mariella Guercio, University of Urbino.
Neil Witheridge APAN29 Sydney February 2010 ARCS Authorisation Services Neil Witheridge Manager, ARCS Authorisation Services APAN29, Sydney, February 2010.
Oxford University e-Science Centre 1 Managing Access 4 Dec Managing Access to Resources on the Grid 4 December 2002.
Leveraging Campus Authentication for Grid Scalability Jim Jokl Marty Humphrey University of Virginia Internet2 Meeting April 2004.
Information Infrastructure Evolution ARIIC is working towards – a distributed electronic research environment that allows researchers to share, annotate,
The DEER The Distributed European Electronic Resource.
The UK Access Management Federation John Chapman Project Adviser – Becta.
Federated Identity Management for HEP David Kelsey HEPiX, IHEP Beijing 18 Oct 2012.
G É ANT2 Development Support Activity and the Republic of Moldova 1st RENAM User Conference Chisinau, Republic of Moldova 14-May-2007 Valentino Cavalli.
19-Sep-05 Alex Reid: Australian Middleware 1 Middleware Picture in Australia Alex Reid Director, eResearch/Middleware, AARNet.
MAPS Middleware Action Plan & Strategy Project Middleware Action Plan & Strategy Project (MAPS) Patricia McMillan, Project Manager.
126/02/2016 META ACCESS MANAGEMENT SYSTEM A Ship on the Grid – Interoperability between Shibboleth and the Grid – Dr. Erik Vullings Programme Manager Macquarie.
INTRODUCTION TO IDENTITY FEDERATIONS Heather Flanagan, NSRC.
Authentication and Authorisation for Research and Collaboration Taipei - Taiwan Mechanisms of Interfederation 13th March 2016 Alessandra.
Bob Jones EGEE Technical Director
SWIM Common PKI and policies & procedures for establishing a Trust Framework                           Kick-off meeting Patrick MANA Project lead 29 November.
HIMSS National Conference New Orleans Convention Center
Australia's National Information Infrastructure for Research Markus Buchhorn Director, ICT Environments, The Australian National University (and APAC,
Presentation transcript:

14-Nov-05 JISC Core Middleware Meeting 1 Middleware Initiatives in Australia Alex Reid Director, eResearch/Middleware, AARNet

14-Nov-05JISC Core Middleware Meeting 2 Contents Australian Research Infrastructure Government Initiatives NREN Middleware Strategy MAMS PKI Project eduroam

14-Nov-05JISC Core Middleware Meeting 3 National Research Infrastructure Backing Australias Ability – An Innovation Action Plan for the Future 2001/2004: $3 billion over 5 years from $5.3 billion over 7 years from Systemic Infrastructure Initiative (SII) to upgrade research infrastructure at Australian universities: $246m over 5 years from to $542m over 6 years from to HEBAC (Higher Education Bandwidth Advisory Committee) ARENAC (Australian Research and Education Network Advisory Committee) orities/australian_research_and_education_network/arenac.htm orities/australian_research_and_education_network/arenac.htm HEIIAC -> ARIIC (Australian Research Information Infrastructure Committee) NRIT (National Research Infrastructure Task Force) search_infrastructure_taskforce_framework/default.htm search_infrastructure_taskforce_framework/default.htm NCRIS (National Collaborative Research Infrastructure Strategy) eResearch Coordinating Committee t.htm/ t.htm/

14-Nov-05JISC Core Middleware Meeting 4 Research Infrastructure Framework BAA $3b + $5.3b HEIIAC ARIIC FRODO $12m MERRI $19m HEBAC ARENAC NREN $70m NRIT NCRIS eRCC eResearch $??? SII $246m + $542m

14-Nov-05JISC Core Middleware Meeting 5 AARNet3 Components APL Tender for v3 of AARNet mid-2004 ARENAC $70m + APL own reserves National Backbone: own 2 fibre pairs across the country – deployed since 2004 at 10Gbps Regional Network: diverse routes, using DWDM, up to 320Gbps International Links: IRU on 2x 10Gbps fibres across the Pacific (SCCN) – PoPs in Seattle, LA Commodity connectivity in Australia & USA (Seattle, Palo Alto) Participate in TEIN2 – PoPs in Singapore & Frankfurt

14-Nov-05JISC Core Middleware Meeting 6 AARNet3 Infrastructure – National

14-Nov-05JISC Core Middleware Meeting 7 AARNet3 Infrastructure – Comparison

14-Nov-05JISC Core Middleware Meeting 8 AARNet3 Infrastructure – Global

14-Nov-05JISC Core Middleware Meeting 9 Place of Middleware Facilities, Services, Resources: Processing, Data Storage, Instruments, Electronic Information Local, Regional, National & International Network Infrastructure Authentication, Authorisation, Access, Accounting: PKI, Shibboleth, etc Knowledge Management, Resource Management, Collaboration Tools, Grid Services Applications, Human Interfaces Users Middleware: Application- independent; Resource- & Location-neutral

14-Nov-05JISC Core Middleware Meeting 10 Draft Middleware Action Plan Following National Forum Dec-04, a Draft Plan was agreed: Undertake an environmental scan. Establish a single PKI Certification Authority for R&E. Establish a sound basis for federated security systems in Australia that will scale to international federations. Establish appropriate mechanisms to coordinate all R&E Middleware initiatives in Australia. Agree to investigate adopting Shibboleth. Establish and sustain strong connections with relevant Australian initiatives/entities. Establish and strengthen overseas links. Promote the swift implementation of enterprise directory services at all Australian education and research institution. Develop strong visibility for and marketing of the Middleware agenda in Australia.

14-Nov-05JISC Core Middleware Meeting 11 Survey of Identity & Access Management Undertaken in May 2005 Establish State-of-Play at Australian universities Identify best practice, barriers to rapid implementation, authorisation requirements Goal is: –pervasive, federated infrastructure that integrates organisations internally while simultaneously allowing them to interoperate with others [Burton Group, 2002] 49% response (low, due to complexity) Currently: –Usernames/passwords, Same Sign-on, EZProxy, VPNs, LDAP, in- house integration Moving to: –Single Sign-on, automated integration (data feeds from corporate systems), Portals, PKI Barriers: –Resources, high risk to critical systems, lack of standards/guidance & training, coordinated middleware

14-Nov-05JISC Core Middleware Meeting 12 ARIIC Projects 1 st Round (FRODO) 22-Oct-03 ($12m): (Federated Repositories of Digital Objects) –MAMS (Meta Access Management System) $4.2m –ARROW (Australian Research Repositories Online to the World) –ADT (Australian Digital Theses Program Expansion) –APSR (Australian Partnership for Sustainable Repositories) 2 nd Round (MERRI) 22-Aug-05 ($19m): (Managed Environment for Research Repository Infrastructure) –MAPS –PKI/Shibboleth (operationalise the CAUDIT PKI Standards Project) –18 Others (mostly specific collections development/access & digitisation)

14-Nov-05JISC Core Middleware Meeting 13 ARIIC MERRI Grant – MAPS Announced by Minister 22-Aug-05 $582,910 granted Lead site: University of Queensland (Nick Tate) Supported by: CAUDIT, CAUL, Monash, ANU, Macquarie, AARNet, GrangeNet From now till end 2006 Purpose: –This project will identify the software and services (middleware) that are currently being used in Australia to link applications across a range of resources on networks and computer systems in Australian universities. The MAPS project will identify existing areas of activity in the university and research sectors, and use these results to tap into the expertise across the sector to build a strategic plan of activities and projects for an Australian collaborative middleware strategy. This is an important project whose outcomes will enable other projects to leverage off common infrastructure and focus on providing new services that can be shared across the education and research sectors.

14-Nov-05JISC Core Middleware Meeting 14 MAPS Activities Goal: Agreed Strategy for Middleware Deployment and Development (note the 2 strands) Project Manager Steering Committee, Reference Group, Kick-off Forum Wide consultation: committees, forums, wikis, mailing lists, Website Environmental Scan/Stocktake (local and global) Analysis of findings, development of draft Strategy Expert Reports Round-Table Finalisation of Strategy Future Funding Proposals

14-Nov-05JISC Core Middleware Meeting 15 Existing Middleware Activity APAC Grid ( ) Nimrod-G ( ) CAUDIT-PKI ( 4/ref/CAUDIT%20PKI%20Standards%20Proposal%20-%20V5.doc ) 4/ref/CAUDIT%20PKI%20Standards%20Proposal%20-%20V5.doc AARLIN ( ) DEST/JISC e-Framework eduroam Emerging developers, end users, identity providers, service providers MAMS ( ): –Developing hands-on technical/policy experience with Shibboleth within the community –Test Shibboleth federation is being established, including a WAYF server –Scouting for suitable test IdPs and SPs

14-Nov-05JISC Core Middleware Meeting 16 MAMS – Broad Goals Meta-Access Management System Addressing the Authentication, Authorisation, Identity, Single- Sign-On, Federation, Trust, Security, Digital Rights and Automated Access Policy Cluster of Problems!! Iterative demonstrations to help drive the gathering of user requirements Development of common services prototypes –Intra-institutional multi-modal SSO –Inter-institutional access management Attribute exchange (Shibboleth) Automation of policy –Federated and extensible identity –Other common services: DRM, search, metadata Implementation advice and programs

14-Nov-05JISC Core Middleware Meeting 17 MAMS Next Steps Shibbolise Fedora, Dspace repository systems Add Shib to test environments at NLA, APSR, … Organise install-fests (SSO workshop) & roadshows Offer support (CMS, forum, mailing-list, FAQs) Start an Australian Federation: –3 levels: Test-Fed (sand pit); OZFed (identity verification); Legal (technically = OZFed, but formal agreement like InCommon) Integrate cross-domain SSO with institutional SSO Integrate with desktop SSO (Kerberos) Integrate XACML into SAML Develop plug-ins for legacy systems Develop ARP manager (Sharpe) & provisioning tools Easy installation packages (Shib+WebISO) Virtual Organisation (client & server) packages Offer policy & legal documents, etc…

14-Nov-05JISC Core Middleware Meeting 18 MAMS ARP Editor – Sharpe Manage SP: - Add & Delete SPs Manage Attribute Mapping: - Create, Edit, Copy (clone), Delete Mapping Sets Manage SP Contracts: - Create, Edit, Delete SP Contracts Manage User Contracts: - Create, Edit, Delete User Contracts

14-Nov-05JISC Core Middleware Meeting 19 CAUDIT PKI Project The CAUDIT PKI Project involves developing a single national PKI standards framework for HE & Research, including: –Certification Authority (CA) –Registration Authorities (RA) – 50+ –Certificate Policy (CP) –Certification Practice Statement (CPS) –Able to scale to 1 million clients Initially built purely for test/trial purposes: –not evolve into a production service model; –only survive until late 2005; –support 4 levels of assurance; –support cross-certification; –support embedding in web browsers (positive Microsoft discussions); –support signed s.

14-Nov-05JISC Core Middleware Meeting 20 CAUDIT PKI Project Certification Levels Certificate Level Description Level 1 No proactive identity check has been provided to the RA. However identity information has been provided by a body that the RA has a trust relationship. Example: A student being enrolled in at least one subject is sufficient for the certificate issuing however identity information has only been supplied by QTAC (or similar state body). Level 2 Subject is required to provide proof of identity by an in-person appearance to the RA. However the individual for what ever reason can not provide the required 100 points of identification. Example: A contractor, who is at an institution for a short time but needs access to a system protected by PK, may not have enough credentials on her person to meet the 100 points check but can provide some credentials like a drivers licence and/or credit card. Level 3 Subject is required to provide proof of identity by an in-person appearance to the RA. That proof should accrue to at least 100 points of identity. Example: A foreign staff member that has a valid passport and has a written reference from an acceptable referee. Level 4 Subject is required to provide the same information for Level 3 certification in addition to a positive check to be conducted by an appropriate external agency.

14-Nov-05JISC Core Middleware Meeting 21 PKI Trust Model AusCERT Root CA is trust anchor for the CAUDIT PKI Old CAs continue to work Cross-certifies with national, international and global PKIs (eg HEBCA) AusCERT will provide: –PMA –Directory of Directories –Single point Certificate Dissemination. –Single point CRL and OCSP. –Virtual CA for institutions that can t deploy own PKI PMA = Policy Mgt Authority; CMS = Cert Mgt System; CRL = Cert Revocation List; OCSP = Online Cert Status Protocol

14-Nov-05JISC Core Middleware Meeting 22 CAUDIT PKI Project Status Current Status: The AusCERT Root CA and the 4-Certification-Level CA have been set up and are issuing certificates. UQ has set up its 4 Institution Level CAs and is issuing end-entity certificates. Monash and Victoria Universities have set up their Institution Level CAs and issuing end-entity certificates; they are now heavily involved in client and CMS capability and interoperability studies with UQ and AusCERT. Certificate Policy/ Certification Practice Statement has been drafted and sent to participant universities for feedback. A few pilot sites have dropped out because they couldn't supply the necessary resources; the others have also had resourcing issues but are soldiering on. Final Report submitted October Next Step is to turn it into a production system, and establish close ties with Shibboleth (authorisation elements) – this has been funded as part of MERRI

14-Nov-05JISC Core Middleware Meeting 23 eduroam Being undertaken jointly by AARNet & GrangeNet 17 members signed up Deploy eduroam in AARNet offices & staff Write and seek endorsement for national eduroam policies (ratification by CAUDIT imminent) Promote and participate in eduroam developments within the APAN region Participate in eduroam global working group See

14-Nov-05JISC Core Middleware Meeting 24 Global Middleware Involvement Europe –Close co-operation with JISC, Terena and European NRENs on eduroam & other Middleware activities Americas –Working on eduroam and Shibboleth activities APAN (Asia-Pacific Area Network) –Taking responsibility for advancing Middleware awareness/agenda within APAN –APAN Middleware mailing list –APAN Middleware stream for Jan 2006 Tokyo APAN meeting Global –Convened eduroam global working group –Involved in general Middleware policy (eg Slaughter meeting) –Global Research & Education Federations mailing list (Refeds) –MACE/MICE participation

14-Nov-05JISC Core Middleware Meeting 25 END QUESTIONS??? For further information about Australian Middleware developments, see: Alex Reid James Sankar: