Internet2: building and using an advanced network environment for research, teaching and learning APRU CIO Forum, 23 March 2007 Heather Boyles,

Slides:



Advertisements
Similar presentations
The Art of Federations. Topics Federations of what… Federated identity versus federations Federations in other sectors – business, gov, ad hoc R&E Federations.
Advertisements

1 Leveraging Your Existing Campus Systems to Access Resource Partners: Federated Identity Management and Tales of Campus Participation EDUCAUSE 2006 October.
Federated Digital Rights Management Mairéad Martin The University of Tennessee TERENA General Assembly Meeting Prague, CZ October 24, 2002.
Trends in Identity Management Nate Klingenstein Internet2 EDUCAUSE Security Professional 2007.
Federated Access: Identity Management and Access to Protected Resources Renée Woodten Frost Associate Director, Middleware & Security
2006 © SWITCH Authentication and Authorization Infrastructures in e-Science (and the role of NRENs) Christoph Witzig SWITCH e-IRG, Helsinki, Oct 4, 2006.
Some Frontier Issues from the Wild, Wild West Ken Klingenstein.
Information Resources and Communications University of California, Office of the President Current Identity Management Initiatives at UC & Beyond: UCTrust.
Information Resources and Communications University of California, Office of the President UCTrust Implementation Experiences David Walker, UCOP Albert.
Presenter’s Name InCommon Approximately 80 members and growing steadily More than two million “users” Most of the major research institutions (MIT joining.
InCommon Policy Conference April Uses  In order to encourage and facilitate legal music programs, a number of universities have contracted with.
New CyberInfrastructure for Collaboration between Higher Ed and NIH.
1 Update on the InCommon Federation, Higher Education’s Community of Trust EDUCAUSE 2005 October 19 10:30am-11:20am.
Updates on Shib, a bit of InCommon and International Federations.
1 Leveraging Your Existing Campus Systems to Access Resource Partners: Federated Identity Management and Tales of Campus Participation Clair Goldsmith,
Welcome to CAMP Identity Management Integration Workshop Ann West NMI-EDIT EDUCAUSE/Internet2.
Federations and Security: A Multi-level Marketing Scheme Ken Klingenstein Director, Internet2 Middleware and Security.
The InCommon Federation The U.S. Access and Identity Management Federation
1 The Partnership Challenge Higher education’s missions are realized in increasingly global, collaborative, online relationships –Higher educations’ digital.
1 The InCommon Federation John Krienke Internet2 Spring Member Meeting Tuesday, April 25, 2006.
The Rise of Federations…Almost Everywhere. Topics Federation Basics Drivers Components International and pulic sector developments InCommon and its uses.
Federations: success brings new challenges Ken Klingenstein Director, Internet2 Middleware and Security.
Digital Object Architecture
InCommon, other federations, the attribute ecosystem, and some killer apps needing guns…
7 October 2015 Shibboleth. Agenda  Shibboleth Background and Status  Why is Shibboleth Important (to Higher Ed)?  Current Pilots Course Management.
Federated Identity Management for HEP David Kelsey WLCG GDB 9 May 2012.
The Research and Education Network: Platform for Innovation Heather Boyles, Next Generation Network Symposium Malaysia 2007-March-15.
VO and Internet2 Middleware. Presenter’s Name Topics Motivations for Internet2 Middleware work Federated identity and InCommon Other IdM Groups, privileges,
2005 © SWITCH Perspectives of Integrating AAI with Grid in EGEE-2 Christoph Witzig Amsterdam, October 17, 2005.
GridShib: Grid/Shibboleth Interoperability September 14, 2006 Washington, DC Tom Barton, Tim Freeman, Kate Keahey, Raj Kettimuthu, Tom Scavo, Frank Siebenlist,
NSF Middleware Initiative Renee Woodten Frost Assistant Director, Middleware Initiatives Internet2 NSF Middleware Initiative.
Shibboleth A Federated Approach to Authentication and Authorization Fed/Ed PKI Meeting June 16, 2004.
Presented by: Presented by: Tim Cameron CommIT Project Manager, Internet 2 CommIT Project Update.
1 InCommon Identity & Access Management Federation John Krienke Operations Manager, InCommon Assistant Director, Internet2
Federations 101 John Krienke Internet2 Fall 2006 Internet2 Member Meeting.
Shibboleth Update Advanced CAMP 7/31/02 RL “Bob” Morgan, Washington Steven Carmody, Brown Scott Cantor, Ohio State Marlena Erdos, IBM/Tivoli Michael Gettes,
Integrated Institutional Identity Infrastructure: Implications and Impacts RL “Bob” Morgan University of Washington Internet2 Member Meeting, May 2005.
Shibboleth Access Management System Walter Hoehn & David Millman, Columbia University.
Scared Straight… if you want to go outside… Authenticate Locally, Act Globally.
NA-MIC National Alliance for Medical Image Computing UCSD: Engineering Core 2 Portal and Grid Infrastructure.
1 Protection and Security: Shibboleth. 2 Outline What is the problem Shibboleth is trying to solve? What are the key concepts? How does the Shibboleth.
Connecting Advanced Networks in Asia-Pacific Kilnam Chon APAN Focusing on Applications -
GRIDS Center Middleware Overview Sandra Redman Information Technology and Systems Center and Information Technology Research Center National Space Science.
3 December 2015 Examples of partnerships and collaborations from the Internet2 experience Interworking2004 Ottawa, Canada Heather Boyles, Internet2
Community Sign-On and BEN. Table of Contents  What is community sign-on?  Benefits  How it works (Shibboleth)  Shibboleth components  CSO workflow.
Leveraging the InCommon Federation to access the NSF TeraGrid Jim Basney Senior Research Scientist National Center for Supercomputing Applications University.
University of Washington Identity and Access Management IEEAF – RENU Network Design Workshop Seattle - 29 Nov 2007 Lori Stevens, Director, Distributed.
Shibboleth: Molecules, Music, and Middleware. Outline ● Terms ● Problem statement ● Solution space – Shibboleth and Federations ● Description of Shibboleth.
Federated Identity Management at NIH…NIH Login and Beyond Debbie Bucci September 2009.
April 14, 2005MIT Libraries Visiting Committee Libraries Strategic Plan Theme III Work to shape the future MacKenzie Smith Associate Director for Technology.
Shibboleth & Federated Identity A Change of Mindset University of Texas Health Science Center at Houston Barry Ribbeck
Internet2 and Cyberinfrastructure Russ Hobby Program Manager,
Connect. Communicate. Collaborate Deploying Authorization Mechanisms for Federated Services in the eduroam architecture (DAMe)* Antonio F. Gómez-Skarmeta.
Welcome to Base CAMP: Enterprise Directory Deployment Ken Klingenstein, Director, Internet2 Middleware Initiative Copyright Ken Klingenstein This.
University of Washington Collaboration: Identity and Access Management Lori Stevens University of Washington October 2007.
Federations: The New Infrastructure Speaker Name Here Date Here Speaker Name Here Date Here.
Identity Management, Federating Identities, and Federations November 21, 2006 Kevin Morooney Jeff Kuhns Renee Shuey.
InCommon® for Collaboration Institute for Computer Policy and Law May 2005 Renee Shuey Penn State Andrea Beesing Cornell David Wasley Internet 2.
Advanced research and education networking in the United States: the Internet2 experience Heather Boyles Director, Member and Partner Relations Internet2.
© Copyright AARNet Pty Ltd PRAGMA Update & some personal observations James Sankar Network Engineer - Middleware.
DICE: Authorizing Dynamic Networks for VOs Jeff W. Boote Senior Network Software Engineer, Internet2 Cándido Rodríguez Montes RedIRIS TNC2009 Malaga, Spain.
Welcome to CAMP Directory Workshop Ken Klingenstein, Internet2 and University of Colorado-Boulder.
1 Identities and Federation: The Next IT Wave (The Canadian Access Federation) Rick Bunt President The Canadian University Council of CIOs (CUCCIO)
01 October 2001 “...By Any Other Name…”. Consequences and Truths (Ken) The Pieces and the Processes (Bob) Directories (Keith) Shibboleth and SAML (Scott)
INTRODUCTION TO IDENTITY FEDERATIONS Heather Flanagan, NSRC.
Community Sign-On and BEN. Table of Contents  What is community sign-on?  Benefits  How it works (Shibboleth)  Shibboleth components  CSO workflow.
Tom Barton, Senior Director for Integration, University of Chicago
New CyberInfrastructure for Collaboration between Higher Ed and NIH
Updates on Shib, a bit of InCommon and International Federations
Fall 2006 Internet2 Member Meeting
Presentation transcript:

Internet2: building and using an advanced network environment for research, teaching and learning APRU CIO Forum, 23 March 2007 Heather Boyles, Keith Hazelton, Ann Doyle,

Outline Internet2 Overview –Brief introduction: Overview of developments, services, activities of the Internet2 community –International R&E network connectivity overview - especially related to APRU institutions, Pacific Rim infrastructure and opportunities for collaboration Identity Management for Inter-institutional collaboration –Campus identity management developments in the Internet2 community –Identity management federations and their relationship to networked collaboration –Federation developments in the APRU community and opportunities for international cooperation

An Asset for the Community Universities Researchers Regional Networks K-12 Industry International An Asset for the Community Universities Researchers Regional Networks K-12 Industry International

Internet2 Activities

Internet2 Network Hybrid optical and IP network Dynamic and static wavelength services Fiber, equipment dedicated to Internet2; Level 3 maintains network and service level Platform supports production services and experimental projects

Internet2 Network - Layer 1 Internet2 Network Optical Switching Node Level3 Regen Site Internet2 Redundant Drop/Add Site ESnet Drop/Add Site

NREN organizations and networks serving APRU institutions AustraliaAARNET CanadaCANARIE – CA*net ChileREUNA ChinaCERNET, CSTNet TaiwanTWAREN IndonesiaITB* JapanSINET, JGN2 KoreaKOREN, KREONET2 MalaysiaMYREN MexicoCUDI New ZealandREANNZ - KAREN PhilippinesPREGINET RussiaRBnet, RUNNET SingaporeSingAREN ThailandUNINET, ThaiSARN (ThaiREN) USAInternet2, NLR

Pacific Rim R&E Networking Trends in global R&E networking –Increasing interconnectedness Number of countries connected, including lesser- developed Number of connections, bandwidth –Regionalization TEIN2 network in Southeast Asia CLARA in Latin America –Hybrid network capabilities Beyond best-efforts shared IP Dedicated circuits to support major global science collaborations

Current AARNet3 Footprint

TRANSPAC2TRANSPAC2

Topology

Internet2 Activities

Internet2 Middleware Goals Much as at the network layer, create a ubiquitous common, persistent & robust core middleware infrastructure for the R&E community In support of inter-institutional & inter-realm collaborations, provide tools & services (e.g. registries, bridge PKI components, root directories) as required

Inter-institutional Collaboration is the Driver One institution hosting course-content for another Students at one college taking an on-line course from another college Libraries purchasing licenses for multiple vendors with specific access policies Researchers making resources available to project members at other schools (e.g. grid resources) Schools in state systems or articulation relationships that require mutual access to services

What questions are common to these scenarios? Are the people using these services who they claim to be? Are they a member of our campus community? Have they been given permission? Is their privacy being protected?

Identity Management (IdM) “Hi! I’m Lisa.” (Identity) “…and here’s my NetID / password to prove it.” (Authentication) “I want to do some E-Reserves reading.” (Authorization : Allowing Lisa to use the services for which she’s authorized) “And I want to change my grade in last semester’s Physics course.” (Authorization  : Preventing her from doing things she’s not supposed to do)

Federated Approach to support inter- institutional collaboration Federated Identity & Access Management –Rely on the Identity Management infrastructure of institutions –To authenticate and pass authorization-related information to service providers or resource hosts –Via institution-to-provider agreements –Facilitated by common membership in a federation (like InCommon) Shibboleth is a way to move the authNZ info between parties

What is Shibboleth? (federating software system) An initiative to develop an architecture and policy framework supporting the sharing – between domains -- of secured web resources and services A framework built on a “Federated” model A project delivering an open source implementation of the architecture and framework Deliverables: open-source, standards-based, privacy- preserving federating software –Software for identity providers = campuses (origins) –Software for resource providers (targets) –Operational Federations (scalable trust)

What are Federations? An association of organizations that come together to exchange information as appropriate about their users and resources in order to enable collaborations and transactions. Uses common policy, technology, and business practices to establish trust Access services from (or provide services to) other institutions, corporate partners, government organizations A contractual arrangement

Identity Federations Enroll locally Authenticate locally Assign attributes locally Act federally

Identity Federations Simplified usability for all collaborations Home organizations carefully manage the release of personal information On-line resource providers focus on the protection and authorization of use of their on-line resources

A federation of higher education, by higher education, for higher education (in US)

InCommon Federation Created to support US Higher Education and its research and business partners Federation operator is an LLC operated by Internet2 Builds on existing campus identity management and single sign-on systems Makes use of open industry standards (SAML) and open source federating software (Shibboleth)

InCommon Members 2/27/07 Case Western Reserve University Clemson University Cornell University Dartmouth Duke University Florida State University Georgetown University Miami University New York University Ohio University Penn State Stanford University Stony Brook University SUNY Buffalo The Ohio State University The University of Chicago University of Alabama at Birmingham University of California, Irvine University of California, Los Angeles University of California, Merced University of California, Office of the President University of California, Riverside University of California, San Diego University of Maryland University of Maryland Baltimore County University of Maryland, Baltimore University of Rochester University of Southern California University of Virginia University of Washington University of Wisconsin - Madison Cdigix EBSCO Publishing Elsevier ScienceDirect Houston Academy of Medicine - Texas Medical Center Library Internet2 JSTOR Napster, LLC OCLC OhioLink - The Ohio Library & Information Network ProtectNetwork Symplicity Corporation Thomson Learning, Inc. Turnitin WebAssign

InCommon Uses Access control to content –Popular content – Napster, CDigix, etc –Scholarly content – Google, OCLC WorldCat –Downloads – Microsoft Access to external services –Student travel, charitable giving, web learning and testing, plagiarism testing service, etc. –Allure for alumni services and other internal businesses –Student loans, student testing, graduate school admissions, etc. Access to national services –The National Science Digital Library –The Teragrid pilot: building on Shibboleth and GridShib

GridShib “Integrating federated authorization infrastructure (Shibboleth) with Grid technology (the Globus Toolkit) to provide attribute-based authorization for distributed scientific communities”

GridShib - from Von Welch Allow the Grid to scale by leveraging existing campus identity management (IdM) –Consider Shibboleth as the interface to campus IdM systems –Get out of identity management game Making joining the Grid as easy as possible for users –No separate long-term credential for Grid access to manage –No new passwords, certificates, etc Allow campuses attributes and VO attributes to be aggregated and used by the Grid for authorization –Allow for scalability in user base through attribute-based authorization - I.e. know groups of users instead of individual users

Research and Education Federations around the world Growing national federations –UK, France, Germany, Switzerland, Australia, Netherlands, Norway, Spain, Denmark, etc. –Many (most) operated by National Research and Education Network (NREN) organizations –Many are Shib-based; all speak Shib on the outside… US Federations –InCommon (Internet2) –State-based Texas, UCOP, Maryland, etc.

Federation activities in APRU countries AustraliaFederation in formation CanadaFederating activity going on Chile ChinaCERNET experimenting with Shibboleth Taiwan Indonesia JapanUPKI initiative of 7 national universities Korea Malaysia Mexico New ZealandPilot activity Philippines Russia Singapore Thailand USAInCommon Federation up and running

Ways to engage in national identity federation work Internet2 working groups TERENA (Europe) EMC2 working group APAN middleware working group TestShib –Open to non-US institutions –An opportunity to try out Shib implementation

Thanks!