EResearchers Requirements the IGTF model of interoperable global trust and with a view towards FIM4R AAI Workshop Presenter: David Groep, Nikhef.

Slides:



Advertisements
Similar presentations
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
Advertisements

David Groep Nikhef Amsterdam PDP & Grid Evolving Assurance – IGTF LoA generalisation David Groep Interoperable Global Trust Federation IGTF Documents at.
Federated Identity Management for Research Communities (FIM4R) David Kelsey (STFC-RAL) EGI TF, AAI workshop 19 Sep 2012.
INFSO-RI Enabling Grids for E-sciencE JRA3 2 nd EU Review Input David Groep NIKHEF.
Geneva, Switzerland, September 2014 Introduction of ISO/IEC Identity Proofing Patrick Curry Director, British Business Federation Authority.
David Groep Nikhef Amsterdam PDP & Grid Differentiated and Collaborative Assurance profiling the identity management landscape for diversifying e-Infrastructure.
Security Incident Response Trust Framework for Federated Identity (Sir-T-Fi) David Kelsey (STFC-RAL) REFEDS, Indianapolis 26 Oct 2014 and now abbreviated.
Trust and Security for FIM (Sirtfi/SCI) David Kelsey (STFC-RAL) FIM4R at CERN 4 Feb 2015.
BoF: Federated Identity Management for Researchers David Kelsey (STFC-RAL) TNC2014, Dublin 20 May 2014.
Authentication and Authorization in a federated environment Jules Wolfrat (SARA)
AARC Overview Licia Florio, David Groep 21 Jan 2015 presented by David Groep, Nikhef.
LiveAP Towards Differentiated Identity Assurance David Groep, Nikhef supported by the Netherlands e-Infrastructure SURFsara, and EGI.eu O-E-15 and EGI-InSPIRE.
Climate Sciences: Use Case and Vision Summary Philip Kershaw CEDA, RAL Space, STFC.
Federated Identity Management for HEP David Kelsey WLCG GDB 9 May 2012.
Ning Zhang, the University of Manchester, UK David Groep, National Institute for Nuclear and High Energy Physics, NL Blair Dillaway, OGF Security Area.
David Groep Nikhef Amsterdam PDP & Grid Evolving Assurance – going where? Collaborative, distributed, and generalized assurance beyond just identity authentication.
7 th FIM 4 R meeting April 2014 ESRIN Frascati.
Authentication and Authorisation for Research and Collaboration Licia Florio AARC Workshop The AARC Project Brussels, 26 October.
Authentication and Authorisation for Research and Collaboration Peter Solagna Milano, AARC General meeting Current status and plans.
A Trust Framework for Security Collaboration among Infrastructures David Kelsey (STFC-RAL, UK) 1 st WISE, Barcelona 20 Oct 2015.
IOTA AP Towards Differentiated Identity Assurance David Groep, Nikhef supported by the Netherlands e-Infrastructure and SURFsara.
A Trust Framework for Security Collaboration among Infrastructures David Kelsey (STFC-RAL, UK) WLCG GDB, CERN 10 Jul 2013.
Federated Identity Management for HEP David Kelsey HEPiX, IHEP Beijing 18 Oct 2012.
EResearchers Requirements ELIXIR AAI Workshop Presenter: Mikael Linden (ELIXIR AAI-TF)
Authentication and Authorisation for Research and Collaboration Christos Kanellopoulos Open Day Event: Towards the European Open.
Additional Services: Security and IPv6 David Kelsey STFC-RAL.
EGI-InSPIRE RI EGI EGI-InSPIRE RI Establishing Identity in EGI the authentication trust fabric of the IGTF and EUGridPMA.
Federated Identity Management for Scientific Collaborations The Common Vision David Kelsey (STFC) 3 Nov 2011.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
Connect communicate collaborate Trust & Identity EC meets GÉANT 19 June 2014 Brussels Valter Nordh, NORDUnet Federation as a Service Task Leader Trust.
Networks ∙ Services ∙ People Marina Adomeit FIM4R meeting Virtual Organisation Platform as a Service VOPaaS Nov 30, 2015, Austria Task Leader,
David Groep Nikhef Amsterdam PDP & Grid Bring the WLCG federation Home Extending your trust options beyond bottom-up identity by collaborating with global.
European Grid Initiative AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
Helix Nebula Workshop On Interoperability among Public And Community Clouds Session 2: Networking Connectivity Convener: Carmela ASERO, EGI.eu19 September.
David Groep Nikhef Amsterdam PDP & Grid AARC Authentication and Authorisation for Research and Collaboration an impression of the road ahead.
Federated Identity Management for Research Communities: FIM4R PSI workshop objectives Bob Jones, CERN.
Networks ∙ Services ∙ People Licia Florio TNC, Lisbon Consuming identities across e- Infrastructures 16 June 2015 PDO GÈANT.
Authentication and Authorisation for Research and Collaboration Licia Florio AARC CORBEL Workshop The AARC Project Paris, 31 May.
Networks ∙ Services ∙ People Marina Adomeit TNC16 Conference, Prague Towards a platform for supporting collaboration GÉANT VOPaaS
EGI-InSPIRE RI EGI (IGTF Liaison Function) EGI-InSPIRE RI IGTF & EUGridPMA status update SHA-2 – and more (David Groep,
News from EUGridPMA EGI OMB, 22 Jan 2013 David Kelsey (STFC) Using notes from David Groep 22/01/20131EUGridPMA News.
Authentication and Authorisation for Research and Collaboration David Kelsey AARC AHM Utrecht NA3 Task 4 – Scalable Policy Negotiation.
Co-ordination & Harmonisation of Advanced e-Infrastructures for Research and Education Data Sharing Grant.
IGTF in 10 years enabling the interoperable global trust federation Nikhef, Amsterdam supported the Dutch national e-Infrastructure funded and coordinated.
Security in the wider world David Kelsey (STFC-RAL) GridPP37 – Ambleside 2 Sep 2016.
SCI & Sirtfi David Kelsey (STFC-RAL) EGI Conference, Lisbon 19 May 2015.
Building Trust for Research and Collaboration
Introduction to AAI Services
WLCG Update Hannah Short, CERN Computer Security.
Boosting AAI for research and collaboration
RCauth.eu CILogon-like service in EGI and the EOSC
Cross-sector and user-centric AAI
Building Interoperable Global Trust
Federated Identity Management for Researchers (FIM4R)
EGI Security Policy Update
Boosting AAI for research and collaboration
Federated Identity Management for Scientific Collaborations
Towards hamonized policies and best practices
Minimal Level of Assurance (LoA)
Policy in harmony: our best practice
Assessing Combined Assurance
Leveraging the IGTF authentication fabric for research
Leveraging the IGTF authentication fabric for research
OIDC Federation for Infrastructures
AARC Blueprint Architecture and Pilots
Supporting communities with harmonized policy
EUGridPMA Status and Current Trends and some IGTF topics March 2018 APGridPMA ISGC Meeting David Groep, Nikhef & EUGridPMA.
OIDC Federation for Infrastructures
RCauth.eu CILogon-like service in EGI and the EOSC
Baseline Expectations for Trust in Federation
Presentation transcript:

eResearchers Requirements the IGTF model of interoperable global trust and with a view towards FIM4R AAI Workshop Presenter: David Groep, Nikhef

IGTF – Interoperable Global Trust Federation supporting distributed IT infrastructures for research IGTF brings together – e-Infrastructure resource providers, user communities and identity authorities to agree on – global, shared minimum requirements and assurance levels – inspired and coordinated by the needs of relying parties Trust is technology-agnostic – focus on global, coordinated identity across communities and across service providers for cooperative services – define ‘best practices’ for assurance levels, attribute authority operations, credential management, auditing and reviewing

Coverage: users and providers ~ users and resources 89 national and regional identity authorities: R&E and commercial >1000 different user communities: small and large, national and global Major relying parties: EGI, PRACE, XSEDE, Open Science Grid, HPCI, wLCG, OGF, … IGTF is a coordinating body, and not a legal entity in itself – although its members may be

Minimum Requirements Federation imposes minimum requirements on identity provider participants – Reflect operational and security needs of resource providers – Differentiated LoA support classic user-based subscriber services: serve all users identity services leveraging (R&E) federations with ID vetting ‘LoA1+’ Identifier-Only Trust Assurance – if relying party has other ways to vet its users, allow for lower-assurance identifiers, thus enabling more ID federations – Research-inspired verification process: self-audits, peer-review, transparent open policies and processes – ‘meet or exceed’ required minimum standards ‘LoA2-’

Community characteristics More than one administrative organisation More than one service provider participates in a single transaction More than one user in a single transaction More than one authority influences effective policy Single interoperating instance at a global level

AAI requirements FIM4R captures the key requirements different Levels of Assurance with provenance authorisation under community and/or facility control browser & non-browser federated access attributes must be able to cross national borders and we also need federations and IdPs to work in a collaborative security and policy framework, addressing the areas identified in e.g. SCI support for individual researchers communities are widely distributed and although large as a whole may be only a one or a few per institution global scope: scientific collaborations extend beyond Europe FIM4R: SCI – Security for Collaboration among Infrastructures:

Are the Requirements Met? NO -security trust and operational issues -differentiated LoA: reviewed and/or audited -support for community and facility control, set by themselves and propagated to the SPs -both browser and non-browser access -attributes to cross national borders Each of these may have been solved in some federations – but what we need is a coherent European/global view, where these requirements are addressed ubiquitously!

Are the Requirements Met? YES Much of the technology is there for community attributes, facility control, non-web-access – we ‘just’ need to bridge it to together, and make sure the technology is deployed uniquitously there may even be ‘too much’ technology, in that we now need to bridge for interoperability – bridges, proxies, and credential stores will a part (likely supported by the RPs, communities and facilities) attributes to cross borders: DPCoC is a great step – now can we do the same for IdPs please? the GEANT eduGAIN Federation Template looks like going this way … – the model of ‘minimum requirements’ and open processes worked well in the IGTF and is ‘natural’ to a research environment

Interoperable Global Trust Federation