1 UPKI-Federation based on Shibboleth National Institute of Informatics Motonori Nakamura Toshiyuki Kataoka, Kyoto University Yasuo Okabe.

Slides:



Advertisements
Similar presentations
UPKI Inter-University Authentication and Authorization Platform for Japanese Cyber-Science Infrastructure Yasuo OKABE Academic Center for Computing and.
Advertisements

eduroam Delegate Authentication System with Shibboleth SSO
Lousy Introduction into SWITCHaai
Practical Digital Signature Issues. Paving the way and new opportunities. Juan Carlos Cruellas – DSS-X co-chair Stefan Drees - DSS-X.
Secure Sockets Layer eXtended (SSLX) Next Generation Internet Security Overview Presentation April 2011.
Toward Production Level Operation of Authentication System for High Performance Computing Infrastructure in Japan Eisaku Sakane and Kento Aida National.
Update of Japanese Academic Access Management Federation GakuNin in 2011 Nakamura, M, Yamaji, K.
Introduction to Identity Management Federation Kazu Yamaji, National Institute of Informatics, Japan.
Lecture 23 Internet Authentication Applications
TechSec WG: Related activities overview Information and discussion TechSec WG, RIPE-45 May 14, 2003 Yuri Demchenko.
2006 © SWITCH Authentication and Authorization Infrastructures in e-Science (and the role of NRENs) Christoph Witzig SWITCH e-IRG, Helsinki, Oct 4, 2006.
Federation of Campus PKI and Grid PKI for Academic GOC Management Conformable to APGrid PMA National Institute of Informatics, JAPAN Toshiyuki Kataoka,
Dorian Grid Identity Management and Federation Dialogue Workshop II Edinburgh, Scotland February 9-10, 2006 Stephen Langella Department.
2015/6/21 UPKI project update Yasuo Okabe Academic Center for Computing and Media Studies Kyoto University.
Dartmouth PKI Deployment Robert Brentrup PKI Summit July 14, 2004.
Beispielbild Shibboleth, a potential security framework for EDIT Lutz Suhrbier AG Netzbasierte Informationssysteme (
Agenda Project beginnings and funding. Purpose of the federation. Federation members. Federation protocols. Special features in our federation. Pilot.
Introduction to PKI Seminar What is PKI? Robert Brentrup July 13, 2004.
Implementing Native Mode and Internet Based Client Management.
03 December 2003 Digital Certificate Operation in a Complex Environment Consultation/Stakeholders Meeting 3 December 2003.
Introduction to PKI Mark Franklin September 10, 2003 Dartmouth College PKI Lab.
Development and Implementation of Multifactor Authentication Motonori Nakamura at National Institute of Informatics and Takuya Matsuhira at Kanazawa University,
Widely Distributed Access Management Tom Barton University of Chicago.
CAMP - June 4-6, Copyright Statement Copyright Robert J. Brentrup and Mark J. Franklin This work is the intellectual property of the authors.
Inside the PKI Framework: * Activating the Puzzle Pieces PKI Summit Snowmass August
AAI with simpleSAMLphp
Copyright 次世代 IC カードシステム研究会 C 1 Nagaaki OHYAMA Tokyo Institute of Technology Chair of NICSS National ID card in Japan May Provoo (Reykjavik,
GakuNin Registration System Motonori Nakamura, NII Japan APAN33 rd Meeting (16 Feb. 2012)
Australian Access Federation Robert Hazeltine Identity and Access Management Enterprise Systems Office.
CASE: Haka federation EuroCAMP, 3-5 April, 2006 CSC, the Finnish IT Center for Science
3 Nov 2003 A. Vandenberg © Second NMI Integration Testbed Workshop on Experiences in Middleware Deployment, Anaheim, CA 1 Shibboleth Pilot Local Authentication.
FIM-related activities and issues being discussed in Japan 1.GEO Grid Yoshio Tanaka (AIST) 2.HPCI, GakuNin Eisaku Sakane, Kento Aida (NII)
PKI interoperability and policy in the wireless world.
National Institute of Informatics Current Status of Institutional Repositories in Japan National Institute of Informatics Izumi Sugita Library Liaison.
Federated Identity Management for HEP David Kelsey WLCG GDB 9 May 2012.
ArcGIS Server and Portal for ArcGIS An Introduction to Security
2005 © SWITCH Perspectives of Integrating AAI with Grid in EGEE-2 Christoph Witzig Amsterdam, October 17, 2005.
Helsinki Institute of Physics (HIP) Liberty Alliance Overview of the Liberty Alliance Architecture Helsinki Institute of Physics (HIP), May 9 th.
Chapter 23 Internet Authentication Applications Kerberos Overview Initially developed at MIT Software utility available in both the public domain and.
Eduroam JP and development of UPKI roaming Yoshikazu Watanabe*, Satoru Yamano* Hideaki Goto**, Hideaki Sone** * NEC Corporation, Japan ** Tohoku University,
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Interoperability Shibboleth - gLite Christoph.
10 years of HEAL-Link Trieste, Italy. Increase of electronic journals accessible to the members of HEAL-Link
NSF Middleware Initiative Renee Woodten Frost Assistant Director, Middleware Initiatives Internet2 NSF Middleware Initiative.
Neil Witheridge APAN29 Sydney February 2010 ARCS Authorisation Services Neil Witheridge Manager, ARCS Authorisation Services APAN29, Sydney, February 2010.
David Kennedy, UMD Shibboleth and Library Resources Internet2 Library/Shibboleth Project.
Introduction of NAREGI-CA National Institute of Informatics JAPAN Toshiyuki Kataoka, July 19, 2006 APAN Grid-Middleware Workshop, Singapore.
Dartmouth PKI Update Robert Brentrup Internet2 Member Meeting April 21, 2004.
Jun Adachi & Masamitsu Negishi National Institute of Informatics, Japan NII October 23, 2006 Beijing, China Cyber Science Infrastructure for.
Connect. Communicate. Collaborate Federation Interoperability Made Possible By Design: eduGAIN Diego R. Lopez (RedIRIS)
Configuring and Troubleshooting Identity and Access Solutions with Windows Server® 2008 Active Directory®
Holly Eggleston, UCSD Shibboleth and Library Resources InCommon Library/Shibboleth Project.
Haka federation status  24 institutions and IdPs end users 96% coverage in universities, 41% in polytechnics  41 services Elearning Libraries.
UPKI Activities - July NII & UPKI Initiative Hideaki Sone, Tohoku University.
Holly Eggleston, UCSD Beyond the IP Address: Shibboleth and Electronic Resources InCommon Library/Shibboleth Project.
1 Earth System Grid Center for Enabling Technologies ESG-CET Security January 7, 2016 Frank Siebenlist Rachana Ananthakrishnan Neill Miller ESG-CET All-Hands.
Federated Identity Management for HEP David Kelsey HEPiX, IHEP Beijing 18 Oct 2012.
Copyright Statement Copyright Robert J. Brentrup This work is the intellectual property of the author. Permission is granted for this material to.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Interoperability Shibboleth - gLite Christoph.
The Roadmap of NAREGI Security Services Masataka Kanamori NAREGI WP
Shibboleth Use at the National e-Science Centre Hub Glasgow at collaborating institutions in the Shibboleth federation depending.
Agenda  Microsoft Directory Synchronization Tool  Active Directory Federation Server  ADFS Proxy  Hybrid Features – LAB.
A Study of Certification Authority Integration Model in a PKI Trust Federation on Distributed Infrastructures for Academic Research Eisaku SAKANE, Takeshi.
Project Moonshot Daniel Kouřil EGI Technical Forum
Authentication and Authorisation for Research and Collaboration Taipei - Taiwan Mechanisms of Interfederation 13th March 2016 Alessandra.
LIGO Identity and Access Management
University of Stuttgart University of Murcia
GakuNin: Federated Identity Management Activities in Japan
Organized by governmental sector (National Institute of information )
Country Update from Japan
GN2 JRA5 Roaming and Authorisation Jürgen Rauschenbach, DFN-Verein
Presentation transcript:

1 UPKI-Federation based on Shibboleth National Institute of Informatics Motonori Nakamura Toshiyuki Kataoka, Kyoto University Yasuo Okabe

2 OUTLINE 1.Overview of UPKI and UPKI-Fed 2.UPKI Single Sing-On Trial 3.Roadmap

3 What is UPKI? We are undertaking the construction of University Public Key Infrastructure (UPKI), which is intended to achieve an inter-university cooperation that makes use of educational and research computing systems, digital contents, networks, and business systems at almost 800 universities and other institutions in Japan, in safe, convenient, and effective ways. We are promoting an Inter-university authentication federation by developing UPKI common specifications, and by developing applications using the PKI.

4 1. Overview of UPKI

5 UPKI Three-layer Architecture

6 UPKI Three-Layer Architecture Open Domain PKI (Public PKI)  Using for authentication, signature and encryption on the internet.  Issuing public certs for servers and individuals in the internet by PKI service provider. Campus PKI  Using to campus network for secure access and secure transaction.  SSO, VPN, 802.1X, e-Approval, etc.  Issuing certs for server and faculty staff/students in campus network by each organization. Grid PKI  Using to authentication for NAREGI.  Issuing certs for HPC resources and NAREGI users by NAREGI-CA.

7 UPKI Activities Web サーバ NII Pub CA Web Srv. Web サーバ S/MIME Other Pub CA S/MIME Web Srv. 学内用 A Univ. CA EE 学内用 B Univ. CA EE A Univ. NAREGI CA EE B Univ. NAREGI CA Campus PKI Open Domain PKI NAREGI PKI S/MIME Auth, Sign, Encrypt. Sign, Encrypt. Auth, Sign, Encrypt. Grid Computing Proxy EE Proxy EE Student, Faculty Server, Super Computer Student, Faculty Server, Super Computer NAREGI-CA Enhancement CA Start-Pack UPKI Common Specification Server Certificates S/MIME Certificates Eduroam Shibboleth

8 UPKI-Fed Inter-Univerisity SSO Architecuture Leveraging PKI and Shibboleth (SAML) technologies, UPKI-Federation that enables secure Single Sign-On for inter- Universities services such as electronic journals is under development. The project is trial stage since Sept

9 Academic Society University SP Faculty Student E-Journal CiN ii 、・・ e-Learning Cert. Issuance Server Cert. IdP University Academic Society University AuthN Society member ・・・ Account Issuance, Wireless LAN ・・ Federation using Shibboleth and PKI Secure access from off-campus, other campus UPKI-Federation - Policy - System Spec. UPKI-IdP Discovery Service Support Portal Operational Organization Metadata Repository UPKI-Fed Inter-University SSO Architecture ・・・ Campus System System ・・・ AuthN Single Sign-On

UPKI-FED SSO TRIAL 2. 10

11 User (B Univ.) Id P B University User (A Univ.) IdP Client Cert.Isssuance AuthN A University Campus CA Commercial Service UPKI-Fed IdP_00 DS IdP_01 Repository Admin. SP SSO CMS(Plone1) Admin. Attributes Management UPKI-Fed Test-bed AuthN UPKI Open Domain CA SP CMS ( Moodle ) CMS ( Plone2 ) CiNii SSO User is authenticated by IdP of his/her University Participant of Commercial Service Attributes Management

12 Feasibility Study Schedule (FY2008) Preparation - Setup documents - VMWare Image for IdP - test-bed including DS, repository Explanatory meeting (July 2008, twice) - Ask to attend both IT people and librarians from each institutes Development - developed test SP - support institutes to setup IdP, SP - metadata distribution - feasibility test instruction - share information by wiki, mailing-list, mail magazine Participants meeting (Nov. 2008) - report status from all institutions Preparation for next step - discussion and development of policy for pilot operation Demonstration at UPKI Symposium 2009 (Feb. 2009)

13 Participants 27 Institutions 30 IdP sites 18 SP sites Aug. Sep. Oct. Nov. Dec. Jan. Feb. 10 Sites 20 Sites 10 Sites SP IdP 30 Sites 18 Sites Completed connection to Elsevier !

14 Status of Participating Institutions NameIdPSP Hokkaido Univ.○ 2 - Tohoku Univ.○ - Yamagata Univ.○ - Fukushima Univ.- - High Energy Accelarator Research Organization - - Tsukuba Univ.○(Local test) Tsukuba Univ. of Technology -- Chiba Univ.Test - Tokyo Univ.○ - Tokyo Institute of Technology ○(Local test) Ocyanomizu Univ. ○ - Advanced Institute of Industrial Technology ○2○2Multi-Mouse AP, (Local test) Keio Univ. -- National Institute of Informatics ○3○3 CiNii Shib-test NameIdPSP Kanazawa Univ.○File Transfer Service, Digital Contents Publishing (Dspace) Nagoya Univ.○ - Aichi Prefectural College of Nursing and Health ○ - Kyoto Univ.○Wireless LAN Account Issuance Service Kyoto Sangyo Univ. ○(Local test) Osaka Univ. ○4○4 (Grid Cert. Issuance Service) Ehime Univ. -- Tokushima Univ.○Inter-Campus SNS(OpenPNE) Hiroshima Univ.○ - Yamaguchi Univ.○ SSO Test(Plone) Kyusyu Univ.○ ( Local test ) Kumamoto Univ.○ - Saga Univ.○ ( Local test )2

15 Feasibility Study Trial using Shibboleth2.0/2.1.2  Single Sign-On connection among Universities’ IdPs, SPs, and commercial SPs from abroad  Shibboleth2.0 protocol among participants in Japan  Shibboleth1.3 protocol to connect to existing commercial SPs from abroad  Metadata automatic download test  Metadata signing, and verification test  Connecting IdP to campus LDAP/AD  Attributes send/receive test, including Japanese Attributes  Tools test such as ArpViewer

16 Connecting to commercial SP from abroad NII IdP (idp.nii.ac.jp) NII Institution’s AD AuthN SP Test SPs in participating Institutions All Institution member can use IdP now ! JAPAN Abroad

17 Connection with commercial SPs from abroad Completed with Elsevier (ScienceDirect, Scopus)  Protocol = Shibboleth1.3 : Changed UPKI-Fed protocol from Shib2.0 only to Shib2.0/Shib1.3  Certificate : Ask SPs from abroad to use commercial public certificate, because we can’t issue UPKI certificate to abroad Connection plan with other commercial SPs  soon : Refworks 、 Nature 、 OUP (Oxford University Press) 、 LWW/Ovid 、 Springer 、 Thomson 、 EBSCO  Within the next fiscal year(?) : CUP ( Cambridge University Press )、 Wiley-Blackwell 、 SAGE 、 ProQuest 、 JSTOR 、 Serials Solutions 、 Taylor&Francis 、 APS ( American Physical Society )

18 Connection with Elsevier ログイン

ROADMAP 3. 19

20 UPKI-Fed Prospective Plan Goal: Inter-University AuthN and AuthZ Infrastructure for ALL Services  “Feasibility Study” will end in Mar  “Pilot Operation” will start from April 2009 FY2008FY2009FY2010 Feasibility Study Pilot Operation Practical Operation Connection using test account Connection using real account under campus policies Practical operation with real account and service

21 Preparation for UPKI-Fed Pilot Operation UPKI-Fed Policy (under development)  “UPKI-Fed Pilot Operation Procedure” (Draft)  “UPKI-Fed System Specification” (Draft) Attributes (Specified in above document)  eppn/persistentID, o, ou, eduPersonAffiliation, etc…  Two bytes code support (Japanese) Name, DisplayName, OrganizationName,,, (Discussing to define “jasn”, “jaDisplayName”, “jao”,,,) Configuration template  Preparing template for attribute-resolver, attribute- filter, attribute-map for UPKI-Fed participants

22 UPKI-Fed Pilot Operation Procedure (Draft)

23 Summary UPKI-Fed: Japanese Academic Federation  Architecture design; Develop suitable architecture on UPKI PKI infrastructure (three layers) taking institutions situations into consideration. Deployment of Shibboleth/SAML  Roadmap; FY2008 Feasibility Study Evaluate and develop architecture using testbed Small start with a few SP services FY2009 Pilot Operation FY2010 ~ Operational