CARSI: Federated Identity and Resource Sharing over CERNET Dr. PING CHEN Peking University( 北京大学 ) Jan, 24 th, 2008.

Slides:



Advertisements
Similar presentations
Lousy Introduction into SWITCHaai
Advertisements

Scaling TeraGrid Access A Testbed for Attribute-based Authorization and Leveraging Campus Identity Management
Pennsylvania Banner Users Group 2008 Fall Conference Campus Identity Management in a Banner World.
FAME-PERMIS Project University of Manchester University of Kent London, July 2006.
Enabling UCTrust Access for Your Application Introduction to The UC CSC Conference UC Santa Barbara, July 21-22, 2008.
Defining the Security Domain Marilu Goodyear John H. Louis University of Kansas.
Access & Identity Management “An integrated set of policies, processes and systems that allow an enterprise to facilitate and control access to online.
KC-ROLO Project Kidderminster College Repository Of Learning Objects Graham Mason & Ed Beddows.
Inter-Institutional Registration UNC Cause December 4, 2007.
Implementing Shibboleth-based Virtual Organisations and VO Federations using IAMSuite (including AAF update) James Dalziel & Alan Lin Professor of Learning.
JISC Metaleth Project Athens, Shibboleth and the University of Bristol 29 th January 2007.
5/25/2015 AEB/Yleisesittely Roaming network access using Shibboleth in University of Helsinki Fall 2004 Internet2 Member Meeting 29th of September, 2004.
Federated Identity Management for Research Communities (FIM4R) David Kelsey (STFC-RAL) EGI TF, AAI workshop 19 Sep 2012.
2006 © SWITCH Authentication and Authorization Infrastructures in e-Science (and the role of NRENs) Christoph Witzig SWITCH e-IRG, Helsinki, Oct 4, 2006.
Beispielbild Shibboleth, a potential security framework for EDIT Lutz Suhrbier AG Netzbasierte Informationssysteme (
Agenda Project beginnings and funding. Purpose of the federation. Federation members. Federation protocols. Special features in our federation. Pilot.
Information Resources and Communications University of California, Office of the President UCTrust Implementation Experiences David Walker, UCOP Albert.
Peter Deutsch Director, I&IT Systems July 12, 2005
Federated A(A(A))I Jens Jensen hepsysman, RAL,
SWITCHaai Team Federated Identity Management.
AAI with simpleSAMLphp
Cancún - Mexico, Andrea Biancini Towards a Federation as a Service From IdP in the Cloud project to FaaS.
Feide is a identity management system on a national level for the educational sector in Norway. Federated Electronic Identity for Norwegian Education Tromsø,
Introduction to Grouper Part 1: Access Management & Grouper Tom Barton University of Chicago and Internet2 Manager – Grouper Project.
Australian Access Federation Robert Hazeltine Identity and Access Management Enterprise Systems Office.
CASE: Haka federation EuroCAMP, 3-5 April, 2006 CSC, the Finnish IT Center for Science
1 Multi Cloud Navid Pustchi April 25, 2014 World-Leading Research with Real-World Impact!
I2Q & WMnet Pilot Presented by Jason Rousell – i2Q Jay Neale - i2Q.
2005 © SWITCH Perspectives of Integrating AAI with Grid in EGEE-2 Christoph Witzig Amsterdam, October 17, 2005.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Interoperability Shibboleth - gLite Christoph.
UCLA Enterprise Directory Identity Management Infrastructure UC Enrollment Service Technical Conference October 16, 2007 Ying Ma
GridShib: Grid/Shibboleth Interoperability September 14, 2006 Washington, DC Tom Barton, Tim Freeman, Kate Keahey, Raj Kettimuthu, Tom Scavo, Frank Siebenlist,
Kalmar Union, a Conferedation of Nordic Identity Federations TNC2009 Mikael Linden, CSC Andreas Solberg, UNINETT.
Social Identity Working Group Steve Carmody. Agenda Intro to Using Social Accounts Status and Recent News –Current UT Pilot –Current InCommon Pilot with.
Empowering people-centric IT Unified device management Access and information protection Desktop Virtualization Hybrid Identity.
Shibboleth at Columbia Update David Millman R&D July ’05
MAT U M A T U Middleware Assisted Take-Up Service For JISC Funded Early Adopters.
7 th FIM 4 R meeting April 2014 ESRIN Frascati.
Kalmar Union lessons: Findings in federation harmonisation REFEDS Mikael Linden, CSC.
Comité Réseau des Universités News from CRU activities: Identity federation, eduroam, PKI, SCS, Sympa, security policies cru.fr 7th.
Federations round table Haka federation of Finland EuroCAMP Mikael Linden CSC, the Finnish IT Center for Science.
ITS – Identity Services ONEForest Security Jake DeSantis Keith Brautigam
Community Sign-On and BEN. Table of Contents  What is community sign-on?  Benefits  How it works (Shibboleth)  Shibboleth components  CSO workflow.
Services Information University Project Sentinel Middleware & Identity Management for the Health Sciences Chad La Joie Georgetown University.
Connect. Communicate. Collaborate AAI scenario: How AutoBAHN system will use the eduGAIN federation for Authentication and Authorization Simon Muyal,
University of Washington Identity and Access Management IEEAF – RENU Network Design Workshop Seattle - 29 Nov 2007 Lori Stevens, Director, Distributed.
Authentication and Authorisation for Research and Collaboration Christos Kanellopoulos GRNET Proposed Pilots for Libraries and eGov.
Shibboleth Trust Model Shibboleth/SAML Communities (aka Federated Administrations) Club Shib Club Shib Application process Policy decision points at the.
Transforming Government Federal e-Authentication Initiative David Temoshok Director, Identity Policy and Management GSA Office of Governmentwide Policy.
June 9, 2009 SURFfederatie: implementing a multi- protocol federation Hans Zandbelt & Joost van Dijk, SURFnet.
Jakob Gadegaard Bendixen, Shibboleth protected proxy servers a case study from the Danish library sector.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
Shibboleth at USMAI David Kennedy Spring 2006 Internet2 Member Meeting, April 24-26, 2006 – Arlington, VA.
Shibboleth Use at the National e-Science Centre Hub Glasgow at collaborating institutions in the Shibboleth federation depending.
Building Preservation Environments with Data Grid Technology Reagan W. Moore Presenter: Praveen Namburi.
INTRODUCTION TO IDENTITY FEDERATIONS Heather Flanagan, NSRC.
Computer Center of Peking University CARSI Today and the Near Future Prof. Ping CHEN Peking University, Beijing, China June 4 th, 2013.
Leveraging Campus Authentication to Access the TeraGrid Scott Lathrop, Argonne National Lab Tom Barton, U Chicago.
Co-ordination & Harmonisation of Advanced e-INfrastructures Technical program: advancement & issues Roberto Barbera University.
Community Sign-On and BEN. Table of Contents  What is community sign-on?  Benefits  How it works (Shibboleth)  Shibboleth components  CSO workflow.
Using Your Own Authentication System with ArcGIS Online
Shibboleth Integration Fairfield University
An authorization service for Virtual Organizations (VO)
Géant-TrustBroker Dynamic inter-federation identity management
ESA Single Sign On (SSO) and Federated Identity Management
The French federation Eurocamp 2007 Helsinki
Some data about the CBIC Federation
Community AAI with Check-In
Presentation transcript:

CARSI: Federated Identity and Resource Sharing over CERNET Dr. PING CHEN Peking University( 北京大学 ) Jan, 24 th, 2008

Agenda Current AAI Situation over CERNET Our Plan: CARSI CARSI Elements  CARSI Infrastructure  CARSI Federation Contract Negotiation & Audit  CARSI Federation Provider Registry  CARSI Virtual Resource Directory  CARSI OpenIdP  CARSI Services Current Deployment Current Focuses

Current AAI situation over CERNET Most Univ. have campus-wide IDM Univ. web applications run in two ways:  accessed publicly without protection  only be visited by a closed set of users Cross-univ. AAI is important to sharing  Sharing object can be user identity resource  Sharing object can also be web applications Cross-univ. AAI and resource sharing is still in the experimental stage

Our Plan: CARSI Cernet Authentication and Resource Sharing Infrastructure Goals:  To integrate university IDMs to a CERNET AAI  To share univ. user account resources over CERNET  To share existing protected web application resources from a closed set of users to CERNET users  To protect existing unprotected web applications  To provide a basic AAI middleware for CERNET applications  To standardize and simplify application’s upgrade to AAI- protected  To push new applications cross universities

CARSI Elements: 1. CARSI infrastructure  Based on SAML/shibboleth 2. CARSI FCNA  Federation Contract Negotiation & Audit 3. CARSI FPR  Federation Provider Registry 4. CARSI OpenIdP  An IdP providing free registered fed account for test users 5. CARSI Services  SP-protected web applications for fed users 6. Others

1. CARSI infrastructure CARSI-Fed: cross-domain federation CARSI-portal  A web portal for fed user login  A web portal providing resource list for fed users CARSI-WAYF: where are you from CARSI-VRD: Virtual Resource Directory CARSI-Person: CARSI User Attribute Specification  CARSI-Uid(Universal user identity): CARSI-IdP: shibboleth IdP + CARSI-SP: shibboleth SP +

Infrastructure Workflow Way 1: 1. Portal login -> 2. select application from resource list -> 3. visit web application Way 2: 1. request to visit web application -> 2. redirected to portal to login -> 3. visit application

CARSI-Portal

Infrastructure Workflow Way 1 Demo Web browser CARSI IdP CARSI SP Application CARSI WAYF CARSI VRD CARSI Portal CARSI SP

Web browser CARSI IdP CARSI SP 1. login with CARSI-Uid Application Infrastructure Workflow Way 1 Demo CARSI WAYF CARSI VRD CARSI Portal CARSI SP

Web browser CARSI IdP CARSI SP 2. Redirect to IdP 3.Pass auth, redirect to VRD 4. Resource list returned to user Application Infrastructure Workflow Way 1 Demo CARSI WAYF CARSI VRD CARSI Portal CARSI SP

Web browser CARSI IdP CARSI SP 5. Select an application to visit 6. Visit SP-protected application 7. First time visit the resource, redirect to WAYF 8. Redirect to visiting user’s IdP 9. The user has passwd auth, redirect to SP Application Infrastructure Workflow Way 1 Demo CARSI WAYF CARSI VRD CARSI Portal CARSI SP

Web browser CARSI IdP CARSI SP CARSI WAYF CARSI VRD CARSI Portal CARSI SP Application 10. Pass authorization, user accesses application Infrastructure Workflow Way 1 Demo

2. CARSI FCNA Federation Contract Negotiation & Audit Goal:  How many and what kind of influences does cross-domain AAI bring to users(IdP) and applications(SP)?  How can cross-domain AAI running in a controllable way? Contract? Negotiation? The economic model?  How is cross-domain AAI being used? What’s user’s using habit? Methods:  Federation log record, aggregation and analysis: IdP log, SP log, Portal log, WAYF log, etc.  Resource sharing statistics Based on IdP, how many IdP users visit other-domain applications, their using habit, etc Based on SP, which domain and what kind of users visit it, what is the peak visiting time, etc  User’s behavior and action tracking Tracing user’s visiting sequence Which visiting sequence is more adopted? How cross-domain AAI benefit them?

CARSI FCNA interfaces

3. CARSI FPR: Federation Provider Registry A system for federation members to manage domain/IdP/SP by themselves Administrators are required to register accounts depending on administrative object Administrator account management is role-based  Role: FedAdmin, OrgAdmin, IdPAdmin, SPAdmin IdP/SP register and management  Followed with corresponding management policy IdP/SP/Admin policy

3. CARSI FPR: Federation Provider Registry FedAdmin  To manage member administrator accounts and member IdP/SPs OrgAdmin  To manage Admins of a domain/organization  Activated by paper documents stamped with organization seal  1 domain may have multiple admins with OrgAdmin role IdPAdmin  To manage 1 IdP  Activated by OrgAdmin or other IdPAdmin for the same IdP  1 IdP may have multiple admins with IdPAdmin role SPAdmin  To manage 1/n SPs  Activated by OrgAdmin or other SPAdmin for the same SP  1 SP may have multiple admins with SPAdmin role

4. CARSI VRD: Virtual Resource Directory A list of sharing web applications One part of CARSI-Portal Synchronized with FPR-registered SPs SP protected Classified and exhibited for user access

5. CARSI-OpenIdP An open identity provider Freely registered Mainly for test purpose

6. CARSI-Services Online served: Black Board System PKU Exquisite Courses Campus IP gateway Content Management System Network Management Systems On-going: CARSI vConf: Video Conference CARSI library others

Current Deployment Members:  5 of 10 CERNET regional nodes: Peking Univ., Tsinghua Univ., BUPT, SCUT, UESTC  1 research institute: Research Institute of Telecommunication Transmission Applications: about 10

Current Deployment

Current Focuses: Complete the above key functions Extend the federation to more universities. Attract more applications. Find out an easy way to make applications shibbolethed

Thank You! CARSI: