glenn wearen 20091203 ifif he anet gwearen

23
Federated Access Glenn Wearen HEAnet

Upload: irish-future-internet-forum

Post on 25-May-2015

776 views

Category:

Technology


0 download

TRANSCRIPT

Page 1: Glenn Wearen 20091203 Ifif He Anet Gwearen

Federated Access

Glenn Wearen

HEAnet

Page 2: Glenn Wearen 20091203 Ifif He Anet Gwearen

TerminologySingle Log On

• single point of authentication (e.g ldap)• synchronised account and credentials• authenticate to each application

Single Sign On• single point of authentication

• single credential, single account• authenticate once

Page 3: Glenn Wearen 20091203 Ifif He Anet Gwearen

TerminologyIdentity Provider

• Organisation that holds identity data/credentials

Service Provider• Organisation accepting federated identities

IdP, SP, OP, RP

Page 4: Glenn Wearen 20091203 Ifif He Anet Gwearen

TerminologyWeb SSO

– OpenID

– Cardspace (Infocard, Higgins etc.)

– SAML, WS-Trust

– Facebook Connect, Friend Connect

– OAuth

Data exchange

Page 5: Glenn Wearen 20091203 Ifif He Anet Gwearen

Federated Access in EducationSAML widely adopted in national academic federations

• UK Access Management Federation

• InCommon

• Switch AAI

• HAKA

• Swamid

• AAF

• Surfederatie

• Feide

• GARR Idem AAI

SAML used in other sectors Realty, Aerospace, Automobile, 401k

Confederation

Page 6: Glenn Wearen 20091203 Ifif He Anet Gwearen

Institutional User Repository

Institutional WebServer

Institutional SAML Server

Service Provider SAML server

Service Provider Web Server

Service Provider User Repository

Federation or Service Provider WAYF Server

Service Provider (SP).

Inst

itutio

n (Id

P).

Page 7: Glenn Wearen 20091203 Ifif He Anet Gwearen

Federated Access in Education

Page 8: Glenn Wearen 20091203 Ifif He Anet Gwearen

– IdP’s• Institutes of Technology

• Universities• Private colleges

• Research agencies

Edugate

Page 9: Glenn Wearen 20091203 Ifif He Anet Gwearen

– SP's• Any IdP can be a SP

• Shared services offered by IdP's• Academic content providers

• Research portals

• Organisations offering academic discount

Edugate

Page 10: Glenn Wearen 20091203 Ifif He Anet Gwearen

Federation is a web of trust underpinned by...– Policy

• Membership rules– Identity providers must ensure identities are assured

– Service providers must not abuse data protection rules

• Confederation/Interfederation

– Technical• Standard protocol

Membership has its benefits

Page 11: Glenn Wearen 20091203 Ifif He Anet Gwearen

Management of identity provider– Consent management

– Attribute release

HEAnet assistance to get started– Directory integration for IdP's

– Application integration for SP's

Membership has its benefits

Page 12: Glenn Wearen 20091203 Ifif He Anet Gwearen

Resource Registry -SP

Page 13: Glenn Wearen 20091203 Ifif He Anet Gwearen

Resource Registry –IdP (i)

Page 14: Glenn Wearen 20091203 Ifif He Anet Gwearen

Resource Registry –IdP (ii)

Page 15: Glenn Wearen 20091203 Ifif He Anet Gwearen

Resource Registry – IdP (iv)

Page 16: Glenn Wearen 20091203 Ifif He Anet Gwearen

Resource Registry – IdP (v)

Page 17: Glenn Wearen 20091203 Ifif He Anet Gwearen

Resource Registry – IdP (v)

Page 18: Glenn Wearen 20091203 Ifif He Anet Gwearen

Future Directions

– Confederation• UK Federation / eduGAIN

– Attribute aggregation• Student account is but one part of a user account

– Who knows?• Schools• Make a 'social' account out of of the 'campus' id.

• National student ID

Page 19: Glenn Wearen 20091203 Ifif He Anet Gwearen

Summary

Terminology

SAML

Edugate

Join us at www.edugate.ie

Page 20: Glenn Wearen 20091203 Ifif He Anet Gwearen
Page 21: Glenn Wearen 20091203 Ifif He Anet Gwearen
Page 22: Glenn Wearen 20091203 Ifif He Anet Gwearen
Page 23: Glenn Wearen 20091203 Ifif He Anet Gwearen