identity management, federating identities, and federations

20
Identity Management, Federating Identities, and Federations November 21, 2006 Kevin Morooney Jeff Kuhns Renee Shuey

Upload: orson-roth

Post on 31-Dec-2015

33 views

Category:

Documents


2 download

DESCRIPTION

Identity Management, Federating Identities, and Federations. November 21, 2006 Kevin Morooney Jeff Kuhns Renee Shuey. Outline. PSU and ITS Identity Management at Penn State Federating and Federations. A little bit about Penn State and ITS. Penn State. Penn State. - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: Identity Management, Federating Identities, and Federations

Identity Management, Federating Identities, and

Federations

November 21, 2006Kevin Morooney

Jeff KuhnsRenee Shuey

Page 2: Identity Management, Federating Identities, and Federations

Outline

‣ PSU and ITS

‣ Identity Management at Penn State

‣ Federating and Federations

Page 3: Identity Management, Federating Identities, and Federations

A little bit about Penn State and ITS...

Page 4: Identity Management, Federating Identities, and Federations

Penn State

Page 5: Identity Management, Federating Identities, and Federations

Penn State

‣ Established 1855, PA’s Land Grant

‣ 24 campus locations

‣ 80K students, 10K faculty, 10K staff

‣ $640M annual research expenditure

Page 6: Identity Management, Federating Identities, and Federations

Information Technology Servicesat

Penn State

Page 7: Identity Management, Federating Identities, and Federations

IdM Level Set• “An integrated system of business processes, policies, and technologies that enable organizations to facilitate and control their users' access to online applications and resources — while protecting confidential personal and business information from unauthorized users. It represents a category of interrelated solutions that are employed to administer user authentication, access, rights, access restrictions, account profiles, passwords, and other attributes supportive of users' roles/profiles on one or more applications or systems. “

• The NMI-EDIT Authentication Roadmap

Page 8: Identity Management, Federating Identities, and Federations

Identity Management at Penn State…

Page 9: Identity Management, Federating Identities, and Federations

Components of IdMat Penn State

‣ Kerberos, DCE, Active Directory

‣ LDAP (eduPerson)

‣ Cosign (WebAccess is local branding)

‣ Shibboleth

‣ Member of InCommon Federation

‣ RSA SecurID Tokens

‣ “Access Account” - branding for Penn State identity (authn only available too), ~120K

‣ “Short Term Access Accounts” (authn only available too), 178/9104 as of 11AM today

‣ “Friends of Penn State” - branding for external identity, ~450K

Page 10: Identity Management, Federating Identities, and Federations

Components of IdM at Penn State - ProofingStart AD20

AgreementAD54

AgreementLibrary

Agreement

Display Password

Newswire?Printing? Newswire Agreement

Printing Agreement

EndSign For Account

No

No

Yes Yes

•GPG Encrypt Signature

•Request E-mail join

•Save all agreements

Page 11: Identity Management, Federating Identities, and Federations

Components of IdMat Penn State – Policy

‣ Student Record Policy

‣ Definition of student records

‣ Definition of student

‣ Public information regarding students

‣ Confidentiality hold

‣ Network Usage Policy

Page 12: Identity Management, Federating Identities, and Federations

Transaction Importance

Tru

st Strength of Identity

Proofing

Page 13: Identity Management, Federating Identities, and Federations

Improving the Quality of Our Digital Identity

‣ Join InCommon Federation

‣ Participate in the eAuthentication project (getting CAF’ed)

‣ Create new service and business models

‣ Create “governance” for IdM

‣ Expire passwords

‣ Increase password strength

Page 14: Identity Management, Federating Identities, and Federations

Federating and Federations…

Page 15: Identity Management, Federating Identities, and Federations

Drivers for Federating in HE

‣ Increasing dependence upon ever richer collaboration

‣ Mandates leading to more research consortia

‣ Increasing number of on-line resources and tools

‣ Access management complexities for resource and tool providers

‣ End-user experience, reliable and efficient to run infrastructure

‣ Federal and State laws & regulations (e. g., FERPA, HIPAA, Gramm-Leach-Bliley Act)

Page 16: Identity Management, Federating Identities, and Federations

The Goal of Federating

‣ Simplified Usability for all collaborations

‣ Home organizations carefully manage the release of personal information

‣ On-line resource providers focus on the protection and authorization of use of their on-line resources.

Page 17: Identity Management, Federating Identities, and Federations

InCommon Federation

‣ Created to support Higher Education and its research and business partners

‣ Federation operator is an LLC operated by Internet2

‣ Builds on existing campus identity management and single sign-on systems

‣ Makes use of open industry standards (SAML) and open source federating software (Shibboleth)

Page 18: Identity Management, Federating Identities, and Federations

eAuthentication Federation

‣ Setting the standards for the identity proofing of individuals and businesses (based on risk of online services used)

‣ Building the necessary infrastructure to support common, unified processes and systems for government-wide use

‣ Helps build the trust that must be an inherent part of every online exchange between citizens and the U.S. Government

Page 19: Identity Management, Federating Identities, and Federations

Figuring out how to work together

Page 20: Identity Management, Federating Identities, and Federations

Before our digital world looks like this…