SlideShare une entreprise Scribd logo
1  sur  23
Télécharger pour lire hors ligne
Federated Access

   Glenn Wearen
      HEAnet
Terminology
Single Log On
    • single point of authentication (e.g ldap)
    • synchronised account and credentials
    • authenticate to each application
Single Sign On
    • single point of authentication
    • single credential, single account
    • authenticate once
Terminology
Identity Provider
     • Organisation that holds identity data/credentials


 Service Provider
     • Organisation accepting federated identities


                     IdP, SP, OP, RP
Terminology
Web SSO
 –   OpenID
 –   Cardspace (Infocard, Higgins etc.)
 –   SAML, WS-Trust
 –   Facebook Connect, Friend Connect
 –   OAuth
 Data exchange
Federated Access in Education
SAML widely adopted in national academic federations
     • UK Access Management Federation
     • InCommon
     • Switch AAI
     • HAKA
     • Swamid
     • AAF                                 Confederation
     • Surfederatie
     • Feide
     • GARR Idem AAI


      SAML used in other sectors Realty, Aerospace, Automobile, 401k
Federation or Service
                                                                 Provider WAYF
                                                                 Server



                                         Institutional SAML
                                         Server
                                                                                     Service Provider
                                                                                     SAML server




                                                                        Service Provider Web
                                                                        Server




                                                                       Se
Institutional User   Institutional Web




                                                                         rvi
                                                                            c
Repository           Server




                                                                           eP
                                                          .  )




                                                                                rov
                                                         IdP




                                                                                   ide
                                                       n(




                                                                                      r(
                                                    tio




                                                                                     SP
                                                titu




                                                                                        )
                                            Ins




                                                                                           .
                                                                    Service Provider User
                                                                    Repository
Federated Access in Education
Edugate
– IdP’s
  •   Institutes of Technology
  •   Universities
  •   Private colleges
  •   Research agencies
Edugate
– SP's
 •   Any IdP can be a SP
 •   Shared services offered by IdP's
 •   Academic content providers
 •   Research portals
 •   Organisations offering academic discount
Membership has its benefits
Federation is a web of trust underpinned by...
  – Policy
     • Membership rules
        – Identity providers must ensure identities are assured
        – Service providers must not abuse data protection rules
     • Confederation/Interfederation
  – Technical
     • Standard protocol
Membership has its benefits
Management of identity provider
  – Consent management
  – Attribute release
HEAnet assistance to get started
  – Directory integration for IdP's
  – Application integration for SP's
Resource Registry -SP
Resource Registry –IdP (i)
Resource Registry –IdP (ii)
Resource Registry – IdP (iv)
Resource Registry – IdP (v)
Resource Registry – IdP (v)
Future Directions
– Confederation
  • UK Federation / eduGAIN
– Attribute aggregation
  • Student account is but one part of a user account
– Who knows?
  • Schools
  • Make a 'social' account out of of the 'campus' id.
  • National student ID
Summary
      Terminology

         SAML

        Edugate

Join us at www.edugate.ie
Glenn Wearen 20091203 Ifif He Anet Gwearen
Glenn Wearen 20091203 Ifif He Anet Gwearen
Glenn Wearen 20091203 Ifif He Anet Gwearen
Glenn Wearen 20091203 Ifif He Anet Gwearen

Contenu connexe

En vedette

Drugsbeleid in jeughdhuizen
Drugsbeleid in jeughdhuizenDrugsbeleid in jeughdhuizen
Drugsbeleid in jeughdhuizen
1003501090
 
Visual Process, an innovative analytical solution by bridging business and da...
Visual Process, an innovative analytical solution by bridging business and da...Visual Process, an innovative analytical solution by bridging business and da...
Visual Process, an innovative analytical solution by bridging business and da...
Avraham CHOUKROUN
 
Cultura y educación
Cultura y educaciónCultura y educación
Cultura y educación
lauraback18
 

En vedette (19)

Drugsbeleid in jeughdhuizen
Drugsbeleid in jeughdhuizenDrugsbeleid in jeughdhuizen
Drugsbeleid in jeughdhuizen
 
Com Score Webinar Getting Beyond Big In Online Video
Com Score Webinar   Getting Beyond Big In Online VideoCom Score Webinar   Getting Beyond Big In Online Video
Com Score Webinar Getting Beyond Big In Online Video
 
Cian Blackwell - Risk management and mitigation 2011
Cian Blackwell - Risk management and mitigation 2011Cian Blackwell - Risk management and mitigation 2011
Cian Blackwell - Risk management and mitigation 2011
 
Imelda Lambkin - Fp7 At Future Internet 091
Imelda Lambkin - Fp7 At Future Internet 091Imelda Lambkin - Fp7 At Future Internet 091
Imelda Lambkin - Fp7 At Future Internet 091
 
Who Smokes? Do You?
Who Smokes? Do You?Who Smokes? Do You?
Who Smokes? Do You?
 
Future internet Forum Google - Eoghan Nolan.
Future internet Forum Google - Eoghan Nolan. Future internet Forum Google - Eoghan Nolan.
Future internet Forum Google - Eoghan Nolan.
 
WhoSmokes?
WhoSmokes?WhoSmokes?
WhoSmokes?
 
SFI Irish Future Internet Forum
SFI Irish Future Internet ForumSFI Irish Future Internet Forum
SFI Irish Future Internet Forum
 
Publish Ireland Future Internet St Eloff
Publish Ireland Future Internet St EloffPublish Ireland Future Internet St Eloff
Publish Ireland Future Internet St Eloff
 
Visual Process, an innovative analytical solution by bridging business and da...
Visual Process, an innovative analytical solution by bridging business and da...Visual Process, an innovative analytical solution by bridging business and da...
Visual Process, an innovative analytical solution by bridging business and da...
 
InsulLiving House Energy Performance Report
InsulLiving House Energy Performance ReportInsulLiving House Energy Performance Report
InsulLiving House Energy Performance Report
 
Cultura y educación
Cultura y educaciónCultura y educación
Cultura y educación
 
Ray Carroll, TSSG - Sustainable and Energy Efficient Data Centre
Ray Carroll, TSSG - Sustainable and Energy Efficient Data CentreRay Carroll, TSSG - Sustainable and Energy Efficient Data Centre
Ray Carroll, TSSG - Sustainable and Energy Efficient Data Centre
 
Barbara Fogerty, Marine Institute - Extended Recognised Maritime Picture to S...
Barbara Fogerty, Marine Institute - Extended Recognised Maritime Picture to S...Barbara Fogerty, Marine Institute - Extended Recognised Maritime Picture to S...
Barbara Fogerty, Marine Institute - Extended Recognised Maritime Picture to S...
 
Jacques Bus F I I R L Presentation J B
Jacques  Bus  F I  I R L  Presentation  J BJacques  Bus  F I  I R L  Presentation  J B
Jacques Bus F I I R L Presentation J B
 
Willie Donnelly IFIF
Willie Donnelly IFIFWillie Donnelly IFIF
Willie Donnelly IFIF
 
Lindadoyle
LindadoyleLindadoyle
Lindadoyle
 
Session 3 Results
Session 3 ResultsSession 3 Results
Session 3 Results
 
Cultura y educación
Cultura y educaciónCultura y educación
Cultura y educación
 

Similaire à Glenn Wearen 20091203 Ifif He Anet Gwearen

Compatible one cloud expowest nov 2012
Compatible one cloud expowest nov 2012Compatible one cloud expowest nov 2012
Compatible one cloud expowest nov 2012
CompatibleOne
 
Web standards, why care?
Web standards, why care?Web standards, why care?
Web standards, why care?
Thomas Roessler
 
Service Oriented Application Development Sterpka
Service Oriented Application Development   SterpkaService Oriented Application Development   Sterpka
Service Oriented Application Development Sterpka
bsterpka
 
CrossRef Annual Meeting 2012 CrossRef Overview Ed Pentz
CrossRef Annual Meeting 2012 CrossRef Overview Ed PentzCrossRef Annual Meeting 2012 CrossRef Overview Ed Pentz
CrossRef Annual Meeting 2012 CrossRef Overview Ed Pentz
Crossref
 
Vodafone xone fev142013v3 ext
Vodafone xone fev142013v3 extVodafone xone fev142013v3 ext
Vodafone xone fev142013v3 ext
InfiniteGraph
 
Market Research Report : Cloud Computing Market in India 2010
Market Research Report : Cloud Computing Market in India 2010Market Research Report : Cloud Computing Market in India 2010
Market Research Report : Cloud Computing Market in India 2010
Netscribes, Inc.
 
Icws10 lecue-gorronogoitia-gonzalez-radzimski-villa-presentation
Icws10 lecue-gorronogoitia-gonzalez-radzimski-villa-presentationIcws10 lecue-gorronogoitia-gonzalez-radzimski-villa-presentation
Icws10 lecue-gorronogoitia-gonzalez-radzimski-villa-presentation
Freddy Lecue
 
IBM Pulse 2013 session - DevOps for Mobile Apps
IBM Pulse 2013 session - DevOps for Mobile AppsIBM Pulse 2013 session - DevOps for Mobile Apps
IBM Pulse 2013 session - DevOps for Mobile Apps
Sanjeev Sharma
 

Similaire à Glenn Wearen 20091203 Ifif He Anet Gwearen (20)

FederatedAccessOpenStack.pdf
FederatedAccessOpenStack.pdfFederatedAccessOpenStack.pdf
FederatedAccessOpenStack.pdf
 
Compatible one cloud expowest nov 2012
Compatible one cloud expowest nov 2012Compatible one cloud expowest nov 2012
Compatible one cloud expowest nov 2012
 
Linking Services and Linked Data: Keynote for AIMSA 2012
Linking Services and Linked Data: Keynote for AIMSA 2012Linking Services and Linked Data: Keynote for AIMSA 2012
Linking Services and Linked Data: Keynote for AIMSA 2012
 
Campus Perspectives on OpenRegistry
Campus Perspectives on OpenRegistryCampus Perspectives on OpenRegistry
Campus Perspectives on OpenRegistry
 
UNINETT IoU - UWAP Prototype
UNINETT IoU - UWAP PrototypeUNINETT IoU - UWAP Prototype
UNINETT IoU - UWAP Prototype
 
UTHOC2 - Under The Hood of Oracle Clusterware 2.0 - Grid Infrastructure by Al...
UTHOC2 - Under The Hood of Oracle Clusterware 2.0 - Grid Infrastructure by Al...UTHOC2 - Under The Hood of Oracle Clusterware 2.0 - Grid Infrastructure by Al...
UTHOC2 - Under The Hood of Oracle Clusterware 2.0 - Grid Infrastructure by Al...
 
Web standards, why care?
Web standards, why care?Web standards, why care?
Web standards, why care?
 
Service Oriented Application Development Sterpka
Service Oriented Application Development   SterpkaService Oriented Application Development   Sterpka
Service Oriented Application Development Sterpka
 
CrossRef Annual Meeting 2012 CrossRef Overview Ed Pentz
CrossRef Annual Meeting 2012 CrossRef Overview Ed PentzCrossRef Annual Meeting 2012 CrossRef Overview Ed Pentz
CrossRef Annual Meeting 2012 CrossRef Overview Ed Pentz
 
Vodafone xone fev142013v3 ext
Vodafone xone fev142013v3 extVodafone xone fev142013v3 ext
Vodafone xone fev142013v3 ext
 
Open Source
Open SourceOpen Source
Open Source
 
Market Research Report : Cloud Computing Market in India 2010
Market Research Report : Cloud Computing Market in India 2010Market Research Report : Cloud Computing Market in India 2010
Market Research Report : Cloud Computing Market in India 2010
 
Os Pittaro
Os PittaroOs Pittaro
Os Pittaro
 
First Operational Technology (OT) High Performance Messaging Patterns for Ent...
First Operational Technology (OT) High Performance Messaging Patterns for Ent...First Operational Technology (OT) High Performance Messaging Patterns for Ent...
First Operational Technology (OT) High Performance Messaging Patterns for Ent...
 
Icws10 lecue-gorronogoitia-gonzalez-radzimski-villa-presentation
Icws10 lecue-gorronogoitia-gonzalez-radzimski-villa-presentationIcws10 lecue-gorronogoitia-gonzalez-radzimski-villa-presentation
Icws10 lecue-gorronogoitia-gonzalez-radzimski-villa-presentation
 
Lean- automobile
Lean- automobileLean- automobile
Lean- automobile
 
Cloud foundry - the building of the open paas presentation
Cloud foundry - the building of the open paas presentationCloud foundry - the building of the open paas presentation
Cloud foundry - the building of the open paas presentation
 
OSCON 2011
OSCON 2011OSCON 2011
OSCON 2011
 
Leveraging IMS for VoLTE and RCS Services in LTE Networks Presented by Adnan ...
Leveraging IMS for VoLTE and RCS Services in LTE Networks Presented by Adnan ...Leveraging IMS for VoLTE and RCS Services in LTE Networks Presented by Adnan ...
Leveraging IMS for VoLTE and RCS Services in LTE Networks Presented by Adnan ...
 
IBM Pulse 2013 session - DevOps for Mobile Apps
IBM Pulse 2013 session - DevOps for Mobile AppsIBM Pulse 2013 session - DevOps for Mobile Apps
IBM Pulse 2013 session - DevOps for Mobile Apps
 

Plus de Irish Future Internet Forum

Plus de Irish Future Internet Forum (13)

NEMBES Future Internet position - Dirk Pesch
NEMBES Future Internet position - Dirk PeschNEMBES Future Internet position - Dirk Pesch
NEMBES Future Internet position - Dirk Pesch
 
IBM Research Future Internet
IBM Research Future InternetIBM Research Future Internet
IBM Research Future Internet
 
Michel Riguidel - ENST the Future of the Internet
Michel Riguidel - ENST the Future of the InternetMichel Riguidel - ENST the Future of the Internet
Michel Riguidel - ENST the Future of the Internet
 
Malcolm Crompton, IIS Partners Irish Future Internet Forum - Socioeconomics
Malcolm Crompton, IIS Partners Irish Future Internet Forum - SocioeconomicsMalcolm Crompton, IIS Partners Irish Future Internet Forum - Socioeconomics
Malcolm Crompton, IIS Partners Irish Future Internet Forum - Socioeconomics
 
Model Smart City Barcelona
Model Smart City BarcelonaModel Smart City Barcelona
Model Smart City Barcelona
 
Irish Future Internet Forum Zed Sabeur
Irish Future Internet Forum Zed SabeurIrish Future Internet Forum Zed Sabeur
Irish Future Internet Forum Zed Sabeur
 
IFIF 2011 opening - Willie Donnelly
IFIF 2011 opening - Willie DonnellyIFIF 2011 opening - Willie Donnelly
IFIF 2011 opening - Willie Donnelly
 
Sdecker
SdeckerSdecker
Sdecker
 
Donal Simmie Ifif Poster 1209
Donal Simmie Ifif Poster 1209Donal Simmie Ifif Poster 1209
Donal Simmie Ifif Poster 1209
 
Think Trust A1 Poster Em Final Version
Think Trust A1 Poster Em Final VersionThink Trust A1 Poster Em Final Version
Think Trust A1 Poster Em Final Version
 
Mickposter Nuim
Mickposter NuimMickposter Nuim
Mickposter Nuim
 
Dleigh
DleighDleigh
Dleigh
 
IFIF Agenda
IFIF AgendaIFIF Agenda
IFIF Agenda
 

Dernier

Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
Joaquim Jorge
 

Dernier (20)

Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 

Glenn Wearen 20091203 Ifif He Anet Gwearen

  • 1. Federated Access Glenn Wearen HEAnet
  • 2. Terminology Single Log On • single point of authentication (e.g ldap) • synchronised account and credentials • authenticate to each application Single Sign On • single point of authentication • single credential, single account • authenticate once
  • 3. Terminology Identity Provider • Organisation that holds identity data/credentials Service Provider • Organisation accepting federated identities IdP, SP, OP, RP
  • 4. Terminology Web SSO – OpenID – Cardspace (Infocard, Higgins etc.) – SAML, WS-Trust – Facebook Connect, Friend Connect – OAuth Data exchange
  • 5. Federated Access in Education SAML widely adopted in national academic federations • UK Access Management Federation • InCommon • Switch AAI • HAKA • Swamid • AAF Confederation • Surfederatie • Feide • GARR Idem AAI SAML used in other sectors Realty, Aerospace, Automobile, 401k
  • 6. Federation or Service Provider WAYF Server Institutional SAML Server Service Provider SAML server Service Provider Web Server Se Institutional User Institutional Web rvi c Repository Server eP . ) rov IdP ide n( r( tio SP titu ) Ins . Service Provider User Repository
  • 8. Edugate – IdP’s • Institutes of Technology • Universities • Private colleges • Research agencies
  • 9. Edugate – SP's • Any IdP can be a SP • Shared services offered by IdP's • Academic content providers • Research portals • Organisations offering academic discount
  • 10. Membership has its benefits Federation is a web of trust underpinned by... – Policy • Membership rules – Identity providers must ensure identities are assured – Service providers must not abuse data protection rules • Confederation/Interfederation – Technical • Standard protocol
  • 11. Membership has its benefits Management of identity provider – Consent management – Attribute release HEAnet assistance to get started – Directory integration for IdP's – Application integration for SP's
  • 18. Future Directions – Confederation • UK Federation / eduGAIN – Attribute aggregation • Student account is but one part of a user account – Who knows? • Schools • Make a 'social' account out of of the 'campus' id. • National student ID
  • 19. Summary Terminology SAML Edugate Join us at www.edugate.ie