Top Banner
The (inter)Federa.on Business Licia Florio, TERENA [email protected] APAN, Chang Mai 16 Feb 2012
28

REFEDS Overview

Nov 29, 2014

Download

Technology

refeds

Presentation to REFEDS Bof at APAN33 by Licia Florio
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: REFEDS Overview

The$(inter)Federa.on$Business$

Licia Florio, TERENA [email protected]

APAN, Chang Mai 16 Feb 2012

Page 2: REFEDS Overview

Background

!  R&E community engaged in identity federations for years: "  Remote eLearning "  Access to publishers "  Sharing of resources

!  Growth brings also issues: "  As you will see….

Page 3: REFEDS Overview

Federations

FEDERATIONS…WEREN’T THEY TALKING ABOUT THIS ALREADY IN STAR TREK * ?

NAH HERE THEY MEAN A FORM OF GOVERNANCE !

*!h$p://en.wikipedia.org/wiki/United_Federa7on_of_Planets!

Page 4: REFEDS Overview

MAYBE WE SHOULD REVIEW SOME TERMS FIRST

Page 5: REFEDS Overview

Identity Federations

Adobe$connect!

[email protected]$

[email protected]!

Other$services!

Federa7on!

Technology!

Trust!

SAML!

Legal!agreements!

ONE SET OF CREDENTIALS TO ACCESS MULTIPLE SERVICES!

Page 6: REFEDS Overview

Inter-federations

Enable users from federation A to access services offered by federation B; Requires integration of technology and policies;

Requires agreements among the participating federations;

Page 7: REFEDS Overview

Inter-federation for Network Access

!  "  (inter)federation technical infrastructure based on

hierarchy of RADIUS Servers and 802.1X; "  Trust between members established via the eduroam

policy; "  Global eduroam Governance Committee to ensure

coordination among different continents •  Led by TERENA

Page 8: REFEDS Overview

Where is eduroam

Page 9: REFEDS Overview

Inter-federation for Web Applications

!  eduGAIN entities are a subset of national federations (via opt in) "  Entities have to ask to be included in eduGAIN

!  Profiles and policies to harmonize environment

Courtesy of euGAIN

Page 10: REFEDS Overview

Who is in eduGAIN

Page 11: REFEDS Overview

WHAT’S REFEDS THEN?

Page 12: REFEDS Overview

Some Dates

2004

2010

2004

Page 13: REFEDS Overview

Why, What, Who

Why:!"  To!give!a!‘voice’!to!the!R&E!community!

"  Millions$of$users$across$thousands$of$ins.tu.ons$in$$30$countries!$$$

What:!"  To!harmonise!best!prac7ses,!policies!&!technologies!

"  To!make!federa7ons!more!userNfriendly!"  To!ease!interNfedera7on!!"  To!influence!direc7ons!in!the!global!iden7ty!space!

Who:!"  Experts!in!the!iden7ty!technologies!"  Iden7ty!Federa7ons!around!the!globe!"  UserNgroups!"  Service!providers!!!

REFEDS$

Page 14: REFEDS Overview

Governance

REFEDs$Workplan$$

REFEDs$Sponsors$Funding!used!to!finance!the!workplan!!

Volunteer!work!!$

Funded!work!!

REFEDs$Par.cipants$

REFEDs$SC$!

WHAT$N!Approves!yearly!plan!

N!Monitors!execu7on!N!Advice!REFEDS!

WHO$N!h$ps://refeds.org/about_work.html!!

Workplan!2011N2012:!!h$ps://refeds.org/docs/refedsworkplan11N12FINAL.pdf!

Page 15: REFEDS Overview

Participating Identity Federations

Page 16: REFEDS Overview

Participating Identity Federations

Page 17: REFEDS Overview

SO FEDERATIONS REALLY WORK! !

EHM….YES….BUT….. LIFE IS STILL DIFFICULT FOR SERVICE PROVIDERS!

Page 18: REFEDS Overview

The Issues

!  Harmonisation of attributes

!  Different data protection laws: "  Not easy within Europe "  And then US, Australia, Asia

!  Different business models: "  To charge or not to charge that’s the problem

! Liability insurances for some federations

! Different legal contracts

Just to give some examples

Page 19: REFEDS Overview

Now think about all this when inter-federating!

Page 20: REFEDS Overview

HOW DO REFEDS HELP?!

THEY TRY TO STANDARDISE FEDERATIONS PROCEDURES AND POLICIES TO INCREASE USABILITY OF FEDERATIONS!

Page 21: REFEDS Overview

Some Work Items

ALribute$Release$WG$$(Steven!Carmody,!Internet!2)!

!h$ps://refeds.terena.org/index.php/

REFEDS_A$ribute_release_wg!!!!

!

Barriers$for$Service$Providers$(Nicole!Harris,!JISC!Advance)$$$$h$ps://refeds.terena.org/index.php/

Barriers_for_Service_Providers!

$

PEER$(Public$EndPoint$En..es$Registry)$(Leif!Johansson,!NORDUNET)$$$h$ps://refeds.terena.org/index.php/PEER!!

Page 22: REFEDS Overview

Barriers for Service Providers Mul.ple$legal$documents$Common!clauses!but!presented!in!

different!ways!

Charging$Fees$Different!federa7ons!=!different!business!

model!!

Data$Protec.on$Different!legal!requirements!in!different!

countries.!!

And$there$is$more!$!

h$ps://refeds.terena.org/index.php/Barriers_for_Service_Providers!

Page 23: REFEDS Overview

Attribute Release WG – Goals

!  Find an approach to the data protection/privacy

liability risks and exposures faced by IDPs and SPs in the worldwide Higher R&E environment

!  Find a scalable way to managing attribute release policies

!  Provide recommendations for GUIs and business practices to meet legal and regulatory requirements

Page 24: REFEDS Overview

The INFORM model

!  The IdP is responsible for releasing users’ information

!  Most of the attributes are about user personal information: "  Services should only require necessary attributes;

"  Users should be informed on what attributes are released;

! eduGAIN approach: ask SP to make a declaration to indicate compliance with privacy laws:

INFORM CONSENT!

Page 25: REFEDS Overview

Next Steps

!  Almost finalised recommendations online on the REFEDS wiki: " https://refeds.terena.org/index.php/

Technical_specifications_on_metadata_elements_and_IdP_attribute_release_GUI

Page 26: REFEDS Overview

Conclusions ! REFEDS work is relevant not only to R&E

community: "  But to all working in the identity space;

! REFEDS monitor EU directives on data protection and all standard technologies: "  And tries to provide recommendations;

!  REFEDS results can benefit you: "  Watch the www.refeds.org space

! Let us know your use-cases and how you solve them!

Page 27: REFEDS Overview

Follow us

Website: http://www.refeds.org

Mailing list: https://www.terena.org/mail-archives/refeds/

Visits

Wiki: https://refeds.terena.org

Page 28: REFEDS Overview

TERENA Networking Conference 2012

Networking to Services

Keynote speakers: Hilmar Veigar Pétursson, CCP Geoff Huston, APNIC Nicole Harris, JISC Advance Jan-Martin Lowendahl, Gartner Research Jacob Appelbaum, University of Washington Leslie Daigle, Internet Society (ISOC)

21 to 24 May 2012 Reykjavik, Iceland tnc2012.terena.org