federated identity management for research: the key is ... · authentication provided by x.509...

48
Federated Identity Management for Research: The Key is Collaboration

Upload: others

Post on 09-Oct-2020

0 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

Federated Identity Management for Research: The Key is Collaboration

Page 2: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

Federated Identity Management for Research:The Key is CollaborationHannah ShortCERN, Identity Federation ManagerAARC Project Participant

With thanks to input from the FIM4R Community and AARC

2

Page 3: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

Who am I?• My job = making digital life

for researchers more secure• Based at CERN• Spend most of my time

working with others like me around the world

3

Page 4: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

The Past

4

Page 5: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

5Image: Maximilen Brice/CERN

Page 6: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

supply - demand = ?

6

Page 7: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

7http://wlcg-public.web.cern.ch

Page 8: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

8

Data

Par

ticip

ants

Page 9: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

9

Field Users Countries Computing Sites

LIGO Gravitational Waves

1,200 20 9

WLCG (CERN)

High Energy Physics

13,000 43 170

ESGF Climate Science

17,000 13 18

Source: http://doi.org/10.5281/zenodo.129603

Page 10: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

The challenge- Large, global user community- Working on a distributed infrastructure- Don’t necessarily know each other- Don’t necessarily ever meet

How can we securely provision digital identities that are trusted by the infrastructure?

10

Page 11: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

11

A: The Research Community B: The Infrastructure

C: The Home Organisation D: Nobody

Who knows the user best?

Page 12: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

12

A: The Research Community B: The Infrastructure

C: The Home Organisation D: Nobody

Who knows the user best?

Page 13: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

13

A: The Research Community B: The Infrastructure

C: The Home Organisation D: Nobody

Who knows what they are working on?

Page 14: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

14

A: The Research Community B: The Infrastructure

C: The Home Organisation D: Nobody

Who knows what they are working on?

Page 15: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

Authentication vs Authorisation

15

Page 16: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

16

Trusted Identity Provider Research

Community

AuthenticationAuthoris

ation

Infrastructure

Page 17: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

● Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

● Authorisation provided by Research Communities adding certificate extensions

2000s

17

Page 18: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

18

Trusted Identity Provider Research

Community

Infrastructure

Where’s the trust?

Page 19: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

19

Trusted Identity Provider Research

Community

AuthenticationAuthoris

ation

Infrastructure

I just wasted 30 minutes with my student trying to sort out his certificate...

Page 20: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

The hope that SAML federations (and Interfederation through eduGAIN) could provide a better solution

2010s

20https://www.geant.org/Services/Trust_identity_and_security/eduGAIN/Pages/About-eduGAIN.aspx

Page 21: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

21

Trusted Identity Provider Research

Community

Infrastructure

Where’s the trust?

Federation

Page 22: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

The realisation that SAML Federations were one small piece of the puzzle

2015+

22https://aarc-project.eu/architecture/

Page 23: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

The realisation that SAML Federations were one small piece of the puzzle

2015+

23https://aarc-project.eu/architecture/

Page 24: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

The Present

24

Page 25: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

AARCAuthentication and Authorisation for Research and Collaboration

25

Page 26: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

26

Page 27: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

Many success stories• gw-astronomy.org • Collaboration hub for

gravitational-wave and multi-messenger astronomy (MMA)

• Used to manage collaboration around the August 17, 2017 kilonova event

27

• EU Photon & Neutron facilities

• Single Sign On for 16 light sources

• Steady growth rate of 20% per year

Slide taken from FIM4R Session, TNC2018

Page 28: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

Is the challenge now solved?

28

Page 29: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

29

** Not all contributors’ logos represented

Page 30: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

30

Page 31: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

Research representation, funding for sustainable operation, ongoing coordination

Governance & Sustainability

Attribute release, remove interoperability barriers, non-legal status, user mobility

Baseline of User Experience

For federations, interfederation and organisations

Security Incident Response Readiness

Reuse generic services, follow best practices for interoperability

Harmonisation of Proxy Operations & Practices

Support multifactor authentication and publish Assurance Profiles

Sensitive Research User Experience

31

FIM4R Recommendations

Slide taken from FIM4R Session, TNC2018

Page 32: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

Security, a closer look

32

Page 33: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

Security, a closer look

33https://docs.oasis-open.org/security/saml/v2.0/saml-metadata-2.0-os.pdf

Page 34: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

Attribute release, a closer look

34

Identity Provider

Research Service

IDNameEmail

Page 35: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

Nine Stakeholder Groups to address• General Stakeholders

• Network coordinators and operators: GÉANT (Europe), Internet2 (US)

• Research funding bodies • REFEDS (Research and Education FEDerations group)

• Identity federation stakeholders• Researchers’ Home organisations• National R&E federations• eduGAIN operators providing the Interfederation

• Research stakeholders• Generic e-infrastructures• Research community proxies in particular• Research communities

35Slide taken from FIM4R Session, TNC2018

Page 36: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

Nine Stakeholder Groups to address• General Stakeholders

• Network coordinators and operators: GÉANT (Europe), Internet2 (US)

• Research funding bodies • REFEDS (Research and Education FEDerations group)

• Identity federation stakeholders• Researchers’ Home organisations• National R&E federations• eduGAIN operators providing the Interfederation

• Research stakeholders• Generic e-infrastructures• Research community proxies in particular• Research communities

36Slide taken from FIM4R Session, TNC2018

Collaboration is critical

Page 37: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

The Future

37

Page 38: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

Trends

38

Diverse compute resources

New Protocols

Increased focus on Data

Protection

Increased focus on Operational

Security

Research Community AAIs

Infrastructure AAIs

Page 39: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

What does this mean for Research Infrastructures?

39

Page 40: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

40https://aarc-project.eu/wp-content/uploads/2018/09/AARC2-DJRA1.1-V3-v3FINAL.pdf

Page 41: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

41https://aarc-project.eu/wp-content/uploads/2018/09/AARC2-DJRA1.1-V3-v3FINAL.pdf

Page 42: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

42

Page 43: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

Impact• Interoperability fundamental

• Technical• Policy

• Overhead of AAI significant• Hosted options will be critical• Sustainable support for key components required

The FIM4R Recommendations go some way to defining the path towards an interoperable future

43

Page 44: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

44

A: Read the FIM4R Paper B: Share with others

C: Think of the Researchers D: Nothing

What can you do?

Page 45: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

45

A: Read the FIM4R Paper B: Share with others

C: Think of the Researchers D: Nothing

What can you do?

Page 46: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

“Every researcher is entitled to focus on their work and not be impeded by needless obstacles nor required to understand anything about the FIM infrastructure enabling their access to research services.” FIM4R version 2

46

Page 47: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)

fim4r.org

47

Page 48: Federated Identity Management for Research: The Key is ... · Authentication provided by X.509 certificates from trusted Certificate Authorities (ID vetting, strong policy set)