SlideShare una empresa de Scribd logo
1 de 18
Descargar para leer sin conexión
eduTEAMS
Niels Van Dijk,
SURFnet
GÉANT supports and represents over 40 NRENs across Europe.
Together they support over 10,000 institutions and 50 million academic users.
About GÉANT
eduroam - secure global roaming access service 250+ million authentications per
month in 89 territories
eduGAIN - interconnects identity federations around the world, simplifying access to
content, services and resources ~ 3500 identity providers accessing services
AARC project – collaborating with e-infrastructures, research collaborations,
libraries & federations to share policies, architectures, training materials & pilots that
avoid re-inventing the authentication & authorisation wheel
REFEDs – supporting identity federations worldwide
Trusted Introducer – services for security and incident response teams
Certificate Service – delivering cost-effective digital certificates.
In partnership with
Supporting users and enabling secure access to services
Trust, Identity & Security
• Challenges in Authentication space
• International Collaboration
• Collaborative organisations work with people outside
scope of R&E communities as well
• Requires Collaborative organisations to peer with other
non R&E Identity providers or maintain an additional
Identity provider
• Challenges in Authorization space
• Services run by Collaborative Organisations often need
attribute or group related information in the context of
their collaboration, which are not issued by Institutions
• Requires Collaborative Organisations to manage and
provide additional attributes and groups towards their
services, independently from the Institutions
4
Challenges for Collaborative Organisations
• The FIM4R paper (April 2012) was one of the first to articulate
collective requirements for using Federated AAI for VOs.
• The VOPaaS has performed a survey among several small and
large Pan-European VOs to (re-)validate the requirements.
5
Market Analysis
6
Market Analysis Results
http://www.geant.org/Projects/GEANT_Project_GN4-1/deliverables/D9-2_Market-
Analysis-for-Virtual-Organisation-Platform-as-a-Service.pdf
• Goal
• Investigate the conditions that would allow GÉANT to provide
services to support Collaborative organisations
• Focus on delivery of technical services
• Out of scope:
• Technical development
• Policy & LOA development
• Activities
• Gather requirements and priorities with/from communities
• Look at existing tools and technologies
• Look into delivery model
• Investigate business case & sustainability
• Pilot with communities
• Operations and Market
7
GEANT CO Platform as a Service Project
Objectives Conclusions Q&AChallenges Achievements
Components
• eduTEAMS Membership
Management service
• eduTEAMS Discovery
Service
• eduTEAMS Identity Hub
Characteristics
• 2 monthly release cycle
• Supports AARC
architecture
• Single- and multi-tenant
options
Documentation, Cookbooks,
Privacy Policy etc available
https://wiki.geant.org/display/ED
eduTEAMS
A suite of services for using federated AAI for collaborations
Collaboration suite
to enable use of
federated identity
in research
communities
Partner for any e-
Infra or Research
Infra inc. “long tail”,
informal groups
8
eduTEAMS - Pilots
Engaging with communities, eInfras and NRENs
9
Research communities and
e-Infrastructures
• AARC2-as-VO (Pilot committed)
• LifeScience AAI (Pilot)
• Umbrella (Pilot committed)
• HPC-Europe (Pilot intrest)
• EUDAT (Pilot committed)*
• EGI *
* as part of AARC2 interoperability
activity
NRENS
• JISC (UK)
Moonshot Pathfinder project
• SURFnet (NL)
Science Collaboration Zone project
• WAYF (DK)
eduVPN
Collaboration usecases
Components – LEGO approach
Choose how much of the platform they want
• eduTEAMS Membership Management service
• VO specific workflows for onboarding members
• Registry for VO persistent Identifier
• Limited set of attributes to maximise interoperability
• Use of eduperson entitlement to carry richer info
• Available through eduGAIN
• eduTEAMS Identity Hub
• One persistent (SAML) IdP for many ‘Guest’ Identity Providers
• Available and accessible through eduGAIN
• Supports Research and Scholarship Entity Category
• Discovery Service
• Service based or embedded discovery for eduGAIN SPs
• Allows per SP filtering of IdPs
• Allows per entity category filtering, e.g. R&S
11
eduTEAMS
ecosystem
REST AA
SAML AA
COmanage
eduTEAMS
Membership
Managemen
t
eduTEAMS
Identity Hub
IdP
AuthN:
ID + attributes
External IdP
SP(proxy)
Objectives Conclusions Q&AChallenges Achievements 12
eduTEAMS
Membership Management Service (MMS)
Manage Roles and Rights
• Available trough eduGAIN
• CoCo and R&S supported
• Strong focus on privacy and GDPR
• part of AARC2 interop activity
• Technical and cookbooks:
https://wiki.geant.org/display/ED/Membership
+Management+Service
• Service:
https://registry.eduTEAMS.org
NRENS
• JISC (Pilot committed)
• Moonshot Pathfinder project
• SURFnet (Pilot committed)
• Science Collaboration Zone project
• GARR (Pilot interest)
• SWITCH (Pilot interest)
• SWITCH eduID
• Swiss Personalised Health Network
• Swiss Data Science Center
• Swiss National Supercomputing Centre
Objectives Conclusions Q&AChallenges Achievements
eduTEAMS
Discovery Service
• Component of eduTEAMS, but
generically usable for eduGAIN SPs
• Based on proven service from CESNET
• Engaged in RA21 Pilot – Resource Access
for the 21st Century (https://ra21.org)
• Publishers, libraries and users
https://wiki.geant.org/display/ED/Discovery+Servic
e
13
Objectives Conclusions Q&AChallenges Achievements 14
eduTEAMS Identity
Hub Persistent ID
Account
Recovery
LOA
Implemented
Future
eduTEAMS
Identity Hub
https://wiki.geant.org/display/ED/Identity+Hub
• Moonshot interaction with third-party AA systems
• investigate potential for Assent service
• and also all kinds of scientific collaborations
• Combined access & authorization for web-based and non-web based
services
JISC eduTEAMS pilot
15
Moonshot and eduTEAMS
16
SAML AA
COmanage
eduTEAMS
Membership
Management
eduTEAMS
Identity Hub
IdP
External IdP
Webbased
Service
Moonshot
Compute
resource
Storage
resource
Groups
& roles
Any questions?
Thank you
Any questions?
Thank you
Any questions? /
Thank you

Más contenido relacionado

La actualidad más candente

Wasn't expecting that! Now what?
Wasn't expecting that! Now what?Wasn't expecting that! Now what?
Wasn't expecting that! Now what?
Jisc
 
10 Tech Trends in Healthcare
10 Tech Trends in Healthcare10 Tech Trends in Healthcare
10 Tech Trends in Healthcare
Extreme Networks
 

La actualidad más candente (20)

How to streamline data governance and security across on-prem and cloud?
How to streamline data governance and security across on-prem and cloud?How to streamline data governance and security across on-prem and cloud?
How to streamline data governance and security across on-prem and cloud?
 
Location, location, location - HPE Aruba
Location, location, location - HPE ArubaLocation, location, location - HPE Aruba
Location, location, location - HPE Aruba
 
Trust and identity
Trust and identityTrust and identity
Trust and identity
 
Keynote Theatre. Keynote Day 2. 16:30 Evelyn de Souza
Keynote Theatre. Keynote Day 2. 16:30   Evelyn de Souza Keynote Theatre. Keynote Day 2. 16:30   Evelyn de Souza
Keynote Theatre. Keynote Day 2. 16:30 Evelyn de Souza
 
Cyber Security - Maintaining Operational Control of Critical Services
Cyber Security - Maintaining Operational Control of Critical ServicesCyber Security - Maintaining Operational Control of Critical Services
Cyber Security - Maintaining Operational Control of Critical Services
 
Wasn't expecting that! Now what?
Wasn't expecting that! Now what?Wasn't expecting that! Now what?
Wasn't expecting that! Now what?
 
ePlus Enabling a Total Healthcare IT Transformation to Deliver the Future of ...
ePlus Enabling a Total Healthcare IT Transformation to Deliver the Future of ...ePlus Enabling a Total Healthcare IT Transformation to Deliver the Future of ...
ePlus Enabling a Total Healthcare IT Transformation to Deliver the Future of ...
 
Mobility Trends Impacting Healthcare
Mobility Trends Impacting HealthcareMobility Trends Impacting Healthcare
Mobility Trends Impacting Healthcare
 
Novel cloud computingsecurity issues
Novel cloud computingsecurity issuesNovel cloud computingsecurity issues
Novel cloud computingsecurity issues
 
Protecting Innovation Through Next Generation Enterprise File Sharing
Protecting Innovation Through Next Generation Enterprise File SharingProtecting Innovation Through Next Generation Enterprise File Sharing
Protecting Innovation Through Next Generation Enterprise File Sharing
 
Enabling Science with Trust and Security – Guest Keynote
Enabling Science with Trust and Security – Guest KeynoteEnabling Science with Trust and Security – Guest Keynote
Enabling Science with Trust and Security – Guest Keynote
 
Cure for the Common Cloud: How Healthcare can Safely Enable the Cloud
Cure for the Common Cloud: How Healthcare can Safely Enable the CloudCure for the Common Cloud: How Healthcare can Safely Enable the Cloud
Cure for the Common Cloud: How Healthcare can Safely Enable the Cloud
 
(SACON) Srinivas posarala - Challenges & Approach
(SACON) Srinivas posarala - Challenges & Approach(SACON) Srinivas posarala - Challenges & Approach
(SACON) Srinivas posarala - Challenges & Approach
 
Crossing the Threshold: Clinical Portals from a Site Perspective
Crossing the Threshold: Clinical Portals from a Site Perspective Crossing the Threshold: Clinical Portals from a Site Perspective
Crossing the Threshold: Clinical Portals from a Site Perspective
 
Shadow IT: The CISO Perspective on Regaining Control
Shadow IT: The CISO Perspective on Regaining ControlShadow IT: The CISO Perspective on Regaining Control
Shadow IT: The CISO Perspective on Regaining Control
 
Ann West- Trust Federations: What We Have In Common
Ann West- Trust Federations: What We Have In CommonAnn West- Trust Federations: What We Have In Common
Ann West- Trust Federations: What We Have In Common
 
Moving healthcare applications to the cloud
Moving healthcare applications to the cloudMoving healthcare applications to the cloud
Moving healthcare applications to the cloud
 
Open Platforms for Healthcare Applications
Open Platforms for Healthcare ApplicationsOpen Platforms for Healthcare Applications
Open Platforms for Healthcare Applications
 
10 Tech Trends in Healthcare
10 Tech Trends in Healthcare10 Tech Trends in Healthcare
10 Tech Trends in Healthcare
 
Cybersecurity Challenges in Healthcare
Cybersecurity Challenges in HealthcareCybersecurity Challenges in Healthcare
Cybersecurity Challenges in Healthcare
 

Similar a eduTEAMS

Internet2 and Cyberinfrastructure
Internet2 and CyberinfrastructureInternet2 and Cyberinfrastructure
Internet2 and Cyberinfrastructure
karl.barnes
 
Digital Transformation at the University of Edinburgh
Digital Transformation at the University of EdinburghDigital Transformation at the University of Edinburgh
Digital Transformation at the University of Edinburgh
Mark Ritchie
 

Similar a eduTEAMS (20)

Building Successful API Programs in Higher Education
Building Successful API Programs in Higher EducationBuilding Successful API Programs in Higher Education
Building Successful API Programs in Higher Education
 
Trust and identity in the Géant project - Networkshop44
Trust and identity in the Géant project - Networkshop44Trust and identity in the Géant project - Networkshop44
Trust and identity in the Géant project - Networkshop44
 
BDVA i Spaces - What they are, how to become one, value and collaborations
BDVA i Spaces - What they are, how to become one, value and collaborationsBDVA i Spaces - What they are, how to become one, value and collaborations
BDVA i Spaces - What they are, how to become one, value and collaborations
 
Bdva - iSpaces
Bdva - iSpacesBdva - iSpaces
Bdva - iSpaces
 
Turning FAIR into Reality - Role for Libraries
Turning FAIR into Reality - Role for Libraries Turning FAIR into Reality - Role for Libraries
Turning FAIR into Reality - Role for Libraries
 
Edugate/IE Federation - Glenn Wearen, Edugate Federation Operator, HEAnet
Edugate/IE Federation -  Glenn Wearen, Edugate Federation Operator, HEAnetEdugate/IE Federation -  Glenn Wearen, Edugate Federation Operator, HEAnet
Edugate/IE Federation - Glenn Wearen, Edugate Federation Operator, HEAnet
 
Sgci nsf-si2-2-21-17
Sgci nsf-si2-2-21-17Sgci nsf-si2-2-21-17
Sgci nsf-si2-2-21-17
 
SGCI OAC webinar 4 18-19
SGCI OAC webinar 4 18-19SGCI OAC webinar 4 18-19
SGCI OAC webinar 4 18-19
 
Sgci nasa-esds-10-29-18
Sgci nasa-esds-10-29-18Sgci nasa-esds-10-29-18
Sgci nasa-esds-10-29-18
 
Membership Intro Presentation
Membership Intro PresentationMembership Intro Presentation
Membership Intro Presentation
 
Crowdtesting 2.0 - From Anonymous Crowd to Target Audience & Customer Community
Crowdtesting 2.0 - From Anonymous Crowd to Target Audience & Customer CommunityCrowdtesting 2.0 - From Anonymous Crowd to Target Audience & Customer Community
Crowdtesting 2.0 - From Anonymous Crowd to Target Audience & Customer Community
 
SGCI-Mizzou18Sep2017
SGCI-Mizzou18Sep2017SGCI-Mizzou18Sep2017
SGCI-Mizzou18Sep2017
 
Regtech in Fintech + QuSandbox Demo
Regtech in Fintech + QuSandbox DemoRegtech in Fintech + QuSandbox Demo
Regtech in Fintech + QuSandbox Demo
 
Facing the Data Challenge: Institutions, Disciplines, Services and Risks
Facing the Data Challenge: Institutions, Disciplines, Services and RisksFacing the Data Challenge: Institutions, Disciplines, Services and Risks
Facing the Data Challenge: Institutions, Disciplines, Services and Risks
 
Identity and User Access Management.pptx
Identity and User Access Management.pptxIdentity and User Access Management.pptx
Identity and User Access Management.pptx
 
Internet2 and Cyberinfrastructure
Internet2 and CyberinfrastructureInternet2 and Cyberinfrastructure
Internet2 and Cyberinfrastructure
 
Sgci about-poster-02-2016-v4-1
Sgci about-poster-02-2016-v4-1Sgci about-poster-02-2016-v4-1
Sgci about-poster-02-2016-v4-1
 
Digital Transformation at the University of Edinburgh
Digital Transformation at the University of EdinburghDigital Transformation at the University of Edinburgh
Digital Transformation at the University of Edinburgh
 
NISO-STM RA21 Project Update
NISO-STM RA21 Project UpdateNISO-STM RA21 Project Update
NISO-STM RA21 Project Update
 
Blackboard Learn Deployment: A Detailed Update of Managed Hosting and SaaS De...
Blackboard Learn Deployment: A Detailed Update of Managed Hosting and SaaS De...Blackboard Learn Deployment: A Detailed Update of Managed Hosting and SaaS De...
Blackboard Learn Deployment: A Detailed Update of Managed Hosting and SaaS De...
 

Más de Jisc

Más de Jisc (20)

Towards a code of practice for AI in AT.pptx
Towards a code of practice for AI in AT.pptxTowards a code of practice for AI in AT.pptx
Towards a code of practice for AI in AT.pptx
 
Jamworks pilot and AI at Jisc (20/03/2024)
Jamworks pilot and AI at Jisc (20/03/2024)Jamworks pilot and AI at Jisc (20/03/2024)
Jamworks pilot and AI at Jisc (20/03/2024)
 
Wellbeing inclusion and digital dystopias.pptx
Wellbeing inclusion and digital dystopias.pptxWellbeing inclusion and digital dystopias.pptx
Wellbeing inclusion and digital dystopias.pptx
 
Accessible Digital Futures project (20/03/2024)
Accessible Digital Futures project (20/03/2024)Accessible Digital Futures project (20/03/2024)
Accessible Digital Futures project (20/03/2024)
 
Procuring digital preservation CAN be quick and painless with our new dynamic...
Procuring digital preservation CAN be quick and painless with our new dynamic...Procuring digital preservation CAN be quick and painless with our new dynamic...
Procuring digital preservation CAN be quick and painless with our new dynamic...
 
International students’ digital experience: understanding and mitigating the ...
International students’ digital experience: understanding and mitigating the ...International students’ digital experience: understanding and mitigating the ...
International students’ digital experience: understanding and mitigating the ...
 
Digital Storytelling Community Launch!.pptx
Digital Storytelling Community Launch!.pptxDigital Storytelling Community Launch!.pptx
Digital Storytelling Community Launch!.pptx
 
Open Access book publishing understanding your options (1).pptx
Open Access book publishing understanding your options (1).pptxOpen Access book publishing understanding your options (1).pptx
Open Access book publishing understanding your options (1).pptx
 
Scottish Universities Press supporting authors with requirements for open acc...
Scottish Universities Press supporting authors with requirements for open acc...Scottish Universities Press supporting authors with requirements for open acc...
Scottish Universities Press supporting authors with requirements for open acc...
 
How Bloomsbury is supporting authors with UKRI long-form open access requirem...
How Bloomsbury is supporting authors with UKRI long-form open access requirem...How Bloomsbury is supporting authors with UKRI long-form open access requirem...
How Bloomsbury is supporting authors with UKRI long-form open access requirem...
 
Jisc Northern Ireland Strategy Forum 2023
Jisc Northern Ireland Strategy Forum 2023Jisc Northern Ireland Strategy Forum 2023
Jisc Northern Ireland Strategy Forum 2023
 
Jisc Scotland Strategy Forum 2023
Jisc Scotland Strategy Forum 2023Jisc Scotland Strategy Forum 2023
Jisc Scotland Strategy Forum 2023
 
Jisc stakeholder strategic update 2023
Jisc stakeholder strategic update 2023Jisc stakeholder strategic update 2023
Jisc stakeholder strategic update 2023
 
JISC Presentation.pptx
JISC Presentation.pptxJISC Presentation.pptx
JISC Presentation.pptx
 
Community-led Open Access Publishing webinar.pptx
Community-led Open Access Publishing webinar.pptxCommunity-led Open Access Publishing webinar.pptx
Community-led Open Access Publishing webinar.pptx
 
The Open Access Community Framework (OACF) 2023 (1).pptx
The Open Access Community Framework (OACF) 2023 (1).pptxThe Open Access Community Framework (OACF) 2023 (1).pptx
The Open Access Community Framework (OACF) 2023 (1).pptx
 
Are we onboard yet University of Sussex.pptx
Are we onboard yet University of Sussex.pptxAre we onboard yet University of Sussex.pptx
Are we onboard yet University of Sussex.pptx
 
JiscOAWeek_LAIR_slides_October2023.pptx
JiscOAWeek_LAIR_slides_October2023.pptxJiscOAWeek_LAIR_slides_October2023.pptx
JiscOAWeek_LAIR_slides_October2023.pptx
 
UWP OA Week Presentation (1).pptx
UWP OA Week Presentation (1).pptxUWP OA Week Presentation (1).pptx
UWP OA Week Presentation (1).pptx
 
An introduction to Cyber Essentials
An introduction to Cyber EssentialsAn introduction to Cyber Essentials
An introduction to Cyber Essentials
 

Último

Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
panagenda
 

Último (20)

Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challenges
 
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectors
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu SubbuApidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
 
A Beginners Guide to Building a RAG App Using Open Source Milvus
A Beginners Guide to Building a RAG App Using Open Source MilvusA Beginners Guide to Building a RAG App Using Open Source Milvus
A Beginners Guide to Building a RAG App Using Open Source Milvus
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...
Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...
Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024
 

eduTEAMS

  • 2. GÉANT supports and represents over 40 NRENs across Europe. Together they support over 10,000 institutions and 50 million academic users. About GÉANT
  • 3. eduroam - secure global roaming access service 250+ million authentications per month in 89 territories eduGAIN - interconnects identity federations around the world, simplifying access to content, services and resources ~ 3500 identity providers accessing services AARC project – collaborating with e-infrastructures, research collaborations, libraries & federations to share policies, architectures, training materials & pilots that avoid re-inventing the authentication & authorisation wheel REFEDs – supporting identity federations worldwide Trusted Introducer – services for security and incident response teams Certificate Service – delivering cost-effective digital certificates. In partnership with Supporting users and enabling secure access to services Trust, Identity & Security
  • 4. • Challenges in Authentication space • International Collaboration • Collaborative organisations work with people outside scope of R&E communities as well • Requires Collaborative organisations to peer with other non R&E Identity providers or maintain an additional Identity provider • Challenges in Authorization space • Services run by Collaborative Organisations often need attribute or group related information in the context of their collaboration, which are not issued by Institutions • Requires Collaborative Organisations to manage and provide additional attributes and groups towards their services, independently from the Institutions 4 Challenges for Collaborative Organisations
  • 5. • The FIM4R paper (April 2012) was one of the first to articulate collective requirements for using Federated AAI for VOs. • The VOPaaS has performed a survey among several small and large Pan-European VOs to (re-)validate the requirements. 5 Market Analysis
  • 7. • Goal • Investigate the conditions that would allow GÉANT to provide services to support Collaborative organisations • Focus on delivery of technical services • Out of scope: • Technical development • Policy & LOA development • Activities • Gather requirements and priorities with/from communities • Look at existing tools and technologies • Look into delivery model • Investigate business case & sustainability • Pilot with communities • Operations and Market 7 GEANT CO Platform as a Service Project
  • 8. Objectives Conclusions Q&AChallenges Achievements Components • eduTEAMS Membership Management service • eduTEAMS Discovery Service • eduTEAMS Identity Hub Characteristics • 2 monthly release cycle • Supports AARC architecture • Single- and multi-tenant options Documentation, Cookbooks, Privacy Policy etc available https://wiki.geant.org/display/ED eduTEAMS A suite of services for using federated AAI for collaborations Collaboration suite to enable use of federated identity in research communities Partner for any e- Infra or Research Infra inc. “long tail”, informal groups 8
  • 9. eduTEAMS - Pilots Engaging with communities, eInfras and NRENs 9 Research communities and e-Infrastructures • AARC2-as-VO (Pilot committed) • LifeScience AAI (Pilot) • Umbrella (Pilot committed) • HPC-Europe (Pilot intrest) • EUDAT (Pilot committed)* • EGI * * as part of AARC2 interoperability activity NRENS • JISC (UK) Moonshot Pathfinder project • SURFnet (NL) Science Collaboration Zone project • WAYF (DK) eduVPN Collaboration usecases
  • 10. Components – LEGO approach Choose how much of the platform they want • eduTEAMS Membership Management service • VO specific workflows for onboarding members • Registry for VO persistent Identifier • Limited set of attributes to maximise interoperability • Use of eduperson entitlement to carry richer info • Available through eduGAIN • eduTEAMS Identity Hub • One persistent (SAML) IdP for many ‘Guest’ Identity Providers • Available and accessible through eduGAIN • Supports Research and Scholarship Entity Category • Discovery Service • Service based or embedded discovery for eduGAIN SPs • Allows per SP filtering of IdPs • Allows per entity category filtering, e.g. R&S
  • 12. Objectives Conclusions Q&AChallenges Achievements 12 eduTEAMS Membership Management Service (MMS) Manage Roles and Rights • Available trough eduGAIN • CoCo and R&S supported • Strong focus on privacy and GDPR • part of AARC2 interop activity • Technical and cookbooks: https://wiki.geant.org/display/ED/Membership +Management+Service • Service: https://registry.eduTEAMS.org NRENS • JISC (Pilot committed) • Moonshot Pathfinder project • SURFnet (Pilot committed) • Science Collaboration Zone project • GARR (Pilot interest) • SWITCH (Pilot interest) • SWITCH eduID • Swiss Personalised Health Network • Swiss Data Science Center • Swiss National Supercomputing Centre
  • 13. Objectives Conclusions Q&AChallenges Achievements eduTEAMS Discovery Service • Component of eduTEAMS, but generically usable for eduGAIN SPs • Based on proven service from CESNET • Engaged in RA21 Pilot – Resource Access for the 21st Century (https://ra21.org) • Publishers, libraries and users https://wiki.geant.org/display/ED/Discovery+Servic e 13
  • 14. Objectives Conclusions Q&AChallenges Achievements 14 eduTEAMS Identity Hub Persistent ID Account Recovery LOA Implemented Future eduTEAMS Identity Hub https://wiki.geant.org/display/ED/Identity+Hub
  • 15. • Moonshot interaction with third-party AA systems • investigate potential for Assent service • and also all kinds of scientific collaborations • Combined access & authorization for web-based and non-web based services JISC eduTEAMS pilot 15
  • 16. Moonshot and eduTEAMS 16 SAML AA COmanage eduTEAMS Membership Management eduTEAMS Identity Hub IdP External IdP Webbased Service Moonshot Compute resource Storage resource Groups & roles
  • 17. Any questions? Thank you Any questions? Thank you