SlideShare una empresa de Scribd logo
1 de 28
Descargar para leer sin conexión
Jim Basney
Scott Koranda
CILogon 2.0
This material is based upon work supported by the National Science Foundation under grant numbers
0850557, 0943633, 1053575, 1440609, and 1547268 and by the Department of Energy under award
number DE-SC0008597. Any opinions, findings, and conclusions or recommendations expressed in this
material are those of the authors and do not necessarily reflect the views of the United States
Government or any agency thereof.
CILogon www.cilogon.org
CILogon 2.0 Project
❏ 3 year NSF CICI award
❏ January 2016 - December 2018
❏ Provide an integrated open source
Identity and Access Management (IdAM)
platform for cyberinfrastructure
❏ CILogon: federated identity management
❏ COmanage: collaborative organization
management
❏ Support international collaborations
CILogon www.cilogon.org
NSF CICI Program
❏ Cybersecurity Innovation for
Cyberinfrastructure (CICI)
❏ Funds projects in the areas of
❏ Cybersecurity Center of Excellence
❏ Regional Cybersecurity Collaboration
❏ Secure and Resilient Architecture
❏ Secure Architecture Design
❏ Data Provenance for Cybersecurity
https://www.nsf.gov/funding/pgm_summ.jsp?pims_id=505159
CILogon www.cilogon.org
CILogon 2.0 Team Members
❏ Jim Basney
❏ Terry Fleury
❏ Jeff Gaynor
❏ Venkat Yekkirala
❏ Heather Flanagan
❏ Scott Koranda
❏ Benn Oshrin
❏ Arlen Johnson
CILogon www.cilogon.org
Science Partners
❏ NANOGrav Physics
Frontiers Center
❏ Laser Interferometer
Gravitational-Wave
Observatory (LIGO)
❏ Data Observation Network
for Earth (DataONE)
CILogon www.cilogon.org
Cyberinfrastructure Partners
❏ Operational support
❏ Integration platform
❏ International use
cases
❏ Support for European
identities
❏ Using eduGAIN
CILogon www.cilogon.org
SAML
SP
OIDC
Provider
X.509 CA HSM
OIDC SP
MFA
(OATH)
LDAP
COmanage
Identities
MFA
Tokens
SSH Keys
Groups
Attributes
SAML
AA
User
Registry
Interface
eduGAIN
IdP
Google
IdP
Science
App
OAuth
SP
ORCID
Science
App
Science
App
Science
App
InCommon
IdP
Logical
Component
View
CILogon www.cilogon.org
SAML to OpenID Connect
(OIDC) Gateway
❏ Supporting e-Science clients
❏ Review & approval by CILogon staff
❏ User consent based on requested scopes
❏ openid, profile, email
❏ org.cilogon.userinfo (eppn, affiliation)
❏ edu.uiuc.ncsa.myproxy.getcert
(to allow X.509 certificate issuance)
❏ VO attributes
www.cilogon.org/oidc
CILogon www.cilogon.org
CILogon User Consent
CILogon www.cilogon.org
A Transparent Gateway
❏ CILogon passes campus/VO attributes to
the e-Science SP
❏ Always requiring user consent
❏ Attribute scopes approved per-client
❏ COmanage displays terms and conditions
during VO enrollment
❏ VO attribute release policy applied per client
CILogon www.cilogon.org
Open Researcher and
Contributor ID (ORCID)
❏ Linking ORCID iDs to federated IDs
❏ orcid.org
❏ on campus
❏ search.dataone.org
❏ cilogon.org
❏ eduPersonOrcid
❏ REFEDS ORCID working group
CILogon www.cilogon.org
Demo
SAML
SP
OIDC
Provider
LDAP
COmanage
User
Registry
Interface
Demo
App
InCommon
IdP
❏ Initial integration of CILogon OIDC with
COmanage LDAP to retrieve VO
memberships and ORCID iD
CILogon www.cilogon.org
CILogon www.cilogon.org
CILogon www.cilogon.org
CILogon www.cilogon.org
CILogon www.cilogon.org
CILogon www.cilogon.org
CILogon www.cilogon.org
Demo
CILogon www.cilogon.org
Demo
{
"sub":"http://cilogon.org/serverA/users/534",
"name":"James Alan Basney",
"given_name":"James",
"family_name":"Basney",
"email":"jbasney@illinois.edu"
"idp_name":"University of Illinois at Urbana-Champaign",
"idp":"urn:mace:incommon:uiuc.edu",
"affiliation":
"employee@illinois.edu;member@illinois.edu;staff@illinois.edu",
"eppn":"jbasney@illinois.edu",
"eptid":"urn:mace:incommon:uiuc.edu!https://cilogon.org/shibboleth!
cyXC3O5fi0t1NBsW1NsOxZDyDd4=",
"eduPersonOrcid":["http://orcid.org/0000-0002-0139-0640"],
"isMemberOf":["members","members:Research","Publication Policy"],
}
CILogon www.cilogon.org
CILogon in Europe
❏ Supporting international
research collaborations
❏ Int’l IdP support at cilogon.org soon via
InCommon’s eduGAIN membership
❏ Depends on int’l R&S adoption
❏ European CILogon instance
❏ Addresses EU attribute release policies
❏ IGTF accredited CA: https://rcauth.eu/
CILogon www.cilogon.org
CILogon Monthly Usage
CILogon www.cilogon.org
CILogon Monthly Usage
CILogon www.cilogon.org
❏ In February 2016, Globus began listing
InCommon IdPs directly, rather than as
“alternate login” option
❏ InCommon / CILogon use doubled!
Encouraging Federated Logins
CILogon www.cilogon.org
Attribute Release Challenges
❏ R&S attributes not released for students
❏ Affiliate researcher
❏ Former student
❏ Former employee
❏ IdP operational failures
Students do research!
CILogon www.cilogon.org
Most Used IdPs in Apr 2016
1. LIGO
2. NIH
3. U of Michigan
4. Purdue University
5. U of Chicago
6. UIUC
7. UCLA
8. University of Colorado at
Boulder
9. Google (was #1 in 2012)
10.University of California,
Berkeley
11.Argonne Nat’l Lab
12.Indiana University
13.University of Minnesota
14.LBNL
15.Johns Hopkins
16.Yale University
17.Cornell University
18.Case Western Reserve
University
19.Stanford University
20.University of
Nebraska-Lincoln
R&S ECP
R&S
R&S
R&S
R&S
R&S
R&S
R&S
R&S
R&S
R&S
R&S
R&S
R&S
ECP
ECP
ECP
(unique active users per IdP)
CILogon www.cilogon.org
COmanage News
❏ COmanage Registry Release 1.0.0 in
December 2015
❏ COmanage Registry Release 1.0.3 in
TIER Release 1
❏ COmanage Release 1.0.4 current
CILogon www.cilogon.org
Thanks!
jbasney@ncsa.illinois.edu
skoranda@sphericalcowgroup.com

Más contenido relacionado

Destacado

Slide tutorial penyampaian spt 1770 s dengan wizard
Slide tutorial penyampaian spt 1770 s dengan wizardSlide tutorial penyampaian spt 1770 s dengan wizard
Slide tutorial penyampaian spt 1770 s dengan wizard
Kppkp Bangil
 
Dolly powerpoint
Dolly powerpoint Dolly powerpoint
Dolly powerpoint
dollygoo
 
Commissione pariopportunitalmaschile
Commissione pariopportunitalmaschileCommissione pariopportunitalmaschile
Commissione pariopportunitalmaschile
Francesco Eterno
 
Prabhav services inc
Prabhav services incPrabhav services inc
Prabhav services inc
hiren2012
 
Sosialisasi tanggal 22 mei 2012
Sosialisasi tanggal 22 mei 2012Sosialisasi tanggal 22 mei 2012
Sosialisasi tanggal 22 mei 2012
Kppkp Bangil
 
A sore throat or strep throat
A sore throat or strep throatA sore throat or strep throat
A sore throat or strep throat
Megan Perkins
 

Destacado (20)

Brianna
BriannaBrianna
Brianna
 
Science
ScienceScience
Science
 
Ten ways to take your hashtags to the next level
Ten ways to take your hashtags to the next levelTen ways to take your hashtags to the next level
Ten ways to take your hashtags to the next level
 
Pitch deck powerpoint
Pitch deck powerpointPitch deck powerpoint
Pitch deck powerpoint
 
Hashtags & friends
Hashtags & friendsHashtags & friends
Hashtags & friends
 
Slide tutorial penyampaian spt 1770 s dengan wizard
Slide tutorial penyampaian spt 1770 s dengan wizardSlide tutorial penyampaian spt 1770 s dengan wizard
Slide tutorial penyampaian spt 1770 s dengan wizard
 
走出技术壁垒
走出技术壁垒走出技术壁垒
走出技术壁垒
 
Ten tips to improve your Facebook presence
Ten tips to improve your Facebook presenceTen tips to improve your Facebook presence
Ten tips to improve your Facebook presence
 
Presentación de Lluis Font, CEO de Zyncro, en acens Cloudstage
Presentación de Lluis Font, CEO de Zyncro, en acens CloudstagePresentación de Lluis Font, CEO de Zyncro, en acens Cloudstage
Presentación de Lluis Font, CEO de Zyncro, en acens Cloudstage
 
Se 29
Se 29Se 29
Se 29
 
Applying to Graduate School
Applying to Graduate SchoolApplying to Graduate School
Applying to Graduate School
 
Dolly powerpoint
Dolly powerpoint Dolly powerpoint
Dolly powerpoint
 
Commissione pariopportunitalmaschile
Commissione pariopportunitalmaschileCommissione pariopportunitalmaschile
Commissione pariopportunitalmaschile
 
Prabhav services inc
Prabhav services incPrabhav services inc
Prabhav services inc
 
Magazzini
MagazziniMagazzini
Magazzini
 
Ptkp
PtkpPtkp
Ptkp
 
Sosialisasi tanggal 22 mei 2012
Sosialisasi tanggal 22 mei 2012Sosialisasi tanggal 22 mei 2012
Sosialisasi tanggal 22 mei 2012
 
CILogon 2.0 MAGIC SC16
CILogon 2.0 MAGIC SC16CILogon 2.0 MAGIC SC16
CILogon 2.0 MAGIC SC16
 
Sosialisasi badan
Sosialisasi badanSosialisasi badan
Sosialisasi badan
 
A sore throat or strep throat
A sore throat or strep throatA sore throat or strep throat
A sore throat or strep throat
 

Similar a CILogon 2.0 at 2016 Internet2 Global Summit

Trusting External Identity Providers for Global Research Collaborations
Trusting External Identity Providers for Global Research CollaborationsTrusting External Identity Providers for Global Research Collaborations
Trusting External Identity Providers for Global Research Collaborations
jbasney
 
Technology Trends Every STEM Manager Should Know
Technology Trends Every STEM Manager Should KnowTechnology Trends Every STEM Manager Should Know
Technology Trends Every STEM Manager Should Know
Career Communications Group
 

Similar a CILogon 2.0 at 2016 Internet2 Global Summit (20)

CILogon 2.0 at Oct 2017 CICI PI meeting
CILogon 2.0 at Oct 2017 CICI PI meetingCILogon 2.0 at Oct 2017 CICI PI meeting
CILogon 2.0 at Oct 2017 CICI PI meeting
 
CILogon 2.0 at REFEDS 30
CILogon 2.0 at REFEDS 30CILogon 2.0 at REFEDS 30
CILogon 2.0 at REFEDS 30
 
Trusting External Identity Providers for Global Research Collaborations
Trusting External Identity Providers for Global Research CollaborationsTrusting External Identity Providers for Global Research Collaborations
Trusting External Identity Providers for Global Research Collaborations
 
Current State of the Drone Industry - Skylogic Research
Current State of the Drone Industry - Skylogic ResearchCurrent State of the Drone Industry - Skylogic Research
Current State of the Drone Industry - Skylogic Research
 
Intro to Blockchain for Developers using Algorand 2.0
Intro to Blockchain for Developers using Algorand 2.0Intro to Blockchain for Developers using Algorand 2.0
Intro to Blockchain for Developers using Algorand 2.0
 
Hackathon 3.0 idea Carbon footprint on blockchain with IoT
Hackathon 3.0 idea Carbon footprint on blockchain with IoTHackathon 3.0 idea Carbon footprint on blockchain with IoT
Hackathon 3.0 idea Carbon footprint on blockchain with IoT
 
DLT analytics and AI workshop 13 march 2019
DLT analytics and AI workshop   13 march  2019DLT analytics and AI workshop   13 march  2019
DLT analytics and AI workshop 13 march 2019
 
10-K and 10-Q Filings
10-K and 10-Q Filings10-K and 10-Q Filings
10-K and 10-Q Filings
 
Iurii Garasym - Cloud Security Alliance Now in Ukraine. Mission, Opportunitie...
Iurii Garasym - Cloud Security Alliance Now in Ukraine. Mission, Opportunitie...Iurii Garasym - Cloud Security Alliance Now in Ukraine. Mission, Opportunitie...
Iurii Garasym - Cloud Security Alliance Now in Ukraine. Mission, Opportunitie...
 
Technology Trends Every STEM Manager Should Know
Technology Trends Every STEM Manager Should KnowTechnology Trends Every STEM Manager Should Know
Technology Trends Every STEM Manager Should Know
 
CILogon and InCommon: Technical Update
CILogon and InCommon: Technical UpdateCILogon and InCommon: Technical Update
CILogon and InCommon: Technical Update
 
Cities of the Future: Where The Internet of Everything is Connecting the Unco...
Cities of the Future: Where The Internet of Everything is Connecting the Unco...Cities of the Future: Where The Internet of Everything is Connecting the Unco...
Cities of the Future: Where The Internet of Everything is Connecting the Unco...
 
DevOps for Highly Regulated Environments
DevOps for Highly Regulated EnvironmentsDevOps for Highly Regulated Environments
DevOps for Highly Regulated Environments
 
Smart Cities: Open Grid | AWS Public Sector Summit 2016
Smart Cities: Open Grid | AWS Public Sector Summit 2016Smart Cities: Open Grid | AWS Public Sector Summit 2016
Smart Cities: Open Grid | AWS Public Sector Summit 2016
 
Public sector keynote
Public sector keynotePublic sector keynote
Public sector keynote
 
CILogon & SciTokens: OIDC/OAuth Federation
CILogon & SciTokens: OIDC/OAuth FederationCILogon & SciTokens: OIDC/OAuth Federation
CILogon & SciTokens: OIDC/OAuth Federation
 
IDEALondon
IDEALondonIDEALondon
IDEALondon
 
New to the consortium?
New to the consortium?New to the consortium?
New to the consortium?
 
SSI Adoption: What will it take? Riley Hughes
SSI Adoption: What will it take? Riley HughesSSI Adoption: What will it take? Riley Hughes
SSI Adoption: What will it take? Riley Hughes
 
Cisco Connect Toronto 2018 DNA assurance
Cisco Connect Toronto 2018  DNA assuranceCisco Connect Toronto 2018  DNA assurance
Cisco Connect Toronto 2018 DNA assurance
 

Más de jbasney

CILogon: An Integrated Identity and Access Management Platform for Science
CILogon: An Integrated Identity and Access Management Platform for ScienceCILogon: An Integrated Identity and Access Management Platform for Science
CILogon: An Integrated Identity and Access Management Platform for Science
jbasney
 
CTSC at TNC16
CTSC at TNC16CTSC at TNC16
CTSC at TNC16
jbasney
 

Más de jbasney (12)

Guidance and Survey Results from the Trustworthy Data Working Group
Guidance and Survey Results from the Trustworthy Data Working GroupGuidance and Survey Results from the Trustworthy Data Working Group
Guidance and Survey Results from the Trustworthy Data Working Group
 
Federated Identity Needs for the Large Synoptic Survey Telescope (LSST)
Federated Identity Needs for the Large Synoptic Survey Telescope (LSST)Federated Identity Needs for the Large Synoptic Survey Telescope (LSST)
Federated Identity Needs for the Large Synoptic Survey Telescope (LSST)
 
Lightweight Cybersecurity Risk Assessment Tools for Cyberinfrastructure
Lightweight Cybersecurity Risk Assessment Tools for CyberinfrastructureLightweight Cybersecurity Risk Assessment Tools for Cyberinfrastructure
Lightweight Cybersecurity Risk Assessment Tools for Cyberinfrastructure
 
11th FIM4R Workshop: US Projects Update
11th FIM4R Workshop: US Projects Update11th FIM4R Workshop: US Projects Update
11th FIM4R Workshop: US Projects Update
 
CILogon 2.0 at 2017 Internet2 Global Summit
CILogon 2.0 at 2017 Internet2 Global SummitCILogon 2.0 at 2017 Internet2 Global Summit
CILogon 2.0 at 2017 Internet2 Global Summit
 
CTSC+SWAMP: cybersecurity resources for your campus
CTSC+SWAMP: cybersecurity resources for your campusCTSC+SWAMP: cybersecurity resources for your campus
CTSC+SWAMP: cybersecurity resources for your campus
 
CILogon: An Integrated Identity and Access Management Platform for Science
CILogon: An Integrated Identity and Access Management Platform for ScienceCILogon: An Integrated Identity and Access Management Platform for Science
CILogon: An Integrated Identity and Access Management Platform for Science
 
CILogon 2.0 Update at TechEx 2016
CILogon 2.0 Update at TechEx 2016CILogon 2.0 Update at TechEx 2016
CILogon 2.0 Update at TechEx 2016
 
Cybersecurity for Conservation
Cybersecurity for ConservationCybersecurity for Conservation
Cybersecurity for Conservation
 
CTSC at TNC16
CTSC at TNC16CTSC at TNC16
CTSC at TNC16
 
SAML Security Contacts
SAML Security ContactsSAML Security Contacts
SAML Security Contacts
 
FeduShare TechEx15
FeduShare TechEx15FeduShare TechEx15
FeduShare TechEx15
 

Último

Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
panagenda
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 

Último (20)

Spring Boot vs Quarkus the ultimate battle - DevoxxUK
Spring Boot vs Quarkus the ultimate battle - DevoxxUKSpring Boot vs Quarkus the ultimate battle - DevoxxUK
Spring Boot vs Quarkus the ultimate battle - DevoxxUK
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challenges
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with Milvus
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Ransomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdfRansomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdf
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
 
AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf
 
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdfRising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
Cyberprint. Dark Pink Apt Group [EN].pdf
Cyberprint. Dark Pink Apt Group [EN].pdfCyberprint. Dark Pink Apt Group [EN].pdf
Cyberprint. Dark Pink Apt Group [EN].pdf
 

CILogon 2.0 at 2016 Internet2 Global Summit