+ All Categories
Home > Documents > AA Systems

AA Systems

Date post: 22-Feb-2016
Category:
Upload: edan
View: 33 times
Download: 0 times
Share this document with a friend
Description:
AA Systems. Do you like to puzzle?. 1 st EuroCAMP - Turin March , 3 rd , 2005. [email protected]. Roadmap. Drivers for an AAI The pieces of the puzzle: network and application access, login, authentication, authorisation, identity management Assessments of current AA systems - PowerPoint PPT Presentation
Popular Tags:
36
AA Systems Do you like to puzzle? 1 st EuroCAMP - Turin March, 3 rd , 2005 [email protected] xxx xxx xxx xxx xxx xxx
Transcript
Page 1: AA Systems

AA Systems

Do you like to puzzle?

1st EuroCAMP - TurinMarch, 3rd, [email protected]

xxx

xxxxxx

xxx

xxxxxx

Page 2: AA Systems

2EuroCAMP 2005, Torino

Roadmap

• Drivers for an AAI• The pieces of the puzzle: network and application

access, login, authentication, authorisation, identity management

• Assessments of current AA systems• Federations• Standards• Homework

xxx

xxxxxx

xxx

xxxxxx

Page 3: AA Systems

3EuroCAMP 2005, Torino

Why AAI?Personalised service provisioning! xxx

xxxxxx

xxx

xxxxxx

Page 4: AA Systems

4EuroCAMP 2005, Torino

Why AAI?Educational mobility!

xxx

xxxxxx

xxx

xxxxxx

Page 5: AA Systems

5EuroCAMP 2005, Torino

Why AAI?Network mobility!

xxx

xxxxxx

xxx

xxxxxx

Page 6: AA Systems

6EuroCAMP 2005, Torino

Why AAI?Reduce the digital key ring!

XXX

xxx

xxxxxx

xxx

xxxxxx

Page 7: AA Systems

7EuroCAMP 2005, Torino

xxxAuthentication

xxx

Network

Login

(web)ApplicationAuthorisation

xxx Administration

Ingredients of an AAI

Page 8: AA Systems

8EuroCAMP 2005, Torino

Network access: roaming

Page 9: AA Systems

9EuroCAMP 2005, Torino

Network access: user-controlled light paths

Application

AAA

Broker

SURFnet6

Applications

Broker

NetherLight

Application

Broker

OMNInet

Applications

Broker

Starlight

Services Services Services

AAA AAA AAA

UDDI/WSIL

A-Select

token

Page 10: AA Systems

10EuroCAMP 2005, Torino

Application access:centralise intelligence

Page 11: AA Systems

11EuroCAMP 2005, Torino

Application access:centralise intelligence

Page 12: AA Systems

12EuroCAMP 2005, Torino

Login server:intermediary between application and AA

Page 13: AA Systems

13EuroCAMP 2005, Torino

Authentication:user perspective

Page 14: AA Systems

14EuroCAMP 2005, Torino

Authentication:choose your own method• IP address• Username / password

– LDAP– RADIUS– SQL

• Passfaces• PKI certificate• OTP through SMS• OTP through internet banking• Tokens (SecurID, Vasco, …)• Biometrics

Page 15: AA Systems

15EuroCAMP 2005, Torino

Authorisation:Policy engines

Page 16: AA Systems

16EuroCAMP 2005, Torino

Authorisation:Policy engines

Page 17: AA Systems

17EuroCAMP 2005, Torino

Authorisation:3 scenario’s1. Authentication = authorisation

2. Identity plus a few attributes

3. Privacy-preserving negotiation about attributes to be exchanged

Page 18: AA Systems

18EuroCAMP 2005, Torino

Authorisation:privilege management

Page 19: AA Systems

19EuroCAMP 2005, Torino

Administration:Identity Management

• How to record the identities, credentials (attributes or roles), and privileges?

• Enterprise (or meta) directory to glue all sources of information together

• It’s the underlying basis for an AAI!• …and it’s a hype…

• But since yesterday you know this all

Page 20: AA Systems

20EuroCAMP 2005, Torino

Cross-domain AA:Federations

xxx

xxxxxx

xxx

xxxxxx

xxx

xxxxxx

xxx

xxxxxx

Page 21: AA Systems

21EuroCAMP 2005, Torino

Cross-domain AA:Ingredients• Policies (e.g. InCommon):

– Federation Operating Practices and Procedures– Participant Agreement – Participant Operating Practices

• Technologies:– PKI– Schema’s

xxx

xxxxxx

xxx

xxxxxx

xxx

xxxxxx

xxx

xxxxxx

Page 22: AA Systems

22EuroCAMP 2005, Torino

Quick assessment of current AA systems• Web login (authentication) systems

– A-Select, CAS, Cosign, pubcookie– Portal products (Oracle, SiteMinder, Sun One,

uPortal)• Authorisation systems

– Athens, FEIDE, PAPI, PERMIS, Shibboleth, SPOCP– Portal products

xxx

xxxxxx

xxx

xxxxxx

Page 23: AA Systems

23EuroCAMP 2005, Torino

Web login systems(A-Select, CAS, Cosign, Pubcookie) xxx

xxxxxx

xxx

xxxxxx

Authentication

Network

Login

(web)Application

Authorisation

Administration

Page 24: AA Systems

24EuroCAMP 2005, Torino

Authorisation Athens

Authentication

Network

Login

(web)Application

Authorisation

Administration

xxx

xxxxxx

xxx

xxxxxx

Page 25: AA Systems

25EuroCAMP 2005, Torino

Authorisation PAPI

Authentication

Network

Login

Authorisation

Administration

xxx

xxxxxx

xxx

xxxxxx

(web)Application

Page 26: AA Systems

26EuroCAMP 2005, Torino

AuthorisationPERMIS, SPOCP

Authentication

Network

Login

Authorisation

Administration

(web)Application

xxx

xxxxxx

xxx

xxxxxx

Page 27: AA Systems

27EuroCAMP 2005, Torino

Portal productsOracle, SiteMinder, Sun One, uPortal

Authentication

Network

Login

Authorisation

Administration

xxx

xxxxxx

xxx

xxxxxx

(web)Application

Page 28: AA Systems

28EuroCAMP 2005, Torino

AuthorisationShibboleth Group A Group B

Page 29: AA Systems

29EuroCAMP 2005, Torino

What about……standards?• Currently many proprietary solutions

(sockets, cookies, redirects, …)• Webservices

(SOAP, XML RPC, WSDL, WS-*)• SAML

• For federations:– WS-Federation (Microsoft, IBM)– SAML (OASIS: 150 companies, Internet2)– Liberty Alliance (Sun, 170 companies)

xxx

xxxxxx

xxx

xxxxxx

??

??

? ?

Page 30: AA Systems

30EuroCAMP 2005, Torino

And the future…?

• Converging or dominant standard(s)– Means better interoperability between the pieces

of the puzzle• Universal single sign-on across network and

application domain– Convergence of EduRoam and weblogin services– Including non-web-based applications

xxx

xxxxxx

xxx

xxxxxx

Page 31: AA Systems

31EuroCAMP 2005, Torino

Homework:Manage your identities!

xxx

xxxxxx

xxx

xxxxxx

Page 32: AA Systems

32EuroCAMP 2005, Torino

Homework:Manage your identities!

xxx

xxxxxx

xxx

xxxxxx

Page 33: AA Systems

33EuroCAMP 2005, Torino

Homework:Manage your identities!

xxx

xxxxxx

xxx

xxxxxx

Page 34: AA Systems

34EuroCAMP 2005, Torino

Homework:Start building an AAI!

xxx

xxxxxx

xxx

xxxxxx

xxxAuthentication

xxx

Network

Login

(web)ApplicationAuthorisation

xxx Administration

Page 35: AA Systems

35EuroCAMP 2005, Torino

References

• Identity Management• EduRoam• A-Select weblogin• Privilege Management• Intro on federations• Internet2 Federation• Swiss Federation• End-to-end diagnostics

xxx

xxxxxx

xxx

xxxxxx

Page 36: AA Systems

Thank you!Questions?

xxx

xxxxxx

xxx

xxxxxx


Recommended