Shibboleth Access Management Federations as an Organisational Model for SDI

Similar documents
EUROPEAN LOCATION SERVICES VISION AND STRATEGY. Securing the long-term future of authoritative geospatial information and services

InAcademia Simple Validation Service

The critical role of open standards in SDIs and INSPIRE

EuroSpec service : a preliminary vision

HOW TO CONFIGURE SINGLE SIGN-ON (SSO) FOR SAP CLOUD FOR CUSTOMER USING SAP CLOUD IDENTITY SERVICE

The following is intended to outline our general product direction. It is intended for information purposes only, and may not be incorporated into

Geo Names and Geo Business (expectations from geospatial industry)

SDI Terms-of-Use IPR Management: GDI NRW Modeling Approach

Edinburgh Napier University

GÉANT project update. eduteams - AAI as a Service for Collaborative organisations. InAcademia Simple affiliation validation as a Service

OPERATIONAL CORE OF GDI NRW SET UP - JOINT PROJECT

Enabling GIS in Distribution Utility for Energy Audit and Load flow analysis

INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES

Building Online Portals for Your Customers & Partners with Okta. An Architectural Overview OKTA WHITE PAPER

InAcademia. Simple Validation Service

The Challenges in the Implementation of Brunei Darussalam Spatial Data Infrastructure (BSDI)

Supporting e-government Progress in the United Arab Emirates

The Future is Now: Gill Dickson, 26 May 2015

Daratech Report. What will we do? The Geospatial Managed Environment. Bentley has reported revenue to Daratech for the. years 2004 and 2005

GÉANT IaaS Framework Cookbook

Global Atlas Webinar. Planning the Energy Transition with Global Atlas 2.0 «Your Online Renewa ble Energy Prospector» Lionel Menard: MINES ParisTech

Journey to the Cloud: SAP Strategy and Roadmap for Cloud and Hybrid Analytics Scenarios March 16, 2017

CSP Forum 2014, Athens, May

Ανοικτή Διακυβέρνηση & τρόποι εφαρμογής της Σεπτέμβριος 2015

e-prior Facilitating interoperable electronic procurement across Europe Technical Overview

Business Process Management (BPM) system SimBASE 4 Introduction June 2015

Next steps for the pan-european Mobility Portal public-services.eu

Developing customer-centric online services in Finnish administration

Workspace ONE. Insert Presenter Name. Empowering a Digital Workspace. Insert Presenter Title

E-PLACING PLATFORM CREATING AN ENVIRONMENT FOR SUCCESSFUL MARKET ADOPTION. FOLLOWING CUSTOMER DEMAND Gene Bates. WebConnectivity.

Hydrological models as web services: results from EVOp and ESPA projects

SAP Fiori Keeping Simple Things Simple

Understanding Managed IT. Zyxel s Nebula Cloud-enabled Management Solution Brief for SMB s and Enterprise

Solicitation # Account Provisioning and SSO Solutions Addendum #1 dated 2/14/2017

EuroRoadS Quality Management Plan

Maritime Single Window. INTRASOFT International s Solution for the Global Maritime Community

ShibboLEAP: Seven Libraries and a LEAP of Faith

COURSE OUTLINE: Course 20533C- Implementing Microsoft Azure Infrastructure Solutions

Top. Reasons Enterprises Select kiteworks by Accellion

Full Impact Assessment

ICT opportunities in future Smart Grids

Implementing ArcGIS Solutions. Michael Beavers

NEW YORK CITY DEPARTMENT OF TRANSPORTATION

Smart grids summit, Nice February 2015, 19th

MANAGE THE LIFECYCLE OF EVERY DIGITAL USER

Liberty Alliance Project: Impact on Web Services Application Architectures

PageScope Enterprise Suite End to End Printing Administration. Solutions PageScope Enterprise Suite

Future Data Access & Analysis Architectures Strategy for CEOS

Configuring the ArcGIS for Local Government Solution CHRIS FOX SCOTT OPPMANN

AGILE COLLABORATION AS THE WAY TO BUILD UGANDA NATIONAL LAND INFORMATION SYSTEM

A challenge towards social implementation of PDS with public sector using open source software personium

LEADING EDUCATION AND TRAINING FOR THE FUTURE STRATEGIC PLAN

Challenges of implementing SDI in Botswana

WHITEPAPER. Mobile SSO & the Rise of Mobile Authentication

The architecture of the AliEn system

Potential commercial applications

European Union Location Framework Strategic Vision

Take control of your business communications

A Fresh Look at the Mainframe

BT Personalised Compute Management System. July 2017

The Universal Postal Union (The real THE Post Office) global Postal Trust Services

EUDAT How manage Data into the Collaborative Data Infrastructure: a general overview of EUDAT services

Our vision is to leverage power of maps, location, big data and analytics to change our cities.

NSW DEPARTMENT OF EDUCATION AND COMMUNITIES

Speech of Commissioner Günther H. Oettinger

Noble Enterprise. Unifi ed Contact Center Management

A Modeling Environment for Patient Portals

Primavera Analytics and Primavera Data Warehouse Security Overview

GLOBAL SERVICE DESK FROM COMPUTACENTER

Understanding Your Enterprise API Requirements

Federated Identity Management: Design and Architecture of Federation Models Customer experiences

Foreign Identities in the Austrian E-Government

Benefiting from a 2 Tier GIS Strategy. A whitepaper exploring the implementation of geospatial technology in organisations.

Realize Your Product Promise

Welcome Shared Services Health Portfolio Laboratories. A Distributed Services Workshop 14/12/16

API Gateway Digital access to meaningful banking content

Customers will be able to choose from a variety of ways of doing business with us.

Implementing Structures and Funding Position Paper

European Energy Policy and Standardization Buildings and Building Components

Universal Description, Discovery and Integration (UDDI) 1.0

General information BACKGROUND WHAT IS THE EXPERIENCING EUROPE INITIATIVE? WHAT DOES EXPERIENCING EUROPE OFFER PARTICIPANTS?

SDI Self-Assessment Framework

Towards a Reference Model for the LifeWatch ICT Infrastructure

Leveraging expertise for more economic value from HPC

INSPIRE Strengths, Weaknesses, Opportunities & Threats (SWOT) & Way Forward

CIPS Level 3 Advanced Certificate in Procurement and Supply Operations

Request for Proposal (RFP)

STORK 2.0: Breaking New Grounds on eid and Mandates

Sean P. McDonough National Office 365 Solution Manager Cardinal Solutions Group

Estonian e-government ecosystem: analogue and digital elements

Identity and Access Management

Enterprise Collaboration Patterns

Smart Energy Utilities based on Real-Time GIS Web Services and Internet of Things

Heterogeneous Missions Accessibility Architecture Working Group. HMA Architecture Working Group, Status , S.

Xchanging injects disruptive technology into our customers' business processes, dramatically improving performance, adding value and reducing costs.

AUSTRALIA. ICA 36th CONFERENCE Singapore, October 2002 INTRODUCTION

ehealth Exchange Network in U.S. Bottom Up Complements Top Down?

WP-9 The GMOS Interoperable System

The Flemish SDI - The Flemish Geographical Information Agency. Leen De Temmerman Jo Van Valckenborgh

Transcription:

Shibboleth Access Management Federations as an Organisational Model for SDI C.I.Higgins, M.Koutroumpas, A.Seales, EDINA National Datacentre, Scotland A.Matheus, University of the Bundeswehr, Germany INIRE Conference 2011, Wednesday 29 th June

ESDIN Project An econtentplus Best Practice Network project Resourced EDINA s to investigate ESDI and Access Control Principally using OGC Interoperability Experiments September 2008 to March 2011 Coordinated by EuroGeographics Key goal: help member states prepare their data for INIRE Annex 1 spatial data themes and improve access Been taking forward as the European Location Framework

ESDIN project info (www.esdin.eu) Lantmäteriet The Finnish Geodetic Institute Statens kartverk Helsinki University of Technology National Land Survey of Finland Kort & Matrikelstyrelsen IGN Belgium Kadaster EDINA, University Edinburgh Geodan Software Development & Technology Universität Münster Interactive Instruments Bundesamt für Kartographie und Geodäsie 1Spatial EuroGeographics Bundesamt für Eich- und Vermessungswesen IGN France Institute of Geodesy, Cartography and Remote Sensing National Technical University of Athens National Agency for Cadastre and Real Estate Publicity Romania

EDINA A National Data Centre for Tertiary Education since 1995 to enhance the productivity of research, learning and teaching in UK higher and further education (mission statement) Focus is on services but also undertake r&d Shibboleth used primarily in academic sector https://www.aai.dfn.de/links/ https://spaces.internet2.edu/display/shib/shibbolethfederations EDINA provides technical support in the operation of the UK Access Management Federation Approx 8 million users 837 Member Organisations (IdPs and s)

So whats the problem? Many of the most valuable SDI resources are protected These resources frequently in different admin domains Example: Article 19 of the INIRE Directive Member States may limit public access etc, etc. Many accepted standards for securing these protected geospatial resources but no consensus which to use Consequence: lots of point solutions Major interoperability barrier, eg, how can a X-Border application consume protected OWS while having to deal with multiple different access control mechanism? Make everything open? or Scale back ambitions? or Access Management Federations (AMF s)? or,?

What can Access Management Federations do for us? Fundamental requirement: information on who is accessing your valuable resource = authentication An AMF allows secure sharing of authentication information across administrative domains The members of the federation form a circle of trust and agree to a set of policies and technologies Provides Single Sign On My X-Border appl can now access a protected resource in country A, be challenged for credentials at home institution. Now I can also access additional federation resources (if authorised) in country A, B, C,, without needing to reauthenticate

One Solution - Shibboleth Internet2 consortium Open source package for web Single Sign On across admin boundaries based on standards: Security Assertion Markup Language (SAML) Organisations can exchange user information and make security assertions by obeying privacy policies Devolved authentication maintain and leverage existing user management Enables finer grained authorisation through use of attributes

Federation Service Providers IdP Identity Providers IdP Organisations Coordinating Centre Users IdP Authenticates here IdP IdP

Paper submitted to the International Journal SDI Research to accompany this presentation Premise is that a concomitant security infrastructure is necessary to realise SDI objectives where protected resources are involved Table 1 posits: Twelve required attributes for a solution to securing SDI

1.Based on open security interoperability standards Security Assertion Markup Language (SAML) from OASIS

2.Works across administrative domains Fundamental reason for Access Management Federations

3.Single Sign On Basic Use Case for SAML Principals authenticate at one web site, access the resource of interest, and are then able to access additional protected resources at other web sites without having to re-authenticate

4. Does not require any changes to the OGC interfaces being protected OGC Interoperability Experiments have demonstrated use with range of familiar industry implementations, eg, geoserver, mapserver, Snowflake No need for SOAP bindings

5. Requires minimal changes to the OGC Web Service clients SAML 2 ECP must be implemented Reference implementation available 6 organisations through OGC Interoperability Experiment have made changes Some products now commercially available Browser relatively easy, desktop harder Took weeks, not months

6. Proven production strength Already in daily use by millions Possibly already in your country

7. Satisfies data privacy requirements What set of SAML assertions are required for pan-european SDI authorisation decisions?

8. Flexible in order to accommodate a wide variety of different use cases Different SAML workflows Portal flow Service Provider flow SAML already used by GI community European Space Agency User Management Interfaces for Earth Observation Services Where are the interoperability points?

9. Should be an open source reference implementation Shibboleth

10. Not geospatial specific and in widespread mainstream IT use Leverage broad participation in technology development Stay flexible as much as possible Maximise potential for interoperability

11. Should, in so far as is possible, be built on information systems already in place Huge amount of prior investment in identity management Organisations know best how to manage their users Many Shibb Federations in place already in academic sector across Europe A source of expertise, collaboration and potentially extremely valuable interoperability link across sectors

12. Should not be centralised No huge databases with users credentials Needs to be decentralised to scale

Hard From the European Interoperability Framework for Pan-European egovernment Services (http://ec.europa.eu/idabc/servlets/docb0db.pdf?id=31597)

INIRE Federation OWS Providers WMS WFS IdP WMS IdP WFS Member State organisations, eg, NMCAs Coordinating Centre WMS IdP WMS IdP WFS WFS WMS WMS IdP WFS WFS IdP Key organisations, eg. EEA, JRC

Some options for going forward: 1. One Federation and every every legally mandated organisation joins 2. Multiple federations: one in each country and one pan- European 3. One federation: one organisation in each country, the INIRE point of contact joins the single pan-european federation and acts as the gateway for all the other legally mandated organisations in the country that are standing up INIRE services 4. Multiple federations: one in each country and interfederation interoperability ensures SSO

All material will be available from: http://igibs.blogs.edina.ac.uk/inspire2011/ Comments, questions, suggestions, etc, on blog very welcome Or email: chris.higgins@ed.ac.uk