3 new services streamlining access to eresearch
play

3 New Services Streamlining Access to eResearch Capabilities John - PowerPoint PPT Presentation

3 New Services Streamlining Access to eResearch Capabilities John Scullen (john.scullen@aaf.edu.au) Manager, Strategic Initiatives & Managed Services (EDUcation Global Authentication INfrastructure) Growing International Community 55


  1. 3 New Services Streamlining Access to eResearch Capabilities John Scullen (john.scullen@aaf.edu.au) Manager, Strategic Initiatives & Managed Services

  2. (EDUcation Global Authentication INfrastructure)

  3. Growing International Community 55 federations Service Providers: 2195 Identity Providers: 2883 195 Research & Scholarship • services already available Other services added by request • See technical.edugain.org/entities

  4. eduGAIN Benefits Service Providers Identity Providers One integration Easier access to • • international services Thousands of potential • users Simplifies international • collaboration Extend the reach of • research infrastructure Reduce cost and • complexity

  5. Connecting to eduGAIN Use latest Technical Research & Security software config Scholarship • metadata • SIRTFI • attribute request / release • discovery

  6. Find Out More aaf.edu.au/edugain

  7. Benefits • Release your IdM staff for more important work • Feature updates and security patches • eduGAIN-ready • High availability • Reduce infrastructure • Security designed in from the beginning • Faster deployment of new IdPs • Lowers entry barriers for smaller organisations

  8. On-Premise Cost Factors • Staffing Governance • • Servers Security • • Storage Compliance • • Backup Disaster recovery • • Load balancer costs Testing • • Data centre costs Change management / • stakeholder comms • Monitoring costs

  9. Find Out More Rapid Rapid Identity Provider Identity Provider powered by AAF aaf.edu.au/rapid

  10. AAF CENTRAL

  11. AAF Central • A major step toward a multi-protocol federation • Support for applications using Open ID Connect (OIDC) • Design can accommodate other authentication protocols

  12. Why OIDC? • Developing with OIDC / OAuth2 is simpler than SAML • Add your preferred OIDC library to your development environment • No need to deploy servers or run Shibboleth service provider software • Easier to find experienced developers • OIDC / OAuth2 is widely used to integrate with Google, Facebook and cloud services • Not just web-based authentication • API access • Mobile applications

  13. How does it work? AAF Central rec req rec req rec req SAML Federation OpenID Connect Application Identity Broker SAML (OIDC RP) Resolver Provider Federation res rec res rec res rec

  14. Current State • Available now as a pre-production service • Passes OIDC conformance tests • Peer-reviewed and load tested • Manual connection for now • No eduGAIN support – use SAML if you want to expose your service to international partners • Reasonable coverage of OIDC specification • 3 services in production • ecocloud.org.au • Store.Monash • TERN • 13 services in test

  15. Utopia AAF Central rec rec req req SAML Federation OpenID Connect Application SAML (OIDC RP) Resolver Provider Federation rec res rec res req rec req rec eduGAIN Identity Broker eduGAIN Resolver Federation rec res rec res rec rec req req Social Identity Rapid Connect Google / Application Facebook (Rapid Connect) Resolver Provider etc res res rec rec

  16. Find Out More AAF Central Bradley Beddoes (bradleybeddoes@aaf.edu.au)

Recommend


More recommend