3 New Services Streamlining Access to eResearch Capabilities John - - PowerPoint PPT Presentation

3 new services streamlining access to eresearch
SMART_READER_LITE
LIVE PREVIEW

3 New Services Streamlining Access to eResearch Capabilities John - - PowerPoint PPT Presentation

3 New Services Streamlining Access to eResearch Capabilities John Scullen (john.scullen@aaf.edu.au) Manager, Strategic Initiatives & Managed Services (EDUcation Global Authentication INfrastructure) Growing International Community 55


slide-1
SLIDE 1

3 New Services Streamlining Access to eResearch Capabilities

John Scullen (john.scullen@aaf.edu.au) Manager, Strategic Initiatives & Managed Services

slide-2
SLIDE 2

(EDUcation Global Authentication INfrastructure)

slide-3
SLIDE 3
slide-4
SLIDE 4
slide-5
SLIDE 5
slide-6
SLIDE 6

Growing International Community

55 federations

Identity Providers: 2883 Service Providers: 2195

  • 195 Research & Scholarship

services already available

  • Other services added by request

See technical.edugain.org/entities

slide-7
SLIDE 7

eduGAIN Benefits

Service Providers

  • One integration
  • Thousands of potential

users

  • Extend the reach of

research infrastructure

  • Reduce cost and

complexity Identity Providers

  • Easier access to

international services

  • Simplifies international

collaboration

slide-8
SLIDE 8

Connecting to eduGAIN

Use latest software Technical config

  • metadata
  • attribute

request / release

  • discovery

Research & Scholarship Security

  • SIRTFI
slide-9
SLIDE 9

Find Out More

aaf.edu.au/edugain

slide-10
SLIDE 10
slide-11
SLIDE 11

Benefits

  • Release your IdM staff for more important work
  • Feature updates and security patches
  • eduGAIN-ready
  • High availability
  • Reduce infrastructure
  • Security designed in from the beginning
  • Faster deployment of new IdPs
  • Lowers entry barriers for smaller organisations
slide-12
SLIDE 12

On-Premise Cost Factors

  • Staffing
  • Servers
  • Storage
  • Backup
  • Load balancer costs
  • Data centre costs
  • Monitoring costs
  • Governance
  • Security
  • Compliance
  • Disaster recovery
  • Testing
  • Change management /

stakeholder comms

slide-13
SLIDE 13

Find Out More

aaf.edu.au/rapid

Rapid

Identity Provider

Rapid

Identity Provider

powered by AAF

slide-14
SLIDE 14

AAF CENTRAL

slide-15
SLIDE 15

AAF Central

  • A major step toward a multi-protocol federation
  • Support for applications using Open ID Connect (OIDC)
  • Design can accommodate other authentication protocols
slide-16
SLIDE 16

Why OIDC?

  • Developing with OIDC / OAuth2 is simpler than SAML
  • Add your preferred OIDC library to your development environment
  • No need to deploy servers or run Shibboleth service provider software
  • Easier to find experienced developers
  • OIDC / OAuth2 is widely used to integrate with Google, Facebook and cloud

services

  • Not just web-based authentication
  • API access
  • Mobile applications
slide-17
SLIDE 17

How does it work?

OpenID Connect Provider

rec res req rec

Identity Broker

req rec rec res

AAF Central

Application (OIDC RP)

SAML Federation Resolver

rec res req rec SAML Federation

slide-18
SLIDE 18

Current State

  • Available now as a pre-production service
  • Passes OIDC conformance tests
  • Peer-reviewed and load tested
  • Manual connection for now
  • No eduGAIN support – use SAML if you want to expose your service to international

partners

  • Reasonable coverage of OIDC specification
  • 3 services in production
  • ecocloud.org.au
  • Store.Monash
  • TERN
  • 13 services in test
slide-19
SLIDE 19

OpenID Connect Provider

rec res req rec

Identity Broker

req rec rec res

AAF Central

Application (OIDC RP)

SAML Federation Resolver

rec res req rec SAML Federation

Rapid Connect Provider

rec res req rec Application (Rapid Connect)

eduGAIN Resolver

rec res req rec eduGAIN Federation

Social Identity Resolver

rec res req rec Google / Facebook etc

Utopia

slide-20
SLIDE 20

Find Out More

Bradley Beddoes (bradleybeddoes@aaf.edu.au)

AAF Central