 
              A"Study"of"Credential"Integration"Model" in"Academic"Research"Federation" Supporting"a"Wide"Variety"of"Services International,Symposium,Grids,&,Clouds,2018 20 th – 23 rd March,2018 Academia,Sinica,,Taipei,,Taiwan Eisaku SAKANE,,Takeshi,NISHIMURA,,Kento Aida,,Motonori NAKAMURA National,Institute,of,Informatics,,Japan
Outline • Introduction-to-GakuNin and-HPCI • Issues • Consideration of-credential-integration • Related-works • Summary 2
An#Academic#Identity#Federation#in#Japan SP E=Journals Lib#Services Web#mail Groupware E=Learning Academic#Federations# have#been#established#per# country#basis GakuNin Steering&Committee Discovery&Service Registration&Sys. • Federation&Policy • IdP Auditing Metadata&Repo. Info.&Web&Site • Promotion IdP Univ.#A Univ. B Univ. C Reduction#of#ID#management# Seamless#access#with# Easy#Access#from#out# cost, SSO of#Campus Improvement#of#security Content&Services Application&Services Admin& eLearning Services Most&of& ePortfolio Major& Publishers Foodle 3 3
HPCI:&High&Performance&Computing&Infrastructure Supercomputer centers (IdP & IdM) MICS9based&CA cert. related&system PI getting proxy&cert.&with&Shibboleth :&Communication&w/&Shibboleth GSI9enabled&SSH&login Researcher HPCI&authentication&system&features&include: • Single&user&ID&and&multiple&accounts&called&HPCI9ID,&HPCI&and&local&accounts • HPCI&accounts&are&managed&by&identity&providers. • A&hierarchical&initial&identity&vetting&system&based&on&face9to9face&meetings&with&photo9IDs • Two&kinds&of&credentials&for&services&in&HPCI: • Shibboleth&assertion&for&Web&services:&certificate&issuance,&CMS,&etc. • GSI&proxy&certificate&for&access&to&supercomputers&and&storages 4
Difference(between(HPCI(and(Gakunin • What(is(difference(between(HPCI(and(Gakunin? • IdP in(HPCI(is(different(from(IdP in(Gakunin: • Gakunin IdP is(managed(by(an(academic(institution(and(covers(all(constituent(members(of(its( academic(institution. • HPCI(IdP is(managed(by(a(supercomputer(center((university(or(institute)(and(covers(only(HPCI( users(who(are(not(only(academic(researchers(but(also(industrial(ones. • Why(did(HPCI(build(dedicated(IdPs ? • HPCI(IdP has(to(satisfy(a(strict(LoA imposing(identity(vetting(via(a(faceFtoFface(meeting. • HPCI(IdP needs(to(cover(industrial(researchers. • HPCI(is(not(a(common(service(to(all(constituent(members(of(an academic(institution(like(eF Journals. • Only(if(HPCI(users(are(academic(ones,(at(least(HPCI(and(Gakunin IdPs should(be( integrated. 5
Guiding question • How.do.we.integrate.HPCI.IdP and.GakuNin IdP in.order.that. academic.users.only.need.to.manage.one.credential? • We.select.GakuNin IdP as.primary.identity.provider.because.GakuNin IdP is.operated.by.home.organization that.user.belongs.to. • How do.we.apply.a.credential.issued.by.GakuNin IdP to.HPCI.services? 6
国立情報学研究所 Shibboleth SAML GSI 職員証 情報 研太郎 Authentication+flow+in+HPCI registered+data Initial+Identity Vetting Check C Name �������������� C Affiliation �������������������� Shibboleth+IdP HPCI+account+issuing+(IdP) S h i b b o l e t h + S P myproxyClogon Certificate+issuing bridging as+a+Web+service g s i C l o g i n Supercomputers, Storages 7
情報 Shibboleth SAML GSI 国立情報学研究所 研太郎 職員証 Possibilities)for)GakuNin credential)application registered)data Initial)Identity Vetting Check E Name �������������� E Affiliation �������������������� Shibboleth)IdP HPCI)account)issuing)(IdP) S h i b b o l e t h ) S P myproxyElogon Certificate)issuing bridging as)a)Web)service g s i E l o g i n Supercomputers, Storages 8
国立情報学研究所 Shibboleth SAML GSI 職員証 情報 研太郎 Possibilities)for)GakuNin credential)application registered)data Initial)Identity Vetting Check C Name �������������� C Affiliation �������������������� Shibboleth)IdP HPCI)account)issuing S h i b b o l e t h ) S P We)consider)applying)the)GakuNin credential)to)the)initial)identity) myproxyClogon Certificate)issuing bridging as)a)Web)service vetting)in)HPCI)IdM. g s i C l o g i n Supercomputers, Storages 9
Basic&idea: Initial&identity&vetting&with&external&credential IdM Trusted&Third&Party&(CA,&IdP,&…) 0.&Agree&with&cooperation 2.&Inquiry&about&the&applicant identity&vetting&based& notifying&the&applicant on&an&LoA of the inquiry 1.&Presenting& some credential an&applicant generalized our previous&work,&PoS(ISGC2017)009 10
Initial'identity'vetting'with'credential'issued'by' GakuNin IdP HPCI'IdM GakuNin IdP 0.'Agree'with'cooperation 2.'Shibboleth'authentication the'applicant'already has the account. 1.'Access'to'a'Web'service'for'initial'vetting an'applicant generalized our previous'work,'PoS(ISGC2017)009 11
Initial'identity'vetting'with'credential'issued'by' GakuNin IdP (Cont’d) HPCI'IdM GakuNin IdP 0.'Agree'with'cooperation 2.'Shibboleth'authentication the'applicant'already 2.1.'The'IdP authenticates'the'applicant. has the account. 2.2.'The'IdP confirms'whether'the applicant allows'the'IdP to'send'the'required' attributes'to'the'IdM. 2.3. The'IdM can'check'the'identity'data'against' the'information'provided'by'the IdP. an'applicant generalized our previous'work,'PoS(ISGC2017)009 12
情報 職員証 研太郎 国立情報学研究所 Discussion • Do the+proposed+procedure+provide+the+same+level of assurance? • HPCI+IdM must+vet+the+identity+of+user+based+on+a+face<to<face+meeting+with+a+ photo<ID. The+user+present+her/his+photo<ID+issued+by+ GakuNin IdP (University) home+university. �������������� �������������������� The+proposed+procedure+can+intuitively+be+regarded++the+same+ as+the+initial+identity+vetting+based+on+a+face<to<face+meeting. 13
Discussion((Cont’d) • Another(possibility(of(GakuNin crendential application. • Due to the end of GSI support, HPCI needs to reconsider the authentication and authorization system in HPCI to access to supercomputers(and(storages. • Credential(for(Web(services(may(be(changed(by(new(AA(system(in(HPCI. • However(the(GakuNin credential application(to initial identity(vetting(will( remain(almost(unchanged. 14
Related'Works • AARC'Blueprint'Architecture • Snctfi from'AARC’s'policy'work 15
Summary • We)introduced)authentication)infrastructures,)GakuNin and)HPCI. • We)proposed)a)credential)integration)model)in)which)GakuNin credential)(SAML)assertion))can)be)used)to)the)initial)identity)vetting) in)HPCI. • Our)approach)can)be)extended)to more general)case. • Our approach)should)be)corroborated)with)a)trust)framework. 16
Recommend
More recommend