Introducing the zoo of paper beasts
David Simonsen, WAYF, david@wayf.dk
Introducing the zoo of paper beasts David Simonsen, WAYF, - - PowerPoint PPT Presentation
Introducing the zoo of paper beasts David Simonsen, WAYF, david@wayf.dk Todays walk in the zoo Todays walk in the zoo Federation policy and interfederation policies Todays walk in the zoo Federation policy and interfederation
David Simonsen, WAYF, david@wayf.dk
A circle of trust
(identity provider)
Authentication and attribute releasing entity
(service provider)
Attribute consuming entity
FØD. (USA) (AU)
X
WAYF
LOGIN
Service Institution
1 2
Authorisation
X
WAYF
LOGIN
Service Institution
1 2
Shib- IdP CONSENT Shib- IdP CONSENT Service Shib-SP WAYF Service Shib-SP WAYF CENTRAL WAYF login login
Services Institutions
Shib- IdP CONSENT Shib- IdP CONSENT Service Shib-SP WAYF Service Shib-SP WAYF CENTRAL WAYF login login
Services Institutions
Shib- IdP CONSENT Shib- IdP CONSENT Service Shib-SP WAYF Service Shib-SP WAYF CENTRAL WAYF login login
Services Institutions
Shib- IdP CONSENT Shib- IdP CONSENT Service Shib-SP WAYF Service Shib-SP WAYF CENTRAL WAYF login login
Services Institutions
Shib- IdP CONSENT Shib- IdP CONSENT Service Shib-SP WAYF Service Shib-SP WAYF CENTRAL WAYF login login
Services Institutions
Shib- IdP CONSENT Shib- IdP CONSENT Service Shib-SP WAYF Service Shib-SP WAYF CENTRAL WAYF login login
Services Institutions
X
1 2 3
Services
Y Z
Institutions
LOGIN LDAP LDAP LDAP SAML2
X
1 2 3
Services
Y Z
Institutions
LOGIN LDAP LDAP LDAP SAML2
X
1 2 3
Services
Y Z
Institutions
LOGIN LDAP LDAP LDAP SAML2
D a t a r e s p
s i b l e
X
1 2 3
Services
Y Z
Institutions
LOGIN LDAP LDAP LDAP SAML2
Contracts D a t a r e s p
s i b l e
X 1 2
Services
Y Z
Institutions
Trusted 3rd party
3
UN/Passwd X.509 OTP LOGIN
Possible agreement
LOGIN LOGIN
X 1 2
Services
Y Z
Institutions
Trusted 3rd party
3
UN/Passwd X.509 OTP LOGIN
Possible agreement
LOGIN LOGIN
X 1 2
Services
Y Z
Institutions
Trusted 3rd party
3
UN/Passwd X.509 OTP LOGIN
Possible agreement
LOGIN LOGIN
X 1 2
Services
Y Z
Institutions
Trusted 3rd party
3
UN/Passwd X.509 OTP LOGIN
Possible agreement
LOGIN LOGIN
Data processor
X 1 2
Services
Y Z
Institutions
Trusted 3rd party
3
UN/Passwd X.509 OTP LOGIN
Possible agreement
LOGIN LOGIN
Data processor Contracts
The personal information the service gets
The personal information the service gets
Shib- IdP CONSENT Shib- IdP CONSENT Shib-SP WAYF Shib-SP WAYF WAYFMetadata distribution
The personal information the service gets
Shib- IdP CONSENT Shib- IdP CONSENT Shib-SP WAYF Shib-SP WAYF WAYF X 1 2 Y Z 3Metadata distribution ARP (one-size)
Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing
movement of such data
Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing
movement of such data
It conserns us all...
Transparency
Transparency Legitimate purpose
Transparency Legitimate purpose Proportionality
Volentary (no arm-twisting)
Volentary (no arm-twisting) Specific (one purpose)
Volentary (no arm-twisting) Informed (understandable) Specific (one purpose)
If you do not consent we will say ‘NI’
If you do not consent we will say ‘NI’
If you do not consent we will say ‘NI’
Do you consent to sending a personal pseudonym (non-identifiable pointer) to Microsoft?
If you do not consent we will say ‘NI’
Do you consent to sending a personal pseudonym (non-identifiable pointer) to Microsoft?
All services may recieve your email-adress
All services may recieve your email-adress
BBC will recieve your email-adress
All services may recieve your email-adress
BBC will recieve your email-adress
All services may recieve your email-adress
If you do not consent we will not not decline from not delivering no services
If you do not consent we will not not decline from not delivering no services
If you do not consent you will not get access
If you do not consent we will not not decline from not delivering no services
If you do not consent you will not get access
If you do not consent we will not not decline from not delivering no services
Shib- IdP C O N S E N T Shib- IdP C O N S E N T Shib-SP WAYF Shib-SP WAYF WAYF
X 1 2
Services
Y Z
Institutions
3
FØD. (USA) (AU)
FØD. (USA) (AU)
FØD. (USA) (AU)
FØD. (USA) (AU)
FØD. (USA) (AU)
Confederate
Confederate Cross federate
Confederate Cross federate Interfederate
Confederate Cross federate Interfederate Unite
Confederate Cross federate Interfederate Unite
Confederate Cross federate Interfederate Unite
Confederate Cross federate Interfederate Unite
Use (expensive) lawyers
(do not let the lawyers write your code - and don’t write their code)
Use (expensive) lawyers
(do not let the lawyers write your code - and don’t write their code)
Talk to data and consumer protection agencies
Use (expensive) lawyers
(do not let the lawyers write your code - and don’t write their code)
Talk to data and consumer protection agencies Define your federations’ legal body
Use (expensive) lawyers
(do not let the lawyers write your code - and don’t write their code)
Talk to data and consumer protection agencies Define your federations’ legal body http://www.jisclegal.ac.uk/access/index.html