Introducing the zoo of paper beasts David Simonsen, WAYF, - - PowerPoint PPT Presentation

introducing the zoo of paper beasts
SMART_READER_LITE
LIVE PREVIEW

Introducing the zoo of paper beasts David Simonsen, WAYF, - - PowerPoint PPT Presentation

Introducing the zoo of paper beasts David Simonsen, WAYF, david@wayf.dk Todays walk in the zoo Todays walk in the zoo Federation policy and interfederation policies Todays walk in the zoo Federation policy and interfederation


slide-1
SLIDE 1

Introducing the zoo of paper beasts

David Simonsen, WAYF, david@wayf.dk

slide-2
SLIDE 2

Today’s walk in the zoo

slide-3
SLIDE 3

Today’s walk in the zoo

  • Federation policy and interfederation policies
slide-4
SLIDE 4

Today’s walk in the zoo

  • Federation policy and interfederation policies
  • Agreements
slide-5
SLIDE 5

Today’s walk in the zoo

  • Federation policy and interfederation policies
  • Contracts and contractual relations
  • Agreements
slide-6
SLIDE 6

Today’s walk in the zoo

  • Federation policy and interfederation policies
  • Contracts and contractual relations
  • Agreements
  • Users’ consent
slide-7
SLIDE 7

Today’s walk in the zoo

  • Federation policy and interfederation policies
  • Contracts and contractual relations
  • Attribute Release Policies (ARP’s)
  • Agreements
  • Users’ consent
slide-8
SLIDE 8

Today’s walk in the zoo

  • Memorandums of Understanding (MoU’s)
  • Federation policy and interfederation policies
  • Contracts and contractual relations
  • Attribute Release Policies (ARP’s)
  • Agreements
  • Users’ consent
slide-9
SLIDE 9

Today’s walk in the zoo

  • Memorandums of Understanding (MoU’s)
  • Federation policy and interfederation policies
  • Contracts and contractual relations
  • Attribute Release Policies (ARP’s)
  • Agreements
  • Charters
  • Users’ consent
slide-10
SLIDE 10

What is a federation?

slide-11
SLIDE 11

A circle of trust

slide-12
SLIDE 12

What is an IdP?

(identity provider)

Authentication and attribute releasing entity

slide-13
SLIDE 13

What is an SP?

(service provider)

Attribute consuming entity

slide-14
SLIDE 14

Federation goals

slide-15
SLIDE 15

Federation goals

  • Scalable and better access management
slide-16
SLIDE 16

Federation goals

  • Scalable and better access management
  • Scalable better identity management
slide-17
SLIDE 17

Federation goals

  • Scalable and better access management
  • More services to the users - and vv.
  • Scalable better identity management
slide-18
SLIDE 18

Federation goals

  • Scalable and better access management
  • More services to the users - and vv.
  • Better services
  • Scalable better identity management
slide-19
SLIDE 19

FØD. (USA) (AU)

slide-20
SLIDE 20

Basic concept

X

WAYF

  • 3

1

LOGIN

Service Institution

1 2

slide-21
SLIDE 21

Authorisation

Basic concept

X

WAYF

  • 3

1

LOGIN

Service Institution

1 2

slide-22
SLIDE 22

Shib- IdP CONSENT Shib- IdP CONSENT Service Shib-SP WAYF Service Shib-SP WAYF CENTRAL WAYF login login

Services Institutions

Loosely coupled, Shibboleth

slide-23
SLIDE 23

Shib- IdP CONSENT Shib- IdP CONSENT Service Shib-SP WAYF Service Shib-SP WAYF CENTRAL WAYF login login

Services Institutions

Loosely coupled, Shibboleth

slide-24
SLIDE 24

Shib- IdP CONSENT Shib- IdP CONSENT Service Shib-SP WAYF Service Shib-SP WAYF CENTRAL WAYF login login

Services Institutions

POLICY

slide-25
SLIDE 25

Contracts

slide-26
SLIDE 26

Contracts

  • Bi-lateral, between legal bodies
slide-27
SLIDE 27

Contracts

  • Defines responsabilities, duties, court, etc.
  • Bi-lateral, between legal bodies
slide-28
SLIDE 28

Contracts

  • Defines responsabilities, duties, court, etc.
  • Bi-lateral, between legal bodies
  • What is your legal entity?
  • for the institutions
  • for the federation?
slide-29
SLIDE 29

Contracts

  • Defines responsabilities, duties, court, etc.
  • Bi-lateral, between legal bodies
  • What is your legal entity?
  • for the institutions
  • for the federation?
  • All Swedish universities is ONE legal entity?
slide-30
SLIDE 30

Shib- IdP CONSENT Shib- IdP CONSENT Service Shib-SP WAYF Service Shib-SP WAYF CENTRAL WAYF login login

Services Institutions

Loosely coupled, Shibboleth

slide-31
SLIDE 31

Shib- IdP CONSENT Shib- IdP CONSENT Service Shib-SP WAYF Service Shib-SP WAYF CENTRAL WAYF login login

Services Institutions

POLICY

slide-32
SLIDE 32

Shib- IdP CONSENT Shib- IdP CONSENT Service Shib-SP WAYF Service Shib-SP WAYF CENTRAL WAYF login login

Services Institutions

POLICY

slide-33
SLIDE 33

Central login

X

1 2 3

Services

Y Z

Institutions

LOGIN LDAP LDAP LDAP SAML2

slide-34
SLIDE 34

Central login

X

1 2 3

Services

Y Z

Institutions

LOGIN LDAP LDAP LDAP SAML2

slide-35
SLIDE 35

Central login

X

1 2 3

Services

Y Z

Institutions

LOGIN LDAP LDAP LDAP SAML2

D a t a r e s p

  • n

s i b l e

slide-36
SLIDE 36

Central login

X

1 2 3

Services

Y Z

Institutions

LOGIN LDAP LDAP LDAP SAML2

Contracts D a t a r e s p

  • n

s i b l e

slide-37
SLIDE 37

Decentral login

X 1 2

Services

Y Z

Institutions

Trusted 3rd party

3

UN/Passwd X.509 OTP LOGIN

Possible agreement

LOGIN LOGIN

slide-38
SLIDE 38

Decentral login

X 1 2

Services

Y Z

Institutions

Trusted 3rd party

3

UN/Passwd X.509 OTP LOGIN

Possible agreement

LOGIN LOGIN

slide-39
SLIDE 39

Decentral login

X 1 2

Services

Y Z

Institutions

Trusted 3rd party

3

UN/Passwd X.509 OTP LOGIN

Possible agreement

LOGIN LOGIN

slide-40
SLIDE 40

Decentral login

X 1 2

Services

Y Z

Institutions

Trusted 3rd party

3

UN/Passwd X.509 OTP LOGIN

Possible agreement

LOGIN LOGIN

Data processor

slide-41
SLIDE 41

Decentral login

X 1 2

Services

Y Z

Institutions

Trusted 3rd party

3

UN/Passwd X.509 OTP LOGIN

Possible agreement

LOGIN LOGIN

Data processor Contracts

slide-42
SLIDE 42

Attribute Release Policies

The personal information the service gets

slide-43
SLIDE 43

Attribute Release Policies

The personal information the service gets

Shib- IdP CONSENT Shib- IdP CONSENT Shib-SP WAYF Shib-SP WAYF WAYF

Metadata distribution

slide-44
SLIDE 44

Attribute Release Policies

The personal information the service gets

Shib- IdP CONSENT Shib- IdP CONSENT Shib-SP WAYF Shib-SP WAYF WAYF X 1 2 Y Z 3

Metadata distribution ARP (one-size)

slide-45
SLIDE 45

Users’ informed consent to exchange of personal data

slide-46
SLIDE 46

Users’ informed consent to exchange of personal data

slide-47
SLIDE 47

EU directive

Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing

  • f personal data and on the free

movement of such data

slide-48
SLIDE 48

EU directive

Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing

  • f personal data and on the free

movement of such data

It conserns us all...

slide-49
SLIDE 49

Principles for data exchange

slide-50
SLIDE 50

Principles for data exchange

Transparency

slide-51
SLIDE 51

Principles for data exchange

Transparency Legitimate purpose

slide-52
SLIDE 52

Principles for data exchange

Transparency Legitimate purpose Proportionality

slide-53
SLIDE 53

The consent must be...

slide-54
SLIDE 54

The consent must be...

Volentary (no arm-twisting)

slide-55
SLIDE 55

The consent must be...

Volentary (no arm-twisting) Specific (one purpose)

slide-56
SLIDE 56

The consent must be...

Volentary (no arm-twisting) Informed (understandable) Specific (one purpose)

slide-57
SLIDE 57

Volentary

If you do not consent we will say ‘NI’

slide-58
SLIDE 58

Volentary

If you do not consent we will say ‘NI’

WRONG

slide-59
SLIDE 59

Volentary

If you do not consent we will say ‘NI’

WRONG

Do you consent to sending a personal pseudonym (non-identifiable pointer) to Microsoft?

slide-60
SLIDE 60

Volentary

If you do not consent we will say ‘NI’

WRONG

Do you consent to sending a personal pseudonym (non-identifiable pointer) to Microsoft?

R i g h t

slide-61
SLIDE 61

Specific

All services may recieve your email-adress

slide-62
SLIDE 62

Specific

All services may recieve your email-adress

WRONG

slide-63
SLIDE 63

BBC will recieve your email-adress

Specific

All services may recieve your email-adress

WRONG

slide-64
SLIDE 64

BBC will recieve your email-adress

Specific

All services may recieve your email-adress

WRONG

R i g h t

slide-65
SLIDE 65

Informed

If you do not consent we will not not decline from not delivering no services

slide-66
SLIDE 66

Informed

If you do not consent we will not not decline from not delivering no services

WRONG

slide-67
SLIDE 67

If you do not consent you will not get access

Informed

If you do not consent we will not not decline from not delivering no services

WRONG

slide-68
SLIDE 68

If you do not consent you will not get access

Informed

If you do not consent we will not not decline from not delivering no services

WRONG

R i g h t

slide-69
SLIDE 69

Consent in a Shib-føderation

Shib- IdP C O N S E N T Shib- IdP C O N S E N T Shib-SP WAYF Shib-SP WAYF WAYF

slide-70
SLIDE 70

Hub-and-spoke

X 1 2

Services

Y Z

Institutions

3

slide-71
SLIDE 71

Interfederation

slide-72
SLIDE 72

Interfederation

FØD. (USA) (AU)

slide-73
SLIDE 73

Interfederation

FØD. (USA) (AU)

slide-74
SLIDE 74

Interfederation

FØD. (USA) (AU)

slide-75
SLIDE 75

Interfederation

FØD. (USA) (AU)

slide-76
SLIDE 76

Interfederation

FØD. (USA) (AU)

slide-77
SLIDE 77

Connecting federations

slide-78
SLIDE 78

Connecting federations

Confederate

slide-79
SLIDE 79

Connecting federations

Confederate Cross federate

slide-80
SLIDE 80

Connecting federations

Confederate Cross federate Interfederate

slide-81
SLIDE 81

Connecting federations

Confederate Cross federate Interfederate Unite

slide-82
SLIDE 82

Connecting federations

Confederate Cross federate Interfederate Unite

slide-83
SLIDE 83

Connecting federations

Confederate Cross federate Interfederate Unite

slide-84
SLIDE 84

Connecting federations

Confederate Cross federate Interfederate Unite

slide-85
SLIDE 85
slide-86
SLIDE 86
slide-87
SLIDE 87

Recommendations

slide-88
SLIDE 88

Recommendations

Use (expensive) lawyers

(do not let the lawyers write your code - and don’t write their code)

slide-89
SLIDE 89

Recommendations

Use (expensive) lawyers

(do not let the lawyers write your code - and don’t write their code)

Talk to data and consumer protection agencies

slide-90
SLIDE 90

Recommendations

Use (expensive) lawyers

(do not let the lawyers write your code - and don’t write their code)

Talk to data and consumer protection agencies Define your federations’ legal body

slide-91
SLIDE 91

Recommendations

Use (expensive) lawyers

(do not let the lawyers write your code - and don’t write their code)

Talk to data and consumer protection agencies Define your federations’ legal body http://www.jisclegal.ac.uk/access/index.html