EOSC-hub receives funding from the European Union’s Horizon 2020 research and innovation programme under grant agreement No. 777536.
eosc-hub.eu
@EOSC_eu
AARC Blueprint Architecture and its evolution – towards the EOSC
AAI for research communities
Dissemination level: Public
31/01/2019 2
AARC Blueprint Architecture and its evolution
ESFRI RIs and EOSC Workshop
“Community-first” AARC BPA approach
Researchers sign in using their institutional
(eduGAIN), social or community-managed IdP
via their Research Community AAI
Community-specific services are connected to
a single Community AAI
Generic services (e.g. RCauth.eu Online CA)
can be connected to more than one
Community AAI proxies
e-Infra services are connected to a single e-
infra SP proxy service gateway, e.g. B2ACCESS,
Check-in, Identity Hub, etc
31/01/2019 3
AARC Blueprint Architecture and its evolution
ESFRI RIs and EOSC Workshop
Uniform representation of unique user identifiers
Standardised way of expressing group membership, role
information & resource capabilities
Non-web-browser-based access (e.g. SSH/SFTP or HTTP APIs via
OAuth2 tokens and X.509 certs)
Delegation (e.g. via token exchange)
Release of mandatory set of user attributes (incl. unique shared id)
- REFEDS Research & Scholarship entity category
Operational security, incident response, and traceability- REFEDS
Sirtfi
Privacy requirements for processing personal information- GÉANT
Data Protection Code of Conduct
Rules and conditions that govern access to and use of service and
resources - WISE Baseline Acceptable Use Policy (AUP)
Assurance information- REFEDS Assurance Framework, IGTF/AARC
assurance profiles
31/01/2019 4ESFRI RIs and EOSC Workshop
EOSC-hub AAI builds on AARC BPA & Policy
best practices & recommendations
Communities with an existing Community AAI can connect to the
EOSC-hub e-Infra Proxies and gain access to generic e-Infra services
Communities that don’t operate their own AAI service can make
use of either dedicated or multi-tenant deployments of AAI services
operated by EOSC-hub
Multi-tenant deployments:
- aimed at medium-to-small research communities/groups or
individual researchers.
- community members, groups and authorisation attributes are
still managed by community managers.
Dedicated deployments:
- customisation of user-facing interfaces: IdP discovery page,
enrolment, group membership UI
- customisation of AAI proxy behaviour (e.g. attribute aggregation
rules, service entitlements)
- possibility of bespoke AAI Solutions, which might include
individual Components from the GÉANT eduTEAMS, EGI Check-
in, INDIGO IAM, EUDAT B2ACCESS, and PERUN
31/01/2019 5ESFRI RIs and EOSC Workshop
How the EOSC-hub AAI services help communities
access resources
31/01/2019 6
EOSC-hub Community AAI services
ESFRI RIs and EOSC Workshop
@nliampotis
Thank you
for your attention!
Questions?

More Related Content

PPT
Ck Coalition 2009
PPTX
EOSC-hub AAI architecture (EOSC hub week, Malaga, 16 - 20 April 2018)
PPTX
EOSC-hub AAI: Initial building blocks (EOSC hub week, Malaga, 16 - 20 April 2...
PPTX
EOSC-hub - EGI Check-in service
PPT
Some Academic Sector/NMCA outcomes from the OGC Web Service Shibboleth Intero...
PPT
OGC Web Service Shibboleth Interoperability Experiment
PPT
Shibboleth Federations and Secure SDI
PPTX
Implementation roadmap for the EOSC
Ck Coalition 2009
EOSC-hub AAI architecture (EOSC hub week, Malaga, 16 - 20 April 2018)
EOSC-hub AAI: Initial building blocks (EOSC hub week, Malaga, 16 - 20 April 2...
EOSC-hub - EGI Check-in service
Some Academic Sector/NMCA outcomes from the OGC Web Service Shibboleth Intero...
OGC Web Service Shibboleth Interoperability Experiment
Shibboleth Federations and Secure SDI
Implementation roadmap for the EOSC

Similar to Curious about EOSC federated AAI? (20)

PPT
Shibboleth Access Management Federations as an Organisational Model for SDI
PPT
Inspire2011 shibb am_fs_paper_v3
PPTX
EOSC-hub & RCauth.eu presentation
PPT
Access Control in ESDIN: Shibboleth
PPT
Eunis federation2
PPT
'Connecting poeple to resources' by Nicole Harris at UKSG 2007
PPTX
EOSC Portal future plans
PPTX
European Research Projects as EOSC Service Providers
PDF
Sshoc kick off meeting - 1.2.1 How to Connect to EOSC? - Tiziana Ferrari - EGI
PPTX
EOSC-hub: A Collaborative Framework for the EOSC Implementation
PDF
Draft Governance Framework for the EOSC
PPT
McShibboleth Presentation
PPT
EUDAT Collaborative Data Infrastructure: Data Access and Re-use Service Area
PPTX
ENES Climate Analytics Service (ECAS)
PPT
JISC License Workshop
PPTX
Shaping the EOSC Portal - future vision for EOSC Hub
PPTX
The EOSC Compute Platform with the EGI-ACE project
PDF
Governance and Sustainability of EOSC: ambitions, challenges and opportunities
PDF
20190523 archiver fim
PDF
Technology Standarization Commitees
Shibboleth Access Management Federations as an Organisational Model for SDI
Inspire2011 shibb am_fs_paper_v3
EOSC-hub & RCauth.eu presentation
Access Control in ESDIN: Shibboleth
Eunis federation2
'Connecting poeple to resources' by Nicole Harris at UKSG 2007
EOSC Portal future plans
European Research Projects as EOSC Service Providers
Sshoc kick off meeting - 1.2.1 How to Connect to EOSC? - Tiziana Ferrari - EGI
EOSC-hub: A Collaborative Framework for the EOSC Implementation
Draft Governance Framework for the EOSC
McShibboleth Presentation
EUDAT Collaborative Data Infrastructure: Data Access and Re-use Service Area
ENES Climate Analytics Service (ECAS)
JISC License Workshop
Shaping the EOSC Portal - future vision for EOSC Hub
The EOSC Compute Platform with the EGI-ACE project
Governance and Sustainability of EOSC: ambitions, challenges and opportunities
20190523 archiver fim
Technology Standarization Commitees
Ad

Recently uploaded (20)

PDF
7.Physics_8_WBS_Electricity.pdfXFGXFDHFHG
PPT
Cell Structure Description and Functions
PPTX
congenital heart diseases of burao university.pptx
PPTX
gene cloning powerpoint for general biology 2
PPTX
2currentelectricity1-201006102815 (1).pptx
PPTX
endocrine - management of adrenal incidentaloma.pptx
PPTX
Presentation1 INTRODUCTION TO ENZYMES.pptx
PPT
Mutation in dna of bacteria and repairss
PPTX
ELISA(Enzyme linked immunosorbent assay)
PPTX
HAEMATOLOGICAL DISEASES lack of red blood cells, which carry oxygen throughou...
PDF
Communicating Health Policies to Diverse Populations (www.kiu.ac.ug)
PDF
Social preventive and pharmacy. Pdf
PPTX
perinatal infections 2-171220190027.pptx
PDF
Unit 5 Preparations, Reactions, Properties and Isomersim of Organic Compounds...
PPT
THE CELL THEORY AND ITS FUNDAMENTALS AND USE
PPTX
Platelet disorders - thrombocytopenia.pptx
PPTX
Cells and Organs of the Immune System (Unit-2) - Majesh Sir.pptx
PDF
From Molecular Interactions to Solubility in Deep Eutectic Solvents: Explorin...
PPTX
Understanding the Circulatory System……..
PDF
Is Earendel a Star Cluster?: Metal-poor Globular Cluster Progenitors at z ∼ 6
7.Physics_8_WBS_Electricity.pdfXFGXFDHFHG
Cell Structure Description and Functions
congenital heart diseases of burao university.pptx
gene cloning powerpoint for general biology 2
2currentelectricity1-201006102815 (1).pptx
endocrine - management of adrenal incidentaloma.pptx
Presentation1 INTRODUCTION TO ENZYMES.pptx
Mutation in dna of bacteria and repairss
ELISA(Enzyme linked immunosorbent assay)
HAEMATOLOGICAL DISEASES lack of red blood cells, which carry oxygen throughou...
Communicating Health Policies to Diverse Populations (www.kiu.ac.ug)
Social preventive and pharmacy. Pdf
perinatal infections 2-171220190027.pptx
Unit 5 Preparations, Reactions, Properties and Isomersim of Organic Compounds...
THE CELL THEORY AND ITS FUNDAMENTALS AND USE
Platelet disorders - thrombocytopenia.pptx
Cells and Organs of the Immune System (Unit-2) - Majesh Sir.pptx
From Molecular Interactions to Solubility in Deep Eutectic Solvents: Explorin...
Understanding the Circulatory System……..
Is Earendel a Star Cluster?: Metal-poor Globular Cluster Progenitors at z ∼ 6
Ad

Curious about EOSC federated AAI?

  • 1. EOSC-hub receives funding from the European Union’s Horizon 2020 research and innovation programme under grant agreement No. 777536. eosc-hub.eu @EOSC_eu AARC Blueprint Architecture and its evolution – towards the EOSC AAI for research communities Dissemination level: Public
  • 2. 31/01/2019 2 AARC Blueprint Architecture and its evolution ESFRI RIs and EOSC Workshop
  • 3. “Community-first” AARC BPA approach Researchers sign in using their institutional (eduGAIN), social or community-managed IdP via their Research Community AAI Community-specific services are connected to a single Community AAI Generic services (e.g. RCauth.eu Online CA) can be connected to more than one Community AAI proxies e-Infra services are connected to a single e- infra SP proxy service gateway, e.g. B2ACCESS, Check-in, Identity Hub, etc 31/01/2019 3 AARC Blueprint Architecture and its evolution ESFRI RIs and EOSC Workshop
  • 4. Uniform representation of unique user identifiers Standardised way of expressing group membership, role information & resource capabilities Non-web-browser-based access (e.g. SSH/SFTP or HTTP APIs via OAuth2 tokens and X.509 certs) Delegation (e.g. via token exchange) Release of mandatory set of user attributes (incl. unique shared id) - REFEDS Research & Scholarship entity category Operational security, incident response, and traceability- REFEDS Sirtfi Privacy requirements for processing personal information- GÉANT Data Protection Code of Conduct Rules and conditions that govern access to and use of service and resources - WISE Baseline Acceptable Use Policy (AUP) Assurance information- REFEDS Assurance Framework, IGTF/AARC assurance profiles 31/01/2019 4ESFRI RIs and EOSC Workshop EOSC-hub AAI builds on AARC BPA & Policy best practices & recommendations
  • 5. Communities with an existing Community AAI can connect to the EOSC-hub e-Infra Proxies and gain access to generic e-Infra services Communities that don’t operate their own AAI service can make use of either dedicated or multi-tenant deployments of AAI services operated by EOSC-hub Multi-tenant deployments: - aimed at medium-to-small research communities/groups or individual researchers. - community members, groups and authorisation attributes are still managed by community managers. Dedicated deployments: - customisation of user-facing interfaces: IdP discovery page, enrolment, group membership UI - customisation of AAI proxy behaviour (e.g. attribute aggregation rules, service entitlements) - possibility of bespoke AAI Solutions, which might include individual Components from the GÉANT eduTEAMS, EGI Check- in, INDIGO IAM, EUDAT B2ACCESS, and PERUN 31/01/2019 5ESFRI RIs and EOSC Workshop How the EOSC-hub AAI services help communities access resources
  • 6. 31/01/2019 6 EOSC-hub Community AAI services ESFRI RIs and EOSC Workshop
  • 7. @nliampotis Thank you for your attention! Questions?