SlideShare a Scribd company logo
Access Management Transition Programme Meeting Access Management Futures: JISC and International Development Strategy  Nicole Harris Senior Services Transition Manager, JISC
A Little Background
Some Background 1995: Athens developed by NISS (National Information Services and Systems) at University of Bath as an in-house system. 1996: eLib Study ‘Technologies to Support Authentication in Higher Education’ identified Athens as a potential solution for all JISC Services.  1997: Athens in use in all JISC Data Centres and rolled out across HEIs / FEIs over the next two years.  1998: CNI White Paper on AAA requirements. JISC commits to using as a basis for next-generation technologies.  1997 – 2000: three year contract for Athens provision with University of Bath and then Eduserv.  2000 – 2008: two three year plus one two year contract with Eduserv for Athens provision.  2000: Alan Robiette and JCAS scope requirements for next generation access management system (ANGEL project starts testing Shibboleth and PAPI technologies).  2002 – 2004: AAA Programme – audit of next generation technologies and ratification of requirements. 2004 – 2007: Core Middleware Programmes. JISC decision to support federated access management. 2006 – 2009: Access Management: Transition Programme.  Roll-out and embedding.
The Requirements  A single access management system for: Intra-institutional resources. Third party digital library type resources. Inter-institutional resources for secure long-term collaboration. Inter-institutional resources for ad-hoc (virtual organisation) collaboration. Evolving strategy: Where possible, JISC should focus on fostering development and use of standards rather than specific technologies.  Institutions should have the widest possible range of options, from full open source to commercial support.  Solutions should be in line with international developments in the field.  Solution must provide real benefits to institutions and service providers.
Not just about preventing.. Copyright: Getty Images from the Education Image Gallery
..but about collaborating and sharing Copyright: Getty Images from the Education Image Gallery
The UK Development Landscape Athens Gateways CA Bridge eduRoam Gateway Development Level of Assurance – FAME project Identity Management –  inter- and intra- NHS / Government N-tier Developments –  SPIE project Authorisation Tools  -  PERMIS, DYVOSE (Authority Delegation) Interfaces / User Tools Virtual Home for Identities Federation Tools Identity / Service Providers   outreach support federation Federation Services
JISC Plans
Access Management Transition Programme!
e-Infrastructure Programme Continued support for integration of UK federation and Grid.  Levels of Assurance: ES-LOA. Identity Project.  Federated tools: 5 new projects. Federated Identities and virtual organisations with Grouper Virtual Organisations and management of organisations objects Integrated Authorisation for Shibboleth/Grid.  Integrating VOMS and PERMIS Virtual Organisation tools Upcoming ITTs / Calls / other work in the areas of…
Orphans American evangelist Dwight Lyman Moody (1837 - 1899) with a group of orphans at one of his Chicago missions. Courtesy of the Education Image Gallery Copyright: Getty Images
Identity Management outside Institutions
Multiple Affiliations
Attributes and Personalisation Copyright: HEFCE
e-Research Access Management for complex data Flexible Service Provider models for virtual organisations  Ongoing work with the National Grid Service, including the CA Copyright: Getty Images  Education Image Gallery
Federated  Tools such as ShARPE
Internet2 Plans
SAML 2.0 Scott Cantor: technical editor of SAML 2.0 specification and lead Shibboleth architect.  SC describes it as a ‘vulcan mind-meld’ of SAML 1.1, Shibboleth and Liberty ID-FF 1.2. You can expect in the long-term:  Focus on federated identity management. Single log-out.  Account linking / management.  More features / more complexity. Copyright: Getty Images Education Image Gallery
Shibboleth 2.0 Major changes: New and broadening concepts  New configuration files Metadata updates Minor installation differences Partial SAML 2.0 support (AuthnRequest, AttributeQuery, SingleLogout).  Better session management Better authentication packaged with Shib Better attribute management – particularly attribute filter policy Focus on SP side discovery service (the future?) Better audit and access logs Java Service Provider  https://spaces.internet2.edu/display/SHIB/ShibTwoRoadmap .
Other Internet2 Stuff More work in collaborative scenarios: virtual organisations etc.  Application integration with infrastructure: wikis, SharePoint, Sakai, mailing lists etc.  Integrated application providers: yahoo, google, e-bay etc.  Easier install IdPs. Information card integration including CardSpace (in place now).  Open Liberty Integration
International Plans
Work with our International Partners International Vendor Liaison, with specific emphasis on work with SURF and Internet2. Directory Schema work with TERENA through TF-EMC2. Inter-federation and licensing work with Knowledge Exchange Partners in Netherlands, Germany and Denmark. Inter-federation work with TERENA, Internet2 and DEST.  Contributions to the Shibboleth code-base through team at EDINA.  Continued international dialogue
and developing the UK federation… (see Josh Howlett presentation)

More Related Content

PPT
The Repository Roadmap - are we heading in the right direction?
PPTX
EADTU Conference - UKOER Technology Challenges
PPT
Karen Church - A Large-Scale Study of European Mobile Information Access
PPT
Metadata Working Group - Status update
PPTX
Turning FAIR data into reality
PPT
Educause2006 - Federated Access Management in the UK
PPT
Some Academic Sector/NMCA outcomes from the OGC Web Service Shibboleth Intero...
PPT
Knowledge Services
The Repository Roadmap - are we heading in the right direction?
EADTU Conference - UKOER Technology Challenges
Karen Church - A Large-Scale Study of European Mobile Information Access
Metadata Working Group - Status update
Turning FAIR data into reality
Educause2006 - Federated Access Management in the UK
Some Academic Sector/NMCA outcomes from the OGC Web Service Shibboleth Intero...
Knowledge Services

What's hot (20)

PPT
OGC Interoperability Experiments and Authentication
PDF
Ready, Set, GO FAIR
PDF
EOSC FAIR Data Session - EOSC Stakeholders Forum 2018
PPTX
Trust and identity in the Géant project - Networkshop44
PPTX
What it means to be FAIR
PPT
Jane Charlton Intro To F A M
PDF
Results from the FAIR Expert Group Stakeholder Consultation on the FAIR Data ...
PPT
Fitt Toolbox Tt Collaboration
PPTX
EOSC-MAR-update.pptx
PPTX
OSFair2017 Workshop | Towards a Policy Framework for the European Open Scienc...
PPTX
AIM Session at #DigiFest14
PPTX
EOSC's value proposition
PPT
Berlin 6 Open Access Conference: Wolfram Horstmann
PPTX
It takes more than a village: lessons on building global research commons
PDF
ELIXIR FAIR Activities - Examplars
PDF
Survey on metadata management and governance in Europe
PPT
Shibboleth Access Management Federations as an Organisational Model for SDI
PPT
1345 1400 Fiona Cullock Edina Case Study
PPTX
E Portfolio
PDF
Repositories for long-term preservation - certification
OGC Interoperability Experiments and Authentication
Ready, Set, GO FAIR
EOSC FAIR Data Session - EOSC Stakeholders Forum 2018
Trust and identity in the Géant project - Networkshop44
What it means to be FAIR
Jane Charlton Intro To F A M
Results from the FAIR Expert Group Stakeholder Consultation on the FAIR Data ...
Fitt Toolbox Tt Collaboration
EOSC-MAR-update.pptx
OSFair2017 Workshop | Towards a Policy Framework for the European Open Scienc...
AIM Session at #DigiFest14
EOSC's value proposition
Berlin 6 Open Access Conference: Wolfram Horstmann
It takes more than a village: lessons on building global research commons
ELIXIR FAIR Activities - Examplars
Survey on metadata management and governance in Europe
Shibboleth Access Management Federations as an Organisational Model for SDI
1345 1400 Fiona Cullock Edina Case Study
E Portfolio
Repositories for long-term preservation - certification
Ad

Similar to JISC Access and Identity Management: Future Directions (20)

PPT
'Connecting poeple to resources' by Nicole Harris at UKSG 2007
PPT
Federated Access Management (SFEU)
PPT
JISC License Workshop
PPTX
Advancing the JISC Access & Identity Management Programme
PPTX
JISC's AIM programme
PDF
Talis Insight Presentation
PPT
FAM The Basics 13 Feb08
PPT
Lessons from the UK Access Management Federation
PPT
Access Management - the Issues for FE Colleges
PPSX
Identity Management Matters
PPT
Federated Access Management, JISC Presentation
PPT
Online Educa: JISC Access and Identity Management
PPT
Access Management for Libraries by John Paschoud & Masha Garibyan
PPT
Eunis federation2
PPT
Inspire2011 shibb am_fs_paper_v3
PPT
OpenAthens and the future of access and identity management
PPT
McShibboleth Presentation
PPTX
Trust and identity
PPT
Technical Requirements of the UK Access Management Federation
PPT
UK Access Management Federation A partnership of JISC Collections & EDINA
'Connecting poeple to resources' by Nicole Harris at UKSG 2007
Federated Access Management (SFEU)
JISC License Workshop
Advancing the JISC Access & Identity Management Programme
JISC's AIM programme
Talis Insight Presentation
FAM The Basics 13 Feb08
Lessons from the UK Access Management Federation
Access Management - the Issues for FE Colleges
Identity Management Matters
Federated Access Management, JISC Presentation
Online Educa: JISC Access and Identity Management
Access Management for Libraries by John Paschoud & Masha Garibyan
Eunis federation2
Inspire2011 shibb am_fs_paper_v3
OpenAthens and the future of access and identity management
McShibboleth Presentation
Trust and identity
Technical Requirements of the UK Access Management Federation
UK Access Management Federation A partnership of JISC Collections & EDINA
Ad

More from JISC.AM (20)

PPT
Identity Assurance Profiles
PPT
Assurance
PPT
I2 Fedsoup
PPT
Cuckoo (Graham Mason, Ed Beddows)
PPT
Federated Futures (Nicole Harris)
PPT
Introduction to Shib 2.0 (Chad La Joie)
PPT
The Identity Project (Rhys Smith)
PPT
Shibboleth 2.0 IdP slides - Installfest (Edited)
PPT
Shibboleth 2.0 SP slides - Installfest
PPT
SARoNGS project (Jens Jensen)
PPT
Names project (Amanda Hill)
PPT
Studies in advanced access mgmt: GFIVO project (Cal Racey)
PDF
Identity: Future directions (David Orrell, Eduserv Foundation)
PDF
Shintau And VPMan proejcts (David Chadwick)
PPT
Identity: Future directions (David Orrell, Eduserv Foundation)
PPT
Internet2 Fall MM 2007 - Jane Charlton
PPT
Openid
PPT
Federated Access Management 102
PPT
Federated Access Management (Sconul Access Conference)
PDF
OpenID and Usercentric Identity: It's All About Me
Identity Assurance Profiles
Assurance
I2 Fedsoup
Cuckoo (Graham Mason, Ed Beddows)
Federated Futures (Nicole Harris)
Introduction to Shib 2.0 (Chad La Joie)
The Identity Project (Rhys Smith)
Shibboleth 2.0 IdP slides - Installfest (Edited)
Shibboleth 2.0 SP slides - Installfest
SARoNGS project (Jens Jensen)
Names project (Amanda Hill)
Studies in advanced access mgmt: GFIVO project (Cal Racey)
Identity: Future directions (David Orrell, Eduserv Foundation)
Shintau And VPMan proejcts (David Chadwick)
Identity: Future directions (David Orrell, Eduserv Foundation)
Internet2 Fall MM 2007 - Jane Charlton
Openid
Federated Access Management 102
Federated Access Management (Sconul Access Conference)
OpenID and Usercentric Identity: It's All About Me

Recently uploaded (20)

PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
PDF
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PDF
NewMind AI Monthly Chronicles - July 2025
PDF
Machine learning based COVID-19 study performance prediction
PPTX
Cloud computing and distributed systems.
PPTX
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PDF
[발표본] 너의 과제는 클라우드에 있어_KTDS_김동현_20250524.pdf
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PDF
CIFDAQ's Market Insight: SEC Turns Pro Crypto
PDF
GDG Cloud Iasi [PUBLIC] Florian Blaga - Unveiling the Evolution of Cybersecur...
PDF
Spectral efficient network and resource selection model in 5G networks
PDF
Modernizing your data center with Dell and AMD
PDF
solutions_manual_-_materials___processing_in_manufacturing__demargo_.pdf
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
DOCX
The AUB Centre for AI in Media Proposal.docx
Reach Out and Touch Someone: Haptics and Empathic Computing
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
NewMind AI Monthly Chronicles - July 2025
Machine learning based COVID-19 study performance prediction
Cloud computing and distributed systems.
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
The Rise and Fall of 3GPP – Time for a Sabbatical?
Diabetes mellitus diagnosis method based random forest with bat algorithm
[발표본] 너의 과제는 클라우드에 있어_KTDS_김동현_20250524.pdf
Understanding_Digital_Forensics_Presentation.pptx
CIFDAQ's Market Insight: SEC Turns Pro Crypto
GDG Cloud Iasi [PUBLIC] Florian Blaga - Unveiling the Evolution of Cybersecur...
Spectral efficient network and resource selection model in 5G networks
Modernizing your data center with Dell and AMD
solutions_manual_-_materials___processing_in_manufacturing__demargo_.pdf
“AI and Expert System Decision Support & Business Intelligence Systems”
The AUB Centre for AI in Media Proposal.docx

JISC Access and Identity Management: Future Directions

  • 1. Access Management Transition Programme Meeting Access Management Futures: JISC and International Development Strategy Nicole Harris Senior Services Transition Manager, JISC
  • 3. Some Background 1995: Athens developed by NISS (National Information Services and Systems) at University of Bath as an in-house system. 1996: eLib Study ‘Technologies to Support Authentication in Higher Education’ identified Athens as a potential solution for all JISC Services. 1997: Athens in use in all JISC Data Centres and rolled out across HEIs / FEIs over the next two years. 1998: CNI White Paper on AAA requirements. JISC commits to using as a basis for next-generation technologies. 1997 – 2000: three year contract for Athens provision with University of Bath and then Eduserv. 2000 – 2008: two three year plus one two year contract with Eduserv for Athens provision. 2000: Alan Robiette and JCAS scope requirements for next generation access management system (ANGEL project starts testing Shibboleth and PAPI technologies). 2002 – 2004: AAA Programme – audit of next generation technologies and ratification of requirements. 2004 – 2007: Core Middleware Programmes. JISC decision to support federated access management. 2006 – 2009: Access Management: Transition Programme. Roll-out and embedding.
  • 4. The Requirements A single access management system for: Intra-institutional resources. Third party digital library type resources. Inter-institutional resources for secure long-term collaboration. Inter-institutional resources for ad-hoc (virtual organisation) collaboration. Evolving strategy: Where possible, JISC should focus on fostering development and use of standards rather than specific technologies. Institutions should have the widest possible range of options, from full open source to commercial support. Solutions should be in line with international developments in the field. Solution must provide real benefits to institutions and service providers.
  • 5. Not just about preventing.. Copyright: Getty Images from the Education Image Gallery
  • 6. ..but about collaborating and sharing Copyright: Getty Images from the Education Image Gallery
  • 7. The UK Development Landscape Athens Gateways CA Bridge eduRoam Gateway Development Level of Assurance – FAME project Identity Management – inter- and intra- NHS / Government N-tier Developments – SPIE project Authorisation Tools - PERMIS, DYVOSE (Authority Delegation) Interfaces / User Tools Virtual Home for Identities Federation Tools Identity / Service Providers outreach support federation Federation Services
  • 10. e-Infrastructure Programme Continued support for integration of UK federation and Grid. Levels of Assurance: ES-LOA. Identity Project. Federated tools: 5 new projects. Federated Identities and virtual organisations with Grouper Virtual Organisations and management of organisations objects Integrated Authorisation for Shibboleth/Grid. Integrating VOMS and PERMIS Virtual Organisation tools Upcoming ITTs / Calls / other work in the areas of…
  • 11. Orphans American evangelist Dwight Lyman Moody (1837 - 1899) with a group of orphans at one of his Chicago missions. Courtesy of the Education Image Gallery Copyright: Getty Images
  • 14. Attributes and Personalisation Copyright: HEFCE
  • 15. e-Research Access Management for complex data Flexible Service Provider models for virtual organisations Ongoing work with the National Grid Service, including the CA Copyright: Getty Images Education Image Gallery
  • 16. Federated Tools such as ShARPE
  • 18. SAML 2.0 Scott Cantor: technical editor of SAML 2.0 specification and lead Shibboleth architect. SC describes it as a ‘vulcan mind-meld’ of SAML 1.1, Shibboleth and Liberty ID-FF 1.2. You can expect in the long-term: Focus on federated identity management. Single log-out. Account linking / management. More features / more complexity. Copyright: Getty Images Education Image Gallery
  • 19. Shibboleth 2.0 Major changes: New and broadening concepts New configuration files Metadata updates Minor installation differences Partial SAML 2.0 support (AuthnRequest, AttributeQuery, SingleLogout). Better session management Better authentication packaged with Shib Better attribute management – particularly attribute filter policy Focus on SP side discovery service (the future?) Better audit and access logs Java Service Provider https://spaces.internet2.edu/display/SHIB/ShibTwoRoadmap .
  • 20. Other Internet2 Stuff More work in collaborative scenarios: virtual organisations etc. Application integration with infrastructure: wikis, SharePoint, Sakai, mailing lists etc. Integrated application providers: yahoo, google, e-bay etc. Easier install IdPs. Information card integration including CardSpace (in place now). Open Liberty Integration
  • 22. Work with our International Partners International Vendor Liaison, with specific emphasis on work with SURF and Internet2. Directory Schema work with TERENA through TF-EMC2. Inter-federation and licensing work with Knowledge Exchange Partners in Netherlands, Germany and Denmark. Inter-federation work with TERENA, Internet2 and DEST. Contributions to the Shibboleth code-base through team at EDINA. Continued international dialogue
  • 23. and developing the UK federation… (see Josh Howlett presentation)