cobweb, aip-6 and access management federations chris higgins, project coordinator, university of...

14
COBWEB, AIP-6 and Access Management Federations Chris Higgins, Project Coordinator, University of Edinburgh. [email protected] Andreas Matheus, Technical Coordinator, Secure Dimensions GmbH. [email protected]

Upload: prosper-phillips

Post on 27-Dec-2015

218 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: COBWEB, AIP-6 and Access Management Federations Chris Higgins, Project Coordinator, University of Edinburgh. chris.higgins@ed.ac.uk Andreas Matheus, Technical

COBWEB, AIP-6 and Access Management Federations

Chris Higgins,Project Coordinator,University of [email protected]

Andreas Matheus,Technical Coordinator,Secure Dimensions [email protected]

Page 2: COBWEB, AIP-6 and Access Management Federations Chris Higgins, Project Coordinator, University of Edinburgh. chris.higgins@ed.ac.uk Andreas Matheus, Technical

Citizen Observatory Web (COBWEB)• Research project started Nov 2012 for 4 years• Crowdsourced environmental data to aid decision making• Introduce quality measures, reduce uncertainty• Fusion crowdsourced data with reference data…• Spatial Data Infrastructure - like initiatives

- National SDI’s in UK, Greece and Germany

- INSPIRE

- GEOSS

• Testbed approach using UNESCO Biosphere Reserves

Page 3: COBWEB, AIP-6 and Access Management Federations Chris Higgins, Project Coordinator, University of Edinburgh. chris.higgins@ed.ac.uk Andreas Matheus, Technical

University of Edinburgh UK (Scotland)

University of Nottingham UK (England)

Aberystwyth University UK (Wales)

Welsh Assembly Government UK (Wales)

Environment Systems Limited UK (Wales)

Ecodyfi UK (Wales)

Open Geospatial Consortium (Europe) Limited UK

University College Dublin Ireland

Technische Universitaet Dresden Germany

Secure Dimensions GmbH Germany

University of Western Greece Greece

OIKOM – Environmental Studies Ltd Greece

GeoCat BV Netherlands

Page 4: COBWEB, AIP-6 and Access Management Federations Chris Higgins, Project Coordinator, University of Edinburgh. chris.higgins@ed.ac.uk Andreas Matheus, Technical

Name Lead Institution Topic

CITI-SENSE Nilu (Norway) Air quality

WeSenseIt University of Sheffield (UK)

Water Management

Citclops Barcelona Digital Centre Tecnològic (Spain)

Coast and ocean

optical monitoring

Omniscientis Spacebel (Belgium) Odour monitoring

COBWEB UEDIN (UK) Environment

FP7-ENV-2012 observatories

Page 5: COBWEB, AIP-6 and Access Management Federations Chris Higgins, Project Coordinator, University of Edinburgh. chris.higgins@ed.ac.uk Andreas Matheus, Technical

GEOSS Architecture Implementation Pilot

• One of the means by which GEOSS addresses interoperability issues and GCI extension work

• Led by the Open Geospatial Consortium (OGC)• All contributions are in-kind• Phased approach• AIP-6 kickoff 28/29 March 2013 in Washington• Still options for participation…

Page 6: COBWEB, AIP-6 and Access Management Federations Chris Higgins, Project Coordinator, University of Edinburgh. chris.higgins@ed.ac.uk Andreas Matheus, Technical

SP

SPIdP

IdP

IdP

IdP

SP

SP

SP

SP

SP

SP

SP

SPSP

Coordinating

Centre

Federation Service Providers

Identity Providers

Users

Organisations

IdP

SP

SP

SP

Authenticates here

Single Sign On

Page 7: COBWEB, AIP-6 and Access Management Federations Chris Higgins, Project Coordinator, University of Edinburgh. chris.higgins@ed.ac.uk Andreas Matheus, Technical

Why put effort into federated access control?

• Authentication is the process of verifying that claims made concerning a subject, eg, identity, who is attempting to access a resource are true

• Frequently, SDI content and service providers need to know who is accessing their valuable, secure, protected data

• The ability for a group of organisations with common objectives, ie, a federation, to securely exchange authentication information is a powerful SDI enabler

• Even more so if removing some of the barriers to interoperability…

Page 8: COBWEB, AIP-6 and Access Management Federations Chris Higgins, Project Coordinator, University of Edinburgh. chris.higgins@ed.ac.uk Andreas Matheus, Technical

COBWEB’s need for Federation technology

• “…addressing questions of privacy…”• COBWEB about environmental, not personal data• Some kinds of protected data that may be

encountered during the project:• Personal information to assign unique identity• Location protected species• Reference data from European National Mapping and

Cadastral Agencies• Conflated data

• Testbed for research and development

Page 9: COBWEB, AIP-6 and Access Management Federations Chris Higgins, Project Coordinator, University of Edinburgh. chris.higgins@ed.ac.uk Andreas Matheus, Technical

GEOSS’s current need for SSO

• From previous AIP’s, identified need for all users to authenticate so can gather metrics

• Concept of a “GEOSS-User”: – any authenticated participant from the GEOSS

AIP-6 Access Management Federation• Access Management Federations enable SSO

Page 10: COBWEB, AIP-6 and Access Management Federations Chris Higgins, Project Coordinator, University of Edinburgh. chris.higgins@ed.ac.uk Andreas Matheus, Technical

AIP-5 “Use Cases” in scope for COBWEB AIP-6 work

• Registration for Authentication via OpenID• Registration as OpenID user for Authentication via SAML2 • Organizational user for Authentication via SAML2 • Identification as "GEOSS User" During Registration • OpenID-Protected Data Access via OpenID Authentication • SAML2-Protected Data Access via OpenID Authentication • OpenID-Protected Data Access via SAML2 Authentication • SAML2-Protected Data Access via SAML2 Authentication • Registering and Modifying a New Identity or Service Provider

Page 11: COBWEB, AIP-6 and Access Management Federations Chris Higgins, Project Coordinator, University of Edinburgh. chris.higgins@ed.ac.uk Andreas Matheus, Technical

GEOSS AIP-6 Data Sharing and COBWEB • Plan is to setup a federation of GEOSS members to establish SSO• Not currently concentrating any particular SBA’s, however SBA Water is

participating• Support Single Sign On• Reliable identification of a “GEOSS-user”• Desired outcome for AIP-6 is answers to:

– Can AMF’s meet COBWEB requirements for privacy?– Do AMF’s meet GEOSS requirements?

Page 12: COBWEB, AIP-6 and Access Management Federations Chris Higgins, Project Coordinator, University of Edinburgh. chris.higgins@ed.ac.uk Andreas Matheus, Technical

Current list of organisations indicating strong interest in participating:

– ESA (European Space Agency)– NASA (North American Space Agency)– INPE (National Institute for Space Research)– Tufts University– Secure Dimensions – EDINA (University of Edinburgh)

Will expand:– Other FP7 projects?– Existing academic sector federations?

{

COBWEB partners

Page 13: COBWEB, AIP-6 and Access Management Federations Chris Higgins, Project Coordinator, University of Edinburgh. chris.higgins@ed.ac.uk Andreas Matheus, Technical

• Sept 2013: Demo of COBWEB AIP-6 outputs at OGC Technical Committee meeting at ESA/ESRIN

• Jan 2014: AIP-6 results demonstrated at GEO Plenary in Geneva

• Feb 2014: Completion of AIP-6 activities• Post AIP-6, COBWEB will respond to feedback from

stakeholders, eg, GEO, in framing next steps, maybe:– Electronic licence negotiation– Authorisation – eCommerce– …?

AIP-6 Results / Future Work

Page 14: COBWEB, AIP-6 and Access Management Federations Chris Higgins, Project Coordinator, University of Edinburgh. chris.higgins@ed.ac.uk Andreas Matheus, Technical

Links to Previous Work regarding AMF • OGC White Paper

http://portal.opengeospatial.org/files/?artifact_id=47848

• Engineering Report from the OGC Web Service Shibboleth Interoperability Experiment

https://portal.opengeospatial.org/files/?artifact_id=47852

• INSPIRE Conference 2011 Paper http://ijsdir.jrc.ec.europa.eu/index.php/ijsdir/article/view/245/324

• Authentication workshop at the GEO-IX Plenary, Brazil, 2012http://edina.ac.uk/events/cobwebworkshop.html