130 likes | 256 Vues
The Open Collaboration Exchange (OCE) presents an innovative transnational infrastructure designed to interconnect identity and service providers, enhancing authentication, authorization, and group management. By leveraging established trust frameworks like eduGAIN, OCE facilitates seamless cloud service delivery across sectors while supporting public-private partnerships. The platform employs open standards and open-source technology, providing self-service configuration and value-added services. OCE aims to overcome barriers in transnational collaboration and promote knowledge transfer between research, education, and other sectors.
E N D
Open Collaboration Exchange Alexander Blanc, Niels van Dijk, JocelynManderveld, Remco Poortinga - van Wijnen VAMP 2013, Espoo
Currentsituation (goodnews) • AAI/FIM well establishedacross Europe andelsewhere • Solid growth (NL) on number of connectedIDPs, SPsandusage • eduGAINbridges HE&R fields
Most used services • All ‘campus centric’ type of services (notsurprisingly) • Alsointernal services (portal, timetable, …) • Institutionssomewhatreluctantto move to the cloud (for employees) • Google appsmostlyforstudentsonly
But… • eduGAINonly start of a solution (enabling) • AlthougheduGAINconnects HE&R, no bridge toother (commercial/research) communities/fieldsyet (see VCH) • (HE&R) FederationstypicallynotallowedtoconnectotherIdPs • Most IdPs focus on ‘campus centric’ services • Difficultto get IdPstoconnectto services for a subset of users • E.g. VO services… • Opt-out vsopt-in? • Try ‘zero attribute’ authentication? • No simplemagic solution
So… • Can we applyideasfrom the networkworld? • Especiallynetwork exchanges? • See FromNetwork Exchange toCollaboration Exchange - A guided tourhttps://tnc2012.terena.org/core/session/10 • Make it easy toconnectand let participantsdecidewhothey want toworkwith
O.C.E. why? Transnational • Several use cases show: • Federated approach needed as ‘enterprise’ IDM trust models are poorly suited for collaborative cross-sector and transnational activities • Transnational collaboration is hindered by differences in federation readiness, licensing issues, technical and other barriers. • OCE allows entities to connect to multiple trust frameworks on one technical platform • OCE will support several well established trust frameworks (e.g. eduGAIN) by default • OCE significantly lowers barriers for transnational cloud service delivery
O.C.E. why? Cross-sector • OCE supports cross-sector collaboration capabilities out of the box • OCE specifically supports public/private partnerships • Therefore decreasing need for guest access • OCE enables knowledge transfer on federated approaches from research and education to other sectors
What are Open Collaboration Exchanges? • An transnational infrastructure for identity- and service providers to interconnect, facilitating authentication-, authorization- and group management processes • An infrastructure; • that combines a technical infrastructure (a "switchboard") with multiple behavioural trust/policy frameworks • and thus allows entities to connect to multiple trust frameworks on one technical platform • An open and secure platform, using open standards, based on open source (OpenConext) technology • Self-service configuration interfaces forall participants • Ecosystem for ‘value-added services’, such as a higher level of authentication, statistics, provisioning, metering/billing, etc. • Aimed towards implementation of multi-stakeholder governance and maintenance • Enabler of cross-sector and transnational collaboration and service delivery
O.C.E. Whatit is not • A replacementforeduGAIN • Leverages/useseduGAINandother services/trust frameworks • Pixiedustforcollaboration • Still a lot (most?) effort for non-technical issues • A trust frameworkitself • ‘Only’ aggregatorwithoptionaladdedself-servicefunctions • A finished product • Stillverymuch a concept/idea, manymanythingsstillunclear
O.C.E.Overview • Entree • IDP1 • SP1 • DIGID • IDP1 • SP1 OCE (metadata) • trust framework2 • IDP1 • SP2 • eduGAIN • IDP1 • IDP2 • SP2 SP1 IDP1 • Trust framework • SURFconext • DIGID • Trust framework • eduGAIN • SURFconext • DIGID OCE (self-service) SP2 IDP2 • Trust framework • eduGAIN • Trust framework • eduGAIN • WAYF
O.C.E. What’s next? • Engage • Different (european) educational federations • Several OpenConext pilot partners • eduGAIN • Global partners • Learn • AMS-IX, Netherlight and other exchanges • Possible similar ideas, initiatives or projects • Partnerships • Work with strategic partners on innovation, governance, and funding • Pilots • In research and education • Cross-sector
O.C.E.pointers • eduGAINwww.edugain.org • OpenConextwww.openconext.org • From Network Exchange toCollaboration Exchange - A guidedtour https://tnc2012.terena.org/core/session/10 • MARIO https://tnc2013.terena.org/core/session/27 • CollaborationExchange for Services andIdentitieshttps://blog.surfnet.nl/?p=2392