50 likes | 209 Vues
A F ew Ideas on eduroam Service Composition. In Brief. Take advantage of the eduroam data exchange to provide additional information useful to other services O paque identity A ttributes used for admission Location Postures (NEA/NAC/…) Possible use cases Delegated authorization
 
                
                E N D
In Brief • Take advantage of the eduroam data exchange to provide additional information useful to other services • Opaque identity • Attributes used for admission • Location • Postures (NEA/NAC/…) • Possible use cases • Delegated authorization • Location-aware services • Security assessment
Some Possible Procedures • The user knows their opaque identity • In advance (EPPN / EPTID) • Interactively (CUI) • By means of an artifact (eduTokenInfoCard) • And can be applied to • Services controlling firewalls by a local user • Queries to establish location and origin at portals or service gateways • STS as enabler for other composed services • Enhanced log correlation and analysis • Any other consumer of the exchanged data
A Path to Start Exploring • Accessible data • Minimum impact on protocols • Access procedures • Requirements for additional components • Humans in the loop • Management • Privacy • eduroam as consumer • Any use case? • Let it happen™