SlideShare a Scribd company logo
Report on EDINA Authentication Related Academic Sector Activities ESDIN Work Package 11 Meeting, KMS, Copenhagen, 9 th  June 2010 Chris Higgins, Michael Koutroumpas, EDINA, University of Edinburgh [email_address]
Aim for next 20 mins or so Brief WP11 on progress with key EDINA activities since Athens meeting Present some thoughts on how to progress and get some discussion
Overall aim of the eContentplus programme is “to make digital content in Europe more accessible, usable and exploitable”  UEDIN trying to represent academic sector interest Trying to bring content to students, lecturers, researchers, etc, in the UK and across the rest of Europe UEDIN/EDINAs objective
Mention of the Academic Sector in the DoW #1 Expected Results :  “ Seamless INSPIRE- conformant access to the above data through a distributed technical architecture to key elements within the European academic sector   ”  A significant number of academic users using INSPIRE conformant ExM data and geoprocessing services, enabling research and education predicated on harmonised data capable of being combined with additional content.  This will be a significant contribution towards the establishment of a European academic SDI through involvement of the European Persistant Testbed for Research and education (PTB)”
Mention of the Academic Sector in the DoW #2 Target users and there needs :   “ European academic sector. To maximise benefit to the European Economic area. Students, researchers, etc, should have access to services which allow them to be educated and conduct research using the highest quality interoperable pan-European data available from the NMCAs.”
Mention of the Academic Sector in the DoW #3 Success indicators :  30 institutions 5 institutions n/a Spatial Information (5) Significant number of academic users engaged in research and education using the harmonised ESDIN geospatial services hosted by UEDIN. 5 Year 3 Year 2 Year 1 Expected Progress Indicator name Objective/expected result Indicator Expected Progress Nr
Mention of the Academic Sector in the DoW #4 Sustainability :  “ UEDIN will continue, with the agreement of EuroGeographics, to make pan-European datasets based view and download services available to the academic sector post project for a minimum of 6 months and longer if funding becomes available. The latter will be possible as ESDIN, and related projects, will lay the foundations for a European academic SDI. ”
DoW #5 Deliverable 11.6 “ Operational view/download services conforming to INSPIRE implementation rules into the academic sector geospatial testbed(s)” Month 29 Accompanying report Initiating through a discussion document to WP11 members and others as appropriate
Status immediately post WP11 Athens Jan 10 EDINA to continue to lead ESDIN work on OGC Authentication Interoperability Experiment With assistance from consultant Andreas Matheus ESDIN NMCAs to be invited to join test Federation Continued relationship with the PTB Open question. How does this work fit with other ESDIN activities?  Especially: WP3: Use Cases WP4: Data Access and Licencing Policy WP11: ESDIN client WP12: Testing Framework
OGC Interoperability Experiments Intended as a relatively simple, low overhead, means for OGC members to get together and advance specific technical objectives within the OGC baseline Facilitated by OGC staff More lightweight than the OGC Web Services initiatives  Focussed on specific interoperability issues  Effort is viewed as voluntary and supported by in-kind contributions by participating member organisations  Duration normally around 6 months
Authentication IE OpenGIS Project Document 09-092r1  Test standard ways of transferring authentication information between OGC clients and OGC services  The following mechanisms will be tested:  HTTP Authentication HTTP Cookies SSL/X509, SAML Shibboleth OpenID WS-Security   From OGC perspective, the main output will be an OGC Engineering Report that may be upgraded to a best practice document
Current Status Sept 2009: pre-Kickoff meeting at the Darmstadt OGC Technical Committee (TC) meeting Dec 2009: formal Kickoff at the Mountain View TC Tentative end date June 2010 IE participants:  NGA; Secure Dimensions; CubeWerx; NASA (Pat Cappelare); The Carbon Project; 52North; WhereGroup; EDINA; BRGM; Lat/Lon; DSTL (UK MOD); German Mapping Authority; Army Geospatial Center; ESRI; Interactive Instruments Nothing on OpenID, WS-Security
Status ESDIN Partners Participation  Test federation with 2 IdPs and 3 SPs established (see demo) 3 clients capable of undergoing Shibb interactions: OpenLayers (browser) OpenJump SAML Enhanced Client Profile (desktop) OpenJump Browser/Artefact SAML profile (desktop) May 10th.  Initial meeting at Kadaster with GeoDan to discuss integration with ESDIN client Participation invite sent to NMCAs with responses from: KMS Kadaster Lantamatariet Fomi
Status PTB Participation #1  Dec ’09’ PTB Phase2 Call for Proposals text… “ Willingness to participate in an “access management federation of European universities” project as part of an OGC Authentication Interoperability Experiment. The objective here is to demonstrate securely sharing licensed data across the European academic sector using OGC Web Services” Solicited proposals from organisations who showed…
Access Management Phase 2 responses from: EDINA, University of Edinburgh FIUGINET (Finnish Universities Geoinformatics Network) and CSC — IT Center for Science Ltd Technical University of Dresden Centre for Geospatial Science, University of Nottingham Pre-conference PTB workshop in association with AGILE 2010 on the 11 th  May discussing outcomes of the phase 2 CfP   Status PTB Participation #2
Immediate Next Steps Continue working with the NMCAs and PTB Effectively technology interoperability experiments Continue working with consultant Andreas Matheus Variety of OWS Continue to work with GeoDan on the ESDIN client Create additional Use Cases and implement to show: A SSO federation that allows NMCAs to securely grant access to each others ExM data (small, medium and large) PTB universities securely accessing ExM data Small/medium scale hosted by EDINA Large scale dependent upon NMCAs Dovetail these Use Cases with the WP3/WP4 work
After that… Write up ESDIN Best Practice document Possibly submit to the OGC? Make the client software we have created openly available  Have an OGC facilitated vendor/NMCA plugfest showing how their software can undergo the Shibb interactions Consider what SAML assertions necessary to make these kinds of pan-European authorisation decisions Consider cross-federation interoperability issues
Additional possibilities? Expand federation to include additional NMCAs Expand federation to include additional universities Explore chaining federation services to show possibilities beyond secure data access Possibly using services and ideas from the academic sector, ie, PTB phase 2 call? Secure the BKG hosted central EGN WFS using Shibb

More Related Content

Report on EDINA Authentication Related Academic Sector Activities

  • 1. Report on EDINA Authentication Related Academic Sector Activities ESDIN Work Package 11 Meeting, KMS, Copenhagen, 9 th June 2010 Chris Higgins, Michael Koutroumpas, EDINA, University of Edinburgh [email_address]
  • 2. Aim for next 20 mins or so Brief WP11 on progress with key EDINA activities since Athens meeting Present some thoughts on how to progress and get some discussion
  • 3. Overall aim of the eContentplus programme is “to make digital content in Europe more accessible, usable and exploitable” UEDIN trying to represent academic sector interest Trying to bring content to students, lecturers, researchers, etc, in the UK and across the rest of Europe UEDIN/EDINAs objective
  • 4. Mention of the Academic Sector in the DoW #1 Expected Results : “ Seamless INSPIRE- conformant access to the above data through a distributed technical architecture to key elements within the European academic sector ” A significant number of academic users using INSPIRE conformant ExM data and geoprocessing services, enabling research and education predicated on harmonised data capable of being combined with additional content. This will be a significant contribution towards the establishment of a European academic SDI through involvement of the European Persistant Testbed for Research and education (PTB)”
  • 5. Mention of the Academic Sector in the DoW #2 Target users and there needs : “ European academic sector. To maximise benefit to the European Economic area. Students, researchers, etc, should have access to services which allow them to be educated and conduct research using the highest quality interoperable pan-European data available from the NMCAs.”
  • 6. Mention of the Academic Sector in the DoW #3 Success indicators : 30 institutions 5 institutions n/a Spatial Information (5) Significant number of academic users engaged in research and education using the harmonised ESDIN geospatial services hosted by UEDIN. 5 Year 3 Year 2 Year 1 Expected Progress Indicator name Objective/expected result Indicator Expected Progress Nr
  • 7. Mention of the Academic Sector in the DoW #4 Sustainability : “ UEDIN will continue, with the agreement of EuroGeographics, to make pan-European datasets based view and download services available to the academic sector post project for a minimum of 6 months and longer if funding becomes available. The latter will be possible as ESDIN, and related projects, will lay the foundations for a European academic SDI. ”
  • 8. DoW #5 Deliverable 11.6 “ Operational view/download services conforming to INSPIRE implementation rules into the academic sector geospatial testbed(s)” Month 29 Accompanying report Initiating through a discussion document to WP11 members and others as appropriate
  • 9. Status immediately post WP11 Athens Jan 10 EDINA to continue to lead ESDIN work on OGC Authentication Interoperability Experiment With assistance from consultant Andreas Matheus ESDIN NMCAs to be invited to join test Federation Continued relationship with the PTB Open question. How does this work fit with other ESDIN activities? Especially: WP3: Use Cases WP4: Data Access and Licencing Policy WP11: ESDIN client WP12: Testing Framework
  • 10. OGC Interoperability Experiments Intended as a relatively simple, low overhead, means for OGC members to get together and advance specific technical objectives within the OGC baseline Facilitated by OGC staff More lightweight than the OGC Web Services initiatives Focussed on specific interoperability issues Effort is viewed as voluntary and supported by in-kind contributions by participating member organisations Duration normally around 6 months
  • 11. Authentication IE OpenGIS Project Document 09-092r1 Test standard ways of transferring authentication information between OGC clients and OGC services The following mechanisms will be tested: HTTP Authentication HTTP Cookies SSL/X509, SAML Shibboleth OpenID WS-Security From OGC perspective, the main output will be an OGC Engineering Report that may be upgraded to a best practice document
  • 12. Current Status Sept 2009: pre-Kickoff meeting at the Darmstadt OGC Technical Committee (TC) meeting Dec 2009: formal Kickoff at the Mountain View TC Tentative end date June 2010 IE participants: NGA; Secure Dimensions; CubeWerx; NASA (Pat Cappelare); The Carbon Project; 52North; WhereGroup; EDINA; BRGM; Lat/Lon; DSTL (UK MOD); German Mapping Authority; Army Geospatial Center; ESRI; Interactive Instruments Nothing on OpenID, WS-Security
  • 13. Status ESDIN Partners Participation Test federation with 2 IdPs and 3 SPs established (see demo) 3 clients capable of undergoing Shibb interactions: OpenLayers (browser) OpenJump SAML Enhanced Client Profile (desktop) OpenJump Browser/Artefact SAML profile (desktop) May 10th. Initial meeting at Kadaster with GeoDan to discuss integration with ESDIN client Participation invite sent to NMCAs with responses from: KMS Kadaster Lantamatariet Fomi
  • 14. Status PTB Participation #1 Dec ’09’ PTB Phase2 Call for Proposals text… “ Willingness to participate in an “access management federation of European universities” project as part of an OGC Authentication Interoperability Experiment. The objective here is to demonstrate securely sharing licensed data across the European academic sector using OGC Web Services” Solicited proposals from organisations who showed…
  • 15. Access Management Phase 2 responses from: EDINA, University of Edinburgh FIUGINET (Finnish Universities Geoinformatics Network) and CSC — IT Center for Science Ltd Technical University of Dresden Centre for Geospatial Science, University of Nottingham Pre-conference PTB workshop in association with AGILE 2010 on the 11 th May discussing outcomes of the phase 2 CfP Status PTB Participation #2
  • 16. Immediate Next Steps Continue working with the NMCAs and PTB Effectively technology interoperability experiments Continue working with consultant Andreas Matheus Variety of OWS Continue to work with GeoDan on the ESDIN client Create additional Use Cases and implement to show: A SSO federation that allows NMCAs to securely grant access to each others ExM data (small, medium and large) PTB universities securely accessing ExM data Small/medium scale hosted by EDINA Large scale dependent upon NMCAs Dovetail these Use Cases with the WP3/WP4 work
  • 17. After that… Write up ESDIN Best Practice document Possibly submit to the OGC? Make the client software we have created openly available Have an OGC facilitated vendor/NMCA plugfest showing how their software can undergo the Shibb interactions Consider what SAML assertions necessary to make these kinds of pan-European authorisation decisions Consider cross-federation interoperability issues
  • 18. Additional possibilities? Expand federation to include additional NMCAs Expand federation to include additional universities Explore chaining federation services to show possibilities beyond secure data access Possibly using services and ideas from the academic sector, ie, PTB phase 2 call? Secure the BKG hosted central EGN WFS using Shibb

Editor's Notes

  1. These are a note to self. Remind myself what it is we are aiming for Come back to PTB
  2. Distinction between ambition and what will be required to actually deliver At end of project, would like to produce a report identifying what done
  3. The current objectives. Question at time whether much of what is being discussed is in scope
  4. Has precedent in Galeon (more than one phase) and Oceans IE (open to non-OGC members)
  5. The current objectives. Question at time whether much of what is being discussed is in scope
  6. The current objectives. Question at time whether much of what is being discussed is in scope Work the Canadians have done
  7. Multiple ESDIN clients demonstrating various aspects of the infrastructure
  8. The current objectives. Question at time whether much of what is being discussed is in scope