Enhancing seamless access using TIGERfed

bdnog 72 views 28 slides Jul 15, 2024
Slide 1
Slide 1 of 28
Slide 1
1
Slide 2
2
Slide 3
3
Slide 4
4
Slide 5
5
Slide 6
6
Slide 7
7
Slide 8
8
Slide 9
9
Slide 10
10
Slide 11
11
Slide 12
12
Slide 13
13
Slide 14
14
Slide 15
15
Slide 16
16
Slide 17
17
Slide 18
18
Slide 19
19
Slide 20
20
Slide 21
21
Slide 22
22
Slide 23
23
Slide 24
24
Slide 25
25
Slide 26
26
Slide 27
27
Slide 28
28

About This Presentation

Enhancing seamless access using TIGERfed, The only identity federation for the R&E community of Bangladesh.


Slide Content

Enhancing seamless access using TIGERfed Abu Naser Md. Nafew Network Engineer, BdREN The only identity federation for the R&E community of Bangladesh.

Evolution of Identity Management

Campus level Identity Management Identity starts at your university campus and research institutions. Staff, Students and researchers join the university community for Work Study Research The institutions will capture some information about the person HR Systems Student Systems Research systems Issue credentials Username / ID Password / Pin MFA Tokens (Mobile app, Security Tokens, SMS, etc )

Campus level Identity Management The Provisioning system provides... Credentials Email Authorization to services Learning Management System (LMS) Wireless access Online Storage Collaboration tools And many other campus services Physical access (swipe card access) Plenty of options for provisioning services Home grown systems (scripts) Commercial offerings MS MIM and FIM SalePoint WSO2 ForgeRock OKTA OpenSource OpenIAM MidPoint Gluu FreeIPA Most institutions will have some processes and tools that make up a provisioning service.

Campus level Identity Management The Provisioning system provides... Credentials Email Authorization to services Learning Management System (LMS) Wireless access Online Storage Collaboration tools And many other campus services Physical access (swipe card access) Plenty of options for provisioning services Home grown systems (scripts) Commercial offerings MS MIM and FIM SalePoint WSO2 ForgeRock OKTA OpenSource OpenIAM MidPoint Gluu FreeIPA Most institutions will have some processes and tools that make up a provisioning service.

Single Sign-on One credential to access many services. Benefits Institutions needs to issue only one set of credentials Enables users to remember fewer credentials Streamlines the login process Reduces the chance of phishing Reduces support desk tickets Risks (all can be mitigated) Authorization still needs to be addressed User may get locked out of many services it authentication service is unavailable Unauthorized users gain access to more than one service Authentication service becomes a point of attack Once provisioning is sorted out, most institutions will move to Single Sign-on Convenience vs Risk

The dawn of federations There is natural progression from enterprise IAM to federated IAM, but we need some level of trust... Federated identity management ( FIdM ) amounts to having a common set of policies, practices and protocols in place to manage the identity and trust into IT users and devices across organizations With a trust framework in place, tools in place and common protocols users and one institution using the credentials issued by their institution can access services at a another institute or company.

Federated Identity Management For higher education, two forms for Federated Identity Management emerged: eduroam : A federation providing wireless access Identity Federations: Single-sign on for Web based applications

eduroam eduroam is an international Wi-Fi internet access roaming service for users in research, higher education and further education. It provides researchers, teachers, and students network access when visiting an institution other than their own. In 2023, the eduroam system recorded over 7.5 billion national and international authentications. HSIA has become one among more than 30 international airports in the world that provide “ eduroam ” services to the travelers. 

eduroam HSIA has become one among more than 30 international airports in the world that provide “ eduroam ” services to the travelers.  This has become the first such instance in the Asia-Pacific region. BdREN is looking forward to enabling “ eduroam ” service at other international airports in the country such as the Osmani International Airport, Sylhet, and the Shah Amanat International Airport, Chittagong.

Identity Federation

Identity Federation Research and Educations identity federations are generally operated by the NREN. Policy framework that ensure trust Technology framework that implements authentication standards SAML (Secure Access Markup Language) OpenIDConnet Management and Support Bring Identity Providers and Service Provider together

Identity Federations Currently there are at least 76 National Research and Educations federations, 15 of which are in the Asia / Pacific region. Different levels of maturity Different focuses Supporting Research Access to Publisher resources Providing teaching and learning tools and infrastructure Collaboration Different levels of support from a fraction of EFTSU to 20+ staff members

TIGERfed The  TIGERfed  is the first and only Identity Federation for education and research organizations in Bangladesh which is operated by Bangladesh Research and Education Network  (BdREN) . The  TIGERfed  Identity Federation is introduced to facilitate and simplify the access of shared services across the Federation.

Federations around the Globe

Benefits of Identity Federation

One of the key beneficiaries of the identity and access federation are the University Libraries

eduGAIN The eduGAIN interfederation service connects identity federations around the world, simplifying access to content, services and resources for the global research and education community. eduGAIN comprises 76 participant federations connecting more than 8,500 Identity and Service Providers. 4959 Identity Providers 3582 Service Providers Continues to grow and improve... TIGERfed is member of edugain

Benefits of Identity Federation for Libraries

Current Methodologies of Accessing Digital Resources OPTION 01 Remotely Access the digital resources from outside of campus by taking the paid services like OpenAthens , EzProxy Remote Access Users can access the digital resources by accessing it from Campus Network Accessing On-Campus

Similarities Between OpenAthens and TIGERfed B A Federation for Remote Access to publishers and digital resources Secured and Reliable Hosted Identity Provider Identity and Access Federation for the research and Education community of Bangladesh Secured and Reliable IDP-as-a-Service with Hosted Solution

Shifting of Remote Access KUET BUET DU BRACU SUST BSMRSTU B U PUST RU SAU BAU University X

Shifting of Remote Access KUET BUET DU BRACU SUST BSMRSTU B U PUST RU SAU BAU University X

Advantages of TIGERfed over OpenAthens KUET BUET DU BRACU SUST BSMRSTU B U PUST RU SAU BAU Free of Cost TIGERfed hosted IDP is completely free of cost No Limits on Accounts There is no limit in the maximum number of accounts for remote access Hassle Free Library Administration doesn’t need to create any account for anyone Dedicated Support 24*7 Support from our NOC in case of any necessity

We Provide SSO and Remote Access to With many edugain services like: indico Cloudstor Sciencedata Semanticscholar and many more…

D e m o n s t r a t i o n o f R e m o t e A c c e s s w i t h T I G E R f e d

Questions?

Thank you TIGERfed