Federated Identity Management Is The State of Texas

  • Slides: 27
Download presentation
Federated Identity Management: Is The State of Texas Ready? TASSCC 2008 August 12, 2008

Federated Identity Management: Is The State of Texas Ready? TASSCC 2008 August 12, 2008 Paul Caskey The University of Texas System-wide Information Services

Agenda • • • Identity Management: The Basics Federating Technologies Benefits of Federation Challenges

Agenda • • • Identity Management: The Basics Federating Technologies Benefits of Federation Challenges of Federation Examples of Federations in Texas Federated Applications What Are Others Doing? How Could It Work In Texas? What Will The Future Hold? Next Steps 2

Id. M: The Basics • Identity Management: § The union of policy, process, governance,

Id. M: The Basics • Identity Management: § The union of policy, process, governance, and technology surrounding the creation, maintenance, and use of digital identities. • Federation: § An organized group of entities who share one or more: – – – Goals Applications Customers Regulatory environments Funding sources Industry 3

Id. M: The Basics (cont. ) • Federated Identity Management: § Participating in an

Id. M: The Basics (cont. ) • Federated Identity Management: § Participating in an organized group of entities who agree to follow shared policies, maintain consistent practices, and trust other participants with respect to the creation, maintenance, and use of digital identities. § Moving away from application or service provider based identity towards institutional or enterprise based identity. § “Authenticate locally, act globally!” 4

Traditional Identity Management Benefits Administrative Apps Grid Computing Institution A Compliance Training Library Institution

Traditional Identity Management Benefits Administrative Apps Grid Computing Institution A Compliance Training Library Institution B = Credentialing / Authentication = Authorization = User Credential

Federated Identity Concept Federation Benefits Administrative Apps Grid Computing Institution A Compliance Training Library

Federated Identity Concept Federation Benefits Administrative Apps Grid Computing Institution A Compliance Training Library Institution B = Credentialing / Authentication = Authorization = User Credential

Id. M: The Basics (cont. ) • What are some of the policies and

Id. M: The Basics (cont. ) • What are some of the policies and practices that are important in federated identity management? § § § Identity verification (vetting) Credentialing Password policies Provisioning Auditing 7

Id. M: The Basics (cont. ) • Examples of policy standards and associated regulation

Id. M: The Basics (cont. ) • Examples of policy standards and associated regulation that affect Federated Id. M: § US Federal Governement’s e. Authentication Credential Assessment Suite – Password Entropy Spreadsheet (assess password policy) § NIST Special Publication 800 -63 § The Office of Management and Budget memorandum OMB 04 -04 § US Federal Homeland Security Presidential Directive 12 (HSPD-12) § The European Union’s privacy directive 95/46/EC 8

Id. M: The Basics (cont. ) • Examples of policy standards and associated rules

Id. M: The Basics (cont. ) • Examples of policy standards and associated rules and laws that affect Federated Id. M (cont): § § § Code of Federal Regulations 21, part 11 HIPAA FERPA (Education only) Sarbanes-Oxley (SOX) Graham-Leach-Bliley (GLB) Texas: TAC 202, TBCC - Title 11: Personal Identity Information 9

Federating Technologies • Security Assertion Markup Language (SAML) – a standard developed and ratified

Federating Technologies • Security Assertion Markup Language (SAML) – a standard developed and ratified by OASIS, an international non-profit standards organization. • WS-Federation – a specification developed by IBM, Microsoft, BEA (and others); OASIS now has a technical committee tasked with standardizing WS-Fed. • Liberty Identity Federation Framework (ID-FF) – has now been integrated into the SAML 2. 0 standard. • Open. ID – a user-centric distributed web-SSO technology, generally more lightweight and less-focused around communities of trust than SAML. 10

Federating Technologies (cont. ) • SAML is the most robust, is mature, is internationally

Federating Technologies (cont. ) • SAML is the most robust, is mature, is internationally standardized, and has a large user base. (demo) • Most available software supports multiple protocols. • Commercial: Sun, IBM/Tivoli, Oracle, Novell, Ping Identity • Open-source: Shibboleth (from Internet 2) • Here’s some comparisons of SAML to WS-Fed: § Sun Blog 1 § Sun Blog 2 (more in-depth) 11

Benefits of Federation • Share Resources (training systems) • Collaborate (wikis) • Lower costs

Benefits of Federation • Share Resources (training systems) • Collaborate (wikis) • Lower costs (no application-based Id. M) • Increase security / Improve the user experience (fewer usernames/passwords) 12

Challenges of Federation • Deploying new infrastructure is hard § The infrastructure must be

Challenges of Federation • Deploying new infrastructure is hard § The infrastructure must be there before gains can be realized, which makes justification a challenge. • Policy development can take considerable time. • Trust can be difficult to achieve. § Good policy and governance helps (“trust but verify”) • Making it ubiquitous across entities of varying size is a challenge. § Many times, it is the smaller organizations that can benefit most. 13

Examples of Government. Funded Federations • National § US: The Federal Government’s e. Authentication

Examples of Government. Funded Federations • National § US: The Federal Government’s e. Authentication initiative (www. cio. gov/eauthentication) § US: The In. Common Federation (www. incommonfederation. org) § Sweden (www. swamid. se) § Denmark (www. dk-aai. dk) § UK (www. ukfederation. org - 5 million + users) § China (CARSI - shibboleth. edu. cn) § France (federation. cru. fr) 14

Examples of Government. Funded Federations (cont. ) • National: (cont) § § § §

Examples of Government. Funded Federations (cont. ) • National: (cont) § § § § Germany (www. dfn. de) The Netherlands (federatie. surfnet. nl) Norway (www. feide. no) Finland (www. csc. fi) Belgium (shib. kuleuven. be) Australia (www. federation. org. au) Switzerland (www. switch. ch) 15

Examples of Other Federations: • Medical Disaster Management: Project Sentinel (http: //sentinel. georgetown. edu/)

Examples of Other Federations: • Medical Disaster Management: Project Sentinel (http: //sentinel. georgetown. edu/) • Cancer Research: ca. BIG (https: //cabig. nci. nih. gov/) • State-based: § North-Carolina (MCNC Project Page) § Texas: Lone Education and Research Network (LEARN) https: //eco. tx-learn. net/ (more later) 16

Federation in Texas • The University of Texas System Federation § Participants include only

Federation in Texas • The University of Texas System Federation § Participants include only U. T. System institutions and “sponsored affiliates”. § Serves a constituency of 190, 000 students and 80, 000 employees § First federated application in 2004, official production status on 9/1/2006 § Focus has been on business applications § 40+ applications in use, including 4 (and counting) commercial products/services 17

Federation in Texas (cont. ) • The Lonestar Education and Research Network (LEARN) Federation

Federation in Texas (cont. ) • The Lonestar Education and Research Network (LEARN) Federation § Participation is open to LEARN members and sponsored affiliates § In pilot operation as of spring 2008 § Policy work underway § Governing board is being formed § One application in use (more under development) 18

Current Federated Applications • • • • Microsoft Dream. Spark (LEARN Federation) Forensics Assessment

Current Federated Applications • • • • Microsoft Dream. Spark (LEARN Federation) Forensics Assessment Center Network (UT/LEARN) Mobile. Campus. com Cayuse Adobe Connect (compliance training) Blackboard (course management) Media. Wiki Federated Wireless Legal. Tracking Risk Management (ISAAC) Financial Reporting Project Reporting Federated Sharepoint (in development) 19

What Are Others Doing? • A quick google search turned up mentions of Federated

What Are Others Doing? • A quick google search turned up mentions of Federated Identity Management in a surprising number of states: § California – Federated Id. M: The Blueprint (PPT) § New York – https: //www. oft. state. ny. us/Policy/G 07 -001/ (trust model) – https: //www. oft. state. ny. us/oft/IAM. htm (IAM) § Washington – http: //dis. wa. gov/enterprisearch/identitymgmt. Initiativ e. Charter. doc (planning doc) 20

What Are Others Doing? (cont. ) • States that are discussing Federated Id. M

What Are Others Doing? (cont. ) • States that are discussing Federated Id. M (cont. ): § New Jersey – http: //www. state. nj. us/it/ps/it_architecture. pdf § Nevada – http: //www. nitoc. nv. gov/ARCH/arcdocs/2005/EACMinutes-2005 -09 -20. doc (older doc) § Wisconsin – Id. M Overview 21

What Are Others Doing? (cont. ) • States that are discussing Federated Id. M

What Are Others Doing? (cont. ) • States that are discussing Federated Id. M (cont. ): § Nebraska – http: //www. nitc. state. ne. us/events/conferences/egov/2004/files/ 345_User. Authentication_Hartman-Fed. ID. ppt § And, last, but most certainly not least, TEXAS – http: //www. dir. state. tx. us/pubs/User. Access. Study. p df (DIR’s user access study from 2006) – http: //architecture. hhsc. state. tx. us/myweb/Documents%20 page /identity. Management. doc (HHS) 22

How Could It Work in Texas? • There are countless agency-to-agency applications § §

How Could It Work in Texas? • There are countless agency-to-agency applications § § § A variety DIR reporting apps (security, projects, etc) Pediatric forensics (FACN) Educational support (K-12) Transportation (Tx. DOT) Law enforcement • The 800 pound elephant in this space is, of course, Texas. Online (government-to-citizen) § Who is the identity provider for Joe Citizen? 23

The Future? • Standards convergence (SAML, WS-Fed, Open. ID) • Interfederation § Building trust

The Future? • Standards convergence (SAML, WS-Fed, Open. ID) • Interfederation § Building trust paths between federations § In certain cases, the legal issues can be daunting (especially on an international basis) • More public Identity Providers (yahoo, google) § Protect. Network. org already serves this purpose worldwide and basic accounts are free. • Cardspace/Infocard 24

Next Steps for Texas • To pursue a Federated Identity Management approach, Texas should:

Next Steps for Texas • To pursue a Federated Identity Management approach, Texas should: § Establish an Id. M governance framework § Define Id. M policies/best-practices (this takes considerable time) § Identify a few low-risk, limited audience applications § Begin pilot operations with those who are ready § Make arrangements for smaller agencies to use externally-hosted identity providers (like Protect. Network. org) 25

 • So, Is the state of Texas ready for Federated identity Management? §

• So, Is the state of Texas ready for Federated identity Management? § The technology is available, secure, robust, reliable, and mature. § Policy frameworks exist. § Governance models can be established. § Expertise is available. § External services are ready. § The benefits are clear and significant. • We're only waiting on us! 26

Thank You! Paul Caskey (pcaskey@utsystem. edu) The University of Texas System-wide Information Services

Thank You! Paul Caskey (pcaskey@utsystem. edu) The University of Texas System-wide Information Services