Federated Access Managment: Making the Business Case

Loading...

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

0 comments

Post a comment

    Post a comment
    Embed Video
    Edit your comment Cancel

    Favorites, Groups & Events

    Federated Access Managment: Making the Business Case - Presentation Transcript

    1. Connecting People to Resources Federated Access: Building the Business Case Nicole Harris Programme Manager
    2. JISC Announcement
      • In March 2006, JISC formally announced its intention to support federated access management as the preferred access management solution for UK Further and Higher Education
      • JISC will continue funding the Athens service until July 2008
      • Athens will be available via a subscription model post July 2008
      • The UK Access Management Federation will launch in November 2006, with early adopters joining in August 2006
      • The Federation is a combined venture between JISC and BECTA
      • All members of the successful pilot federation (SDSS) will be seamlessly moved to the UK Access Management Federation
      • A full support service will be made available to the JISC community to support the transition to the new service
    3. What is Federated Access Management?
      • Current Athens service is a centralised service:
        • Institution provides information about users to Athens (identity information).
        • Athens brokers both authentication and authorisation on the part of the institution with service providers.
      • Federated Access Management devolves authentication back to the institution:
        • Authentication achieved through normal institutional log-on.
        • Service Providers trust institutions to appropriately authenticate.
        • Service Providers and institutions exchange information about users to determine what they can access (attributes: staff, student, law).
        • Same system can be used for internal, external and collaborative access (e-learning partnerships with other institutions, e-portfolios).
    4. The Gateways ATHENS INSTITUTION UK ACCESS MANAGEMENT FEDERATION FEDERATED INSTITUTION ATHENS CENTRAL ATHENS PROTECTED RESOURCE FEDERATED RESOURCE IdP Gateway SP Gateway
    5. The JISC Roadmap
    6. Reviewing Readiness How many institutions will adopt federated access by July 2008? (FE figures: Scotland, Wales and Northern Ireland only)
    7. Federated Access: Developing a Business Case Writing the Business Case
    8. JISC InfoNet Toolkits
    9. JISC InfoNet: Example Business Case Example of Electronic and Document Management System Business Case Development
    10. NMI-EDIT Enterprise Directory Implementation Roadmap
    11. Alpha University Business Case
    12. NMI Enterprise Authentication Roadmap
    13. Elements of a Business Case
      • Strategic Fit: making the strategic case.
        • Inputs and background, institutional strategy drivers (information strategy), other strategic drivers (external), timing implications, critical success factors.
      • Options Appraisal: the economic case.
        • Including costs and benefits analysis for each option.
      • Commercial aspects: the financial case (1).
        • Looks specifically at outsourcing and procurement issues.
      • Affordability: the financial case (2).
        • Funds available for project (implementation) and ongoing running.
      • Achievability: the project management case.
        • Can this be achieved within the organisation’s current capability and capacity?
    14. Federated Access: Developing a Business Case The Strategic Case
    15. The Strategic Case: Questions to Ask
      • Are there institutional drivers for:
      • The implementation of an enterprise directory / identity management solution?
        • Need to manage ‘non-standard’ users more efficiently, need to manage all users more efficiently!
      • Single (simplified) sign-on / devolved authentication?
        • System for both internal and external resources.
      • Collaborative access to resources within other institutions?
        • HE / FE collaboration; franchises in other countries.
      • Research collaboration? Private sector collaboration?
        • ‘Virtual Organisation’ support; third-stream funding opportunities.
    16. Strategic Case: Example – Kings College London
      • VISION STATEMENT: “Using a single password, postgraduate students can access not only King’s own electronic resources but also those of other universities and institutions by co-operative agreements.
      • VISION STATEMENT: “Provide services which reduce the burden of administration and information management.”
      • VISION STATEMENT: “Provide services which facilitate scholarly communication, collaboration and research
      • Federated access management allows not only single sign-on internally using an institutional password, but also allows users to access resources (such as VLEs) at other institutions using that same password (i.e. no need to register elsewhere).
      • Devolved authentication means that institution do not have to administer Athens accounts and single sign-on reduces the need for libraries to manage people as well as resources.
      • Federated access management supports the adoption of ‘virtual organisations and key research tools (such as open access repositories) have been ‘federated’.
    17. Federated Access: Developing a Business Case The Options Appraisal
    18. Institutional Options
      • BECOME A FULL MEMBER OF THE FEDERATION USING COMMUNITY SUPPORTED TOOLS
        • COSTS: Institutional effort to implement software, join federation and enhance institutional directories
        • BENEFITS: Full institutional control, skilled staff and access management solution for internal, external and collaborative resources
      • BECOME A FULL MEMBER OF THE FEDERATION USING TOOLS WITH PAID-FOR SUPPORT
        • COSTS: Cost of support from supplier and institutional effort in liaison with supplier and Federation
        • BENEFITS: Full support in implementation and access management solution for internal, external and collaborative resources
      • SUBSCRIBE TO AN ‘OUTSOURCED IDENTITY PROVIDER’ TO WORK THROUGH THE FEDERATION ON YOUR BEHALF (SUCH AS USE OF CLASSIC ATHENS WITH THE GATEWAYS)
        • COSTS: Subscription costs to external supplier (from July 2008) and internal administration role
        • BENEFITS: Minimum institutional effort to achieve access to external resources only
    19. JISC Options
      • Options appraisal for Services taken at the point where technology, capability and requirements of the community had been fully established through JISC Development programmes.
      • Move Athens to subscription model, no future development .
      • Continue funding Athens, no future development .
      • Continue funding Athens, continue funding development .
      • Transition to federated service, no continued Athens funding .
      • Transition to federated service, limited Athens support .
      • Transition to federated service, continued Athens support .
    20. Options Appraisal: JISC example Not recommended as a strategically sound direction for JISC. Recommendation
      • Fails to meet JISC Strategy on several fronts – ceasing to be innovative and world class status; failing to be economic and efficient in terms of services offered.
      • Negative reaction from community.
      • Access Management a core function of service provision within the strategy. Failure to support will impact on all areas of JISC.
      • Lack of innovation affects UK / JISC International standing.
      Risks
      • Release of JISC service funds.
      • Meets approach of the JISC Development – Service model in terms of moving robust services to subscription models.
      Benefits Eduserv have announced that they will charge a maximum of 50p per account per institution per annum for continued provision of the Athens service. At current service provision (3.5 million user accounts), the cost to UK Higher and Further Education Institutions will be £1,750,000. This represents an increase in cost of the community of £1,120,000 above the JISC managed solution currently supplied. Cost This option would amount to JISC taking the decision to cease financially supporting access management solutions for the community. It presumes that the Athens service is now a stable and self-sustaining model, and that an appropriate subscription model can be applied across HEIs, FEIs and Service Providers. Overview
    21. Federated Access: Developing a Business Case The Financial Case
    22. Federated Access: Developing a Business Case The Project Management Case
    23. Technical Capability / Management Buy-In
    24. Achievability: Skill Set (with thanks to Swish!) Setting up a CVS Repository; Populating (importing) new data;Check out/in. CVS Profiles, bindings and extensions SAML Format and content of XML files ; Namespace (xmlns) definition and use ; XML Schema definitions XML Log4j and log4cpp configuration options ; Analyzing stack traces and locating configuration errors. Java Configuration files: server.xml, workers2.properties, tomcat-users.xml Application WAR deployment ; Use of conf, webapps, WEB-INF and classes directories. Mod_jk use and Tomcat modification to use it ; “ant command” and editing build.properties and build.xml files.Build WAR and dist files. Tomcat Writing simple web pages ; Meaning of every HTTP code ; CSS authoring HTTP and HTML PKI ; Use of the openssl command and every option Trust stores and certificate stores Obtaining certificates, installing them, converting to/from different encoded methods. Building certificate chains. SSL Knowledge of the configuration files for the webserver and being able to correctly specify values for all directives. Virtual host configuration with SSL. Adding modules, building modules Configuring a content management system to host documentation about procedures and configuration file changes. Webserver (Apache, IIS) Security policy management for controlling port use . Where to install applications, configuration files. Syslogd operation, writing startup services, obtaining and inspecting packet dumps, writing scripts to monitor and control multiple log files in many windows and using filtering, sorting and pattern matching to reformat output. Operating System Minimum requirements Skill area
    25. In Summary
      • All institutions have options to consider regarding the adoption of federated access management.
        • Gateways ensure that it is your decision and not ‘chicken and egg’.
      • Institutions have a wide range of drivers that support the adoption of federated access management.
        • Collaborative eLearning, eResearch, ePortfolios, Open Access Repositories, Information / Knowledge Strategies.
      • It is important that this is planned and considered on an institutional basis.
        • What is the best fit for your institution?
        • What’s in your strategy already?
      • Lots of resources available to help in the planning process.
    26. References and Contacts
      • CONTACTS
      • Nicole Harris, JISC Programme Manager: [email_address] ; 07734 058308.
      • Mark Williams JISC Outreach FE: [email_address] 02078482501
      • Jane Charlton JISC Outreach Service providers [email_address] (0) 117 33 10672
      • JISC Access Management Outreach Team: [email_address]
      • SUPPORT
      • JISC Support: www.jisc.ac.uk/federation
      • UK Access Management Federation: www.ukfederation.org.uk
      • REFERENCES
      • JISC InfoNet: www.jiscinfonet.ac.uk
      • NMI-EDIT: www.nmi-edit.org
      • JISC Support: www.jisc.ac.uk /federation
      • UK Access Management Federation: www.ukfederation.org.uk
    27. References and Contacts
      • MATERIALS
      • Roadmap: http://www.jisc.ac.uk/upload/jisc/publications/fam-leaflet-large.jpg
      • Animation: http://www.jisc.ac.uk/whatwedo/themes/access_management/federation/animation.aspx

    + markwilliamsmarkwilliams, 3 years ago

    custom

    1147 views, 0 favs, 1 embeds more stats

    More info about this document

    © All Rights Reserved

    Go to text version

    • Total Views 1147
      • 1144 on SlideShare
      • 3 from embeds
    • Comments 0
    • Favorites 0
    • Downloads 0
    Most viewed embeds
    • 3 views on http://tanweerahmad.blogspot.com

    more

    All embeds
    • 3 views on http://tanweerahmad.blogspot.com

    less

    Flagged as inappropriate Flag as inappropriate
    Flag as inappropriate

    Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

    Cancel
    File a copyright complaint
    Having problems? Go to our helpdesk?

    Categories