SlideShare a Scribd company logo
1 of 1
Download to read offline
Authentication and Authorization exchange for University Federation
                                                                                                                                                                                                                                                   †
                                                                                                                                                                                                  M Nakagawa
                                                                                                        †                                            †                             ††                †      †
                                                                          K Kanenishi                             K Matsuura                                Y Miyoshi                     H Mitsuhara Y Yano
                                                                                                                                                                                     †                                             ††
                                                                                                                  The University of Tokushima                                                 Kochi University

1. Background                                                                                                       3. Shibboleth
                        Informatization of higher education                                                             Features                                                  Federations
                                                                                                                    •       Open source                                                    Name                                Country
                        Introduction of many web systems                                                                    •       Developed by Internet2                               InCommon                        United States
                                                                                                                            •       MACE Project                                         SWITCHaai                         Switzerland
            e-Learning utilization                           System cooperation                                     •       SAML implementation                                           DFN-AAI                              Germany
                                                                                                                            •       Distributed infrastructure                      UK Federation                       United Kingdom
        Increase convenience                                Complex management                                                                                                                    Other federations...
                                                                                                                            •       Building federation
                        Merit                                             Demerit
                                                                                                                                                                      Components
2. Problem
    User                                                Organization
•       Many passwords                                  •    Scattered identity
•       Each authentication                             •    Synchronization

                                                                                                                        ‣ Manage identity                             ‣ Protect resource                          ‣ Find organization
                                                                                                                            ‣       Authentication                       ‣   Query attribute                        ‣   Multiple IdPs
                                                                                                                            ‣       Release attribute                    ‣   Control access                         ‣   SAML feature

                        How to solve?                                                                                       Identity Provider                             Service Provider                         Discovery Service



4. Extension
Authorization exchange                                                                                                              Anonymous user
•       Rewrite attribute                       Why?                  •   Reduce operations                                         •   Decrease traceability
                                                                                                                                                                                                                  Unidentify

        •    Between SP and web system                                    •    Rule maintenance                                         •   For questionnaire                                                                           System A
                                                                                                                                                                                                            Different identities
•       System architecture                                                    •   SP side < IdP side                               •   One time account                         Image

        •    Mapping server                                               •    Authentication processing                                •   Each identity                                                   Access restriction
                                                                                                                                                                                                                                        System B
        •    Library called by web system                             •   User normalization                                            •   Activity restriction                                                  Prototype


    ‣   Pattern matching                                                                                                                                                                                      1

                                                                                                                                        DS                 Request/Response                                                          Process
        ‣    Regular expression                                                                                                                                                                        AuthnRequest
                                                                                                        2                                                                                                                            Abbrev
        ‣    String                                                                                                                                                   Redirect                                3
                                         System                                            5                            3
                                                                                                                                4
    ‣   XML base                                                                                                                                                      Internal
                                                                                                                                                                                                         Assertion
                                            4   Attribute’                                                                                                                                              UUID or NO
                                                                                                            1
                                                                                                    6                                   AuthnRequest                                       SP
        Mapped result        3                                                SP side                                                                             IdP side                        ‣   UUID is user identifier
                                                                                                                                                                                          side
                                                 Library
                             2                                                Web server                                                                          Attribute
                                                                                                                                                                                                  ‣   Lock inactivates account
                                                                                            Session                                             10       SSO
                         Attribute                                                          Initiator                                                             Authority
                                            1    Attribute                                                                      8

                                                                                                             11
                                                                                                                                                                  9
                                                                                                                                                                                              4
                                                                                                                                                                                                        Web                    2

                                                                                            Asserion
                                                                                                                                            7         Authn                                Lock       Interface            UUID
                                                                                           Consumer                                 Credential       Handler
                                                                                                            Assertion
                                                                                            Service         Attribute                                    Tomcat                                           Account                   Anonymous
            Mapping server           Service Provider
                                                                                                                                                                                                          Manager                      IdP




5. Future work
Formulation                                                    Development                                                           Practical use                                        ‣   New federation in Japan
•   Federation policy                                         •   Anonymous user                                                    •   ek4 federation                                        ‣   8 universities
•   Extensionʼs specification                                      •   Reference implementation                                      •   Share educational materials                       ‣   e-Learning, HRD, etc...

More Related Content

Viewers also liked

Dive into Fluentd plugin v0.12
Dive into Fluentd plugin v0.12Dive into Fluentd plugin v0.12
Dive into Fluentd plugin v0.12N Masahiro
 
Fluentd v0.14 Overview
Fluentd v0.14 OverviewFluentd v0.14 Overview
Fluentd v0.14 OverviewN Masahiro
 
Technologies for Data Analytics Platform
Technologies for Data Analytics PlatformTechnologies for Data Analytics Platform
Technologies for Data Analytics PlatformN Masahiro
 
Presto changes
Presto changesPresto changes
Presto changesN Masahiro
 
Fluentd and Kafka
Fluentd and KafkaFluentd and Kafka
Fluentd and KafkaN Masahiro
 
Docker and Fluentd
Docker and FluentdDocker and Fluentd
Docker and FluentdN Masahiro
 

Viewers also liked (7)

Dive into Fluentd plugin v0.12
Dive into Fluentd plugin v0.12Dive into Fluentd plugin v0.12
Dive into Fluentd plugin v0.12
 
Fluentd v0.14 Overview
Fluentd v0.14 OverviewFluentd v0.14 Overview
Fluentd v0.14 Overview
 
Technologies for Data Analytics Platform
Technologies for Data Analytics PlatformTechnologies for Data Analytics Platform
Technologies for Data Analytics Platform
 
The basics of fluentd
The basics of fluentdThe basics of fluentd
The basics of fluentd
 
Presto changes
Presto changesPresto changes
Presto changes
 
Fluentd and Kafka
Fluentd and KafkaFluentd and Kafka
Fluentd and Kafka
 
Docker and Fluentd
Docker and FluentdDocker and Fluentd
Docker and Fluentd
 

Similar to ICCE2009 Poster

Socializing Your Brand in the B2B Marketplace - Tim Husband - Cisco Canada
Socializing Your Brand in the B2B Marketplace - Tim Husband - Cisco CanadaSocializing Your Brand in the B2B Marketplace - Tim Husband - Cisco Canada
Socializing Your Brand in the B2B Marketplace - Tim Husband - Cisco CanadaTim Husband
 
Test Centre case studies - Brendan Kearns (Eircom)
Test Centre case studies - Brendan Kearns (Eircom)Test Centre case studies - Brendan Kearns (Eircom)
Test Centre case studies - Brendan Kearns (Eircom)NGN Test Centre
 
Socializing Your Brand in the B2B Marketplace
Socializing Your Brand in the B2B MarketplaceSocializing Your Brand in the B2B Marketplace
Socializing Your Brand in the B2B MarketplaceCisco Canada
 
An Overview of Dow Jones' Use of Semantic Technologies
An Overview of Dow Jones' Use of Semantic TechnologiesAn Overview of Dow Jones' Use of Semantic Technologies
An Overview of Dow Jones' Use of Semantic TechnologiesChristine Connors
 
BDI 9/16/09 B2B Social Communications Case Studies Conference - Deloitte
BDI 9/16/09 B2B Social Communications Case Studies Conference - DeloitteBDI 9/16/09 B2B Social Communications Case Studies Conference - Deloitte
BDI 9/16/09 B2B Social Communications Case Studies Conference - DeloitteBusiness Development Institute
 
Ea Landscape Capabilities Summary Slides 2009 Share
Ea Landscape Capabilities Summary Slides 2009 ShareEa Landscape Capabilities Summary Slides 2009 Share
Ea Landscape Capabilities Summary Slides 2009 Shareskipboe910
 
Stakeholder Engagement & Co-Creation: Reducing Project Risk
Stakeholder Engagement & Co-Creation: Reducing Project RiskStakeholder Engagement & Co-Creation: Reducing Project Risk
Stakeholder Engagement & Co-Creation: Reducing Project RiskJenny Ambrozek
 
493144 infosys slides_v5
493144 infosys slides_v5493144 infosys slides_v5
493144 infosys slides_v5Accenture
 
CIO Leadership on Web 2.0 and Social Media
CIO Leadership on Web 2.0 and Social MediaCIO Leadership on Web 2.0 and Social Media
CIO Leadership on Web 2.0 and Social MediaAnne Pauker Kreitzberg
 

Similar to ICCE2009 Poster (11)

Socializing Your Brand in the B2B Marketplace - Tim Husband - Cisco Canada
Socializing Your Brand in the B2B Marketplace - Tim Husband - Cisco CanadaSocializing Your Brand in the B2B Marketplace - Tim Husband - Cisco Canada
Socializing Your Brand in the B2B Marketplace - Tim Husband - Cisco Canada
 
Test Centre case studies - Brendan Kearns (Eircom)
Test Centre case studies - Brendan Kearns (Eircom)Test Centre case studies - Brendan Kearns (Eircom)
Test Centre case studies - Brendan Kearns (Eircom)
 
Socializing Your Brand in the B2B Marketplace
Socializing Your Brand in the B2B MarketplaceSocializing Your Brand in the B2B Marketplace
Socializing Your Brand in the B2B Marketplace
 
An Overview of Dow Jones' Use of Semantic Technologies
An Overview of Dow Jones' Use of Semantic TechnologiesAn Overview of Dow Jones' Use of Semantic Technologies
An Overview of Dow Jones' Use of Semantic Technologies
 
N2Y4 Cisco Keynote
N2Y4 Cisco KeynoteN2Y4 Cisco Keynote
N2Y4 Cisco Keynote
 
BDI 9/16/09 B2B Social Communications Case Studies Conference - Deloitte
BDI 9/16/09 B2B Social Communications Case Studies Conference - DeloitteBDI 9/16/09 B2B Social Communications Case Studies Conference - Deloitte
BDI 9/16/09 B2B Social Communications Case Studies Conference - Deloitte
 
Coveo
CoveoCoveo
Coveo
 
Ea Landscape Capabilities Summary Slides 2009 Share
Ea Landscape Capabilities Summary Slides 2009 ShareEa Landscape Capabilities Summary Slides 2009 Share
Ea Landscape Capabilities Summary Slides 2009 Share
 
Stakeholder Engagement & Co-Creation: Reducing Project Risk
Stakeholder Engagement & Co-Creation: Reducing Project RiskStakeholder Engagement & Co-Creation: Reducing Project Risk
Stakeholder Engagement & Co-Creation: Reducing Project Risk
 
493144 infosys slides_v5
493144 infosys slides_v5493144 infosys slides_v5
493144 infosys slides_v5
 
CIO Leadership on Web 2.0 and Social Media
CIO Leadership on Web 2.0 and Social MediaCIO Leadership on Web 2.0 and Social Media
CIO Leadership on Web 2.0 and Social Media
 

More from N Masahiro

Fluentd Project Intro at Kubecon 2019 EU
Fluentd Project Intro at Kubecon 2019 EUFluentd Project Intro at Kubecon 2019 EU
Fluentd Project Intro at Kubecon 2019 EUN Masahiro
 
Fluentd v1 and future at techtalk
Fluentd v1 and future at techtalkFluentd v1 and future at techtalk
Fluentd v1 and future at techtalkN Masahiro
 
Fluentd and Distributed Logging at Kubecon
Fluentd and Distributed Logging at KubeconFluentd and Distributed Logging at Kubecon
Fluentd and Distributed Logging at KubeconN Masahiro
 
Fluentd v1.0 in a nutshell
Fluentd v1.0 in a nutshellFluentd v1.0 in a nutshell
Fluentd v1.0 in a nutshellN Masahiro
 
Fluentd v1.0 in a nutshell
Fluentd v1.0 in a nutshellFluentd v1.0 in a nutshell
Fluentd v1.0 in a nutshellN Masahiro
 
Fluentd v0.12 master guide
Fluentd v0.12 master guideFluentd v0.12 master guide
Fluentd v0.12 master guideN Masahiro
 
Fluentd and Embulk Game Server 4
Fluentd and Embulk Game Server 4Fluentd and Embulk Game Server 4
Fluentd and Embulk Game Server 4N Masahiro
 
Treasure Data and AWS - Developers.io 2015
Treasure Data and AWS - Developers.io 2015Treasure Data and AWS - Developers.io 2015
Treasure Data and AWS - Developers.io 2015N Masahiro
 
Fluentd Unified Logging Layer At Fossasia
Fluentd Unified Logging Layer At FossasiaFluentd Unified Logging Layer At Fossasia
Fluentd Unified Logging Layer At FossasiaN Masahiro
 
Treasure Data and OSS
Treasure Data and OSSTreasure Data and OSS
Treasure Data and OSSN Masahiro
 
Fluentd - RubyKansai 65
Fluentd - RubyKansai 65Fluentd - RubyKansai 65
Fluentd - RubyKansai 65N Masahiro
 
Fluentd - road to v1 -
Fluentd - road to v1 -Fluentd - road to v1 -
Fluentd - road to v1 -N Masahiro
 
Fluentd: Unified Logging Layer at CWT2014
Fluentd: Unified Logging Layer at CWT2014Fluentd: Unified Logging Layer at CWT2014
Fluentd: Unified Logging Layer at CWT2014N Masahiro
 
SQL for Everything at CWT2014
SQL for Everything at CWT2014SQL for Everything at CWT2014
SQL for Everything at CWT2014N Masahiro
 
Can you say the same words even in oss
Can you say the same words even in ossCan you say the same words even in oss
Can you say the same words even in ossN Masahiro
 
I am learing the programming
I am learing the programmingI am learing the programming
I am learing the programmingN Masahiro
 
Fluentd meetup dive into fluent plugin (outdated)
Fluentd meetup dive into fluent plugin (outdated)Fluentd meetup dive into fluent plugin (outdated)
Fluentd meetup dive into fluent plugin (outdated)N Masahiro
 
D vs OWKN Language at LLnagoya
D vs OWKN Language at LLnagoyaD vs OWKN Language at LLnagoya
D vs OWKN Language at LLnagoyaN Masahiro
 
Final presentation at pfintern
Final presentation at pfinternFinal presentation at pfintern
Final presentation at pfinternN Masahiro
 

More from N Masahiro (20)

Fluentd Project Intro at Kubecon 2019 EU
Fluentd Project Intro at Kubecon 2019 EUFluentd Project Intro at Kubecon 2019 EU
Fluentd Project Intro at Kubecon 2019 EU
 
Fluentd v1 and future at techtalk
Fluentd v1 and future at techtalkFluentd v1 and future at techtalk
Fluentd v1 and future at techtalk
 
Fluentd and Distributed Logging at Kubecon
Fluentd and Distributed Logging at KubeconFluentd and Distributed Logging at Kubecon
Fluentd and Distributed Logging at Kubecon
 
Fluentd v1.0 in a nutshell
Fluentd v1.0 in a nutshellFluentd v1.0 in a nutshell
Fluentd v1.0 in a nutshell
 
Fluentd v1.0 in a nutshell
Fluentd v1.0 in a nutshellFluentd v1.0 in a nutshell
Fluentd v1.0 in a nutshell
 
Fluentd v0.12 master guide
Fluentd v0.12 master guideFluentd v0.12 master guide
Fluentd v0.12 master guide
 
Fluentd and Embulk Game Server 4
Fluentd and Embulk Game Server 4Fluentd and Embulk Game Server 4
Fluentd and Embulk Game Server 4
 
Treasure Data and AWS - Developers.io 2015
Treasure Data and AWS - Developers.io 2015Treasure Data and AWS - Developers.io 2015
Treasure Data and AWS - Developers.io 2015
 
Fluentd Unified Logging Layer At Fossasia
Fluentd Unified Logging Layer At FossasiaFluentd Unified Logging Layer At Fossasia
Fluentd Unified Logging Layer At Fossasia
 
Treasure Data and OSS
Treasure Data and OSSTreasure Data and OSS
Treasure Data and OSS
 
Fluentd - RubyKansai 65
Fluentd - RubyKansai 65Fluentd - RubyKansai 65
Fluentd - RubyKansai 65
 
Fluentd - road to v1 -
Fluentd - road to v1 -Fluentd - road to v1 -
Fluentd - road to v1 -
 
Fluentd: Unified Logging Layer at CWT2014
Fluentd: Unified Logging Layer at CWT2014Fluentd: Unified Logging Layer at CWT2014
Fluentd: Unified Logging Layer at CWT2014
 
SQL for Everything at CWT2014
SQL for Everything at CWT2014SQL for Everything at CWT2014
SQL for Everything at CWT2014
 
Can you say the same words even in oss
Can you say the same words even in ossCan you say the same words even in oss
Can you say the same words even in oss
 
I am learing the programming
I am learing the programmingI am learing the programming
I am learing the programming
 
Fluentd meetup dive into fluent plugin (outdated)
Fluentd meetup dive into fluent plugin (outdated)Fluentd meetup dive into fluent plugin (outdated)
Fluentd meetup dive into fluent plugin (outdated)
 
D vs OWKN Language at LLnagoya
D vs OWKN Language at LLnagoyaD vs OWKN Language at LLnagoya
D vs OWKN Language at LLnagoya
 
Goodbye Doost
Goodbye DoostGoodbye Doost
Goodbye Doost
 
Final presentation at pfintern
Final presentation at pfinternFinal presentation at pfintern
Final presentation at pfintern
 

Recently uploaded

Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...DianaGray10
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Scriptwesley chun
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024The Digital Insurer
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businesspanagenda
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdflior mazor
 
Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024The Digital Insurer
 
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...Zilliz
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyKhushali Kathiriya
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoffsammart93
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...apidays
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native ApplicationsWSO2
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsNanddeep Nachan
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc
 
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Jeffrey Haguewood
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWERMadyBayot
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024The Digital Insurer
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodJuan lago vázquez
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MIND CTI
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...apidays
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesrafiqahmad00786416
 

Recently uploaded (20)

Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024
 
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectors
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challenges
 

ICCE2009 Poster

  • 1. Authentication and Authorization exchange for University Federation † M Nakagawa † † †† † † K Kanenishi K Matsuura Y Miyoshi H Mitsuhara Y Yano † †† The University of Tokushima Kochi University 1. Background 3. Shibboleth Informatization of higher education Features Federations • Open source Name Country Introduction of many web systems • Developed by Internet2 InCommon United States • MACE Project SWITCHaai Switzerland e-Learning utilization System cooperation • SAML implementation DFN-AAI Germany • Distributed infrastructure UK Federation United Kingdom Increase convenience Complex management Other federations... • Building federation Merit Demerit Components 2. Problem User Organization • Many passwords • Scattered identity • Each authentication • Synchronization ‣ Manage identity ‣ Protect resource ‣ Find organization ‣ Authentication ‣ Query attribute ‣ Multiple IdPs ‣ Release attribute ‣ Control access ‣ SAML feature How to solve? Identity Provider Service Provider Discovery Service 4. Extension Authorization exchange Anonymous user • Rewrite attribute Why? • Reduce operations • Decrease traceability Unidentify • Between SP and web system • Rule maintenance • For questionnaire System A Different identities • System architecture • SP side < IdP side • One time account Image • Mapping server • Authentication processing • Each identity Access restriction System B • Library called by web system • User normalization • Activity restriction Prototype ‣ Pattern matching 1 DS Request/Response Process ‣ Regular expression AuthnRequest 2 Abbrev ‣ String Redirect 3 System 5 3 4 ‣ XML base Internal Assertion 4 Attribute’ UUID or NO 1 6 AuthnRequest SP Mapped result 3 SP side IdP side ‣ UUID is user identifier side Library 2 Web server Attribute ‣ Lock inactivates account Session 10 SSO Attribute Initiator Authority 1 Attribute 8 11 9 4 Web 2 Asserion 7 Authn Lock Interface UUID Consumer Credential Handler Assertion Service Attribute Tomcat Account Anonymous Mapping server Service Provider Manager IdP 5. Future work Formulation Development Practical use ‣ New federation in Japan • Federation policy • Anonymous user • ek4 federation ‣ 8 universities • Extensionʼs specification • Reference implementation • Share educational materials ‣ e-Learning, HRD, etc...