You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 17 Next »

Participants

Proposers
NameOrganisation
SURFnet
GN4-3 project team
NameOrganisationRole
SURFnetP.I.
DFN-LRZScrum master

Mihály Héder

KIFUMember
RASHDev
Vangjel StavroRASHDev
GEANT AssociationMentor
Stakeholders
Name

Organisation

Role 
Laura PaglioneORCID ORCID contact person
Christos KanellopoulosGEANT AssociationeduTEAMS Service Owner

Activity Overview

Description

Many research collaborations as well as campus services need a solution to deal with guest identity, as in many cases not all users are members of the academic Identity Federations. As a result several federation operators as well as research collaborations operate IdPs or proxies to allow users to authenticate trough external identity providers like social ones. THis has lead to serious reinventing of the the wheel. The need for guest identities burdens the SPs with the integration costs and along the way may force guest users to use specific IdPs as implemented by the SP, which they may not want or may not be able to use, only because the SP decided only to implement a few of these solutions. In the GN4-2 project a first pilot was run as part of the eduTEAMS activity to investigate if a centralized service could be offered to resolve these issues. The aim of eduTEAMS service was to resolve these issues by providing a solution that is technically alike any other IdP in edUGAIN so the integration cost is reduced to zero,  and offers multiple IdPs so the guest users may choose what they want/can to use.

This pilot aims to bring ORCID into the IDhub solution, with formal support from ORCID. It also investigates the (technical) improvements needed to better scale the IDhub solution and will begin a dialog with the service activities to make the pilot move towards a full service offering under the GEANT umbrella.

Goals
The project is finished when ORCID can be used for authentication in eduGAIN in production.

Activity Details

Technical details
Technically this is an application of SATOSA where the south side is a SAML IdP exposed to GEANT or other SAML federations the north side is ORCID API, which is based on OAuth.
Business case
Business case: this service can be maintained at low cost and enhances the appeal of eduTEAMS and at the same time it creates a good relationship with ORCID.


Data protection & Privacy
We are going to accept users and their personal data from ORCID into the SAML side, therefore we have to have a data protection policy about how this data is handled.


Definition of Done (DoD)

Please describe here the set of criteria that the product must meet in order to be considered finished.

<Enter here>


Sustainability
This is a low-cost operation that is planned to be maintained as an eduTEAMS application.

Activity Results

Results
Please provide pointers to completed and intermediary results of this activity

Meetings

Date

Activity

Owner

Minutes

February 19, 2019

Kickoff meeting


 ORCID kick off.pdf
















Documents

No files shared here yet.

ORCID IdP as a Last Resource Business Case Analysis


  • No labels