Title: NIH Identity Federation
1NIH Identity Federation
- Valerie Wampler, CIT/EMIB
- Debbie Bucci, CIT/DECA
2NIH Identity Federation Roadmap
- NIH Login Begin the journey
- NIH External Further the journey
- Define Federation Define the vision
- NIH Industry Technologies Realize the vision
- Next Steps Expand the vision
3NIH Login
- Promote eBusiness
- Single Sign On
- Secure
- Load balanced
- Product CA Site Minder
- Customers NIH Institutes web and applications
with authentication requirements
4NIH Login goals
- Network de-perimeterization
- Bridging organizational boundaries
- Service oriented architecture
- Bridging platform boundaries
5NIH Identity Federation Roadmap
- NIH Login Begin the journey
- NIH External Further the journey
- Define Federation Define the vision
- NIH Industry Technologies Realize the vision
- Next Steps Expand the vision
6NIH External
- Pre-federation Collaboration
- EA Domain Team
- Developed Business Process
- Defined data elements
- AD forest (security boundary)
- 63 projects
- Workflow approval process developed
- Self service registration
- NIST authorization level 1 and 2
- Identity validation done by project owners
- Password self service available to NIH External
7NIH Login, NIH External, AD, Commons
- Identity Silos
- Clogging system with redundant accounts
- Local account store is only source of truth
- Manages credentials for internal/external users
- Manages permissions for internal/external users
8Identity Silos
Your EMPLOYEES onyour NETWORK
9Identity Silos Affect NIH
IT/Helpdesk Productivity
Compliance Risks
End User Productivity
Security Threats
- User privacy
- End-end auditability
- Account setup delays
- Forgotten passwords
- Many logons
- External user account provisioning
- External user password resets
- Compromised passwords
- Excessive Permissions
- Dangling accounts
10NIH Identity Federation Roadmap
- NIH Login Begin the journey
- NIH External Further the journey
- Define Federation Define the vision
- NIH Industry Technologies Realize the vision
- Next Steps Expand the vision
11What is meant by Identity Federation?
- Standards, technologies and use cases that make
the negotiation and allows an identity or
privileges to be portable - Goal allow an individual to use a single name,
password or other identity to access multiple
applications or data sources securely and
seamlessly
12NIH Federation Principles
- Digital Identity
- Federated Identity
- Assertion/Claim
- Federated Trust
- Identity Provider
- Service Provider
- Relying Party
for more information NIHRFC00028 at
http//enterprisearchitecture.nih.gov/
13NIH Federation Solution
- Use existing technology
- Support open industry standards
- WS-
- XML
- SOAL
- SAML
- STS
- Claims Transformation
for more information NIHRFC00028 at
http//enterprisearchitecture.nih.gov/
14Assertion/Claims Transformation
- The idea of claims transformation is the most
important technical advance in distributed
computing for at least a decade. It is so
powerful that it wasnt even fully understood
until we began to build things with it.Â
Kim Cameron, Microsoft Chief Identity Architect
15Federation Flow Example
User
User approves release of token
7
Client
User select digital identity
4
Client tries to access a resource
1
Request Security Token sent to IP
5
3
Which IPs can satisfy RPs policy
RP provides identity requirements policy
2
6
IP returns security token
8
Assertion/Claim released to RP
Identity Provider(IP)
Relying Party(RP)/Service Provider (SP)
16NIH Identity Federation Roadmap
- NIH Login Begin the journey
- NIH External Further the journey
- Define Federation Define the vision
- NIH Industry Technologies Realize the vision
- Next Steps Expand the vision
17NIH Industry Technologies
- Use existing technologies
- NIH Login
- Active Directory, Active Directory Federation
Services - Define common terminology
- Investigate technology
- Employ open technology (where technically
possible) - Work with NIH projects to support Federated
Identity
18Realize the Vision
- inCommon
- LOA 1 available
- LOA 2 coming soon
- Cross-CIT technical working group
- Architectural design Microsoft, CA, CIT DCSS,
CIT DECA, OCITA - Define Use Cases
19Realize the Vision (continued)
- Domain Team
- NIHRFC
- Technical Testing
- External project owners
- inCommon participants
- CA, ADFS, AD/AM, Sharepoint
20NIH Identity Federation Roadmap
- NIH Login Begin the journey
- NIH External Further the journey
- Define Federation Define the vision
- AD NIH Login Realize the vision
- Next Steps Expand the vision
21Next steps for Federation
- Evaluate NIST level 3 and 4 access
- PIV Card
- 2 factor authentication
- PKI
- Develop model of Federation process
- Develop Web Site for contact
- Develop work flow for Federation participant
approval
22Next Steps for You
- Select Collaboration Project
- Contact NIH Federation Team
- nihfederationrequest_at_mail.nih.gov
- Test access
- Pilot
- Advertise new access to Collaborators
23For more information
- Send email to nihfederationrequest_at_mail.nih.gov
- On the Enterprise Architecture Website
http//enterprisearchitecture.nih.gov - NIHRFC