scieee AI-readable full text Open interactive document viewer

IAM4NFDI – JARDS Incubator

Politze, Marius; Nellesen, Marcel; Lummerzheim, Camilla

Abstract

The poster IAM4NFDI – JARDS Incubator was presented at the Base4NFDI User Conference 2024 (https://events.gwdg.de/event/658/) in the Poster Session.

Full text

Funded by DFG as part of NFDI. Grant Number: 521466146 What is an Attribute? Attributes are used to describe the user. They are meant to be used for the authorization decision. Different sets of attributes are available at different layers in the infrastructure. This is somewhat logical, since for example services that are connected to eduGAIN can not see those attributes that are managed in the Community AAI. More generally speaking, the set of attributes coming from “Home-IdPs” in eduGAIN is different to the one that is passed on by the Community AAIs. The set of attributes available from the Infrastructure Proxy will be very similar to those of the Community AAIs. We make use of standardized attribute sets, both for the attributes expected from the Home-IdPs at the Community AAIs, as well as for those that are sent from the Community AAIs to underlying services. IAM4NFDI JARDS Incubator – Towards a Sustainable Attribute Authority (AA) Implementation Marius Politze, Marcel Nellesen, Camilla Lummerzheim, Ilona Lang RWTH Aachen University This work is licensed under Creative Commons Attribution 4.0 International. 6 months Sprint phases: •One sprint lasts 4 weeks •Sprint demo at the end of each sprint •Implementation is organized independently by the teams Starting preparation for the next cycle Resubmit project Project successfully completed Project not completed successfully Call for Incubator Projects Submission deadline for the next cycle Evaluating and prioritizing the submitted projects Selecting and preparing projects for the next cycle Day -90 Day -30 Day 0 Proposal (2 Pages) Pitchtalk (5 min + Questions) 1. Definition of work packages … 2. Definition of interfaces ... 3. Setting up a test instance of a JARDS AA … Sprint demo (10 min) - current state - time plan 4. Implementing support for attribute queries with SAML … 5. Running first test against AA test instance … 6. Setting up and configuring the AA live Instance Final Presentation & Report Exploring the Incubator Life Cycle: JARDS Attribute Authority (AA) Outcome Re-Usable AAImplementation published (Re)Submit next project for AABased Authorization The more you know: What is an Attribute Authority? The AA is responsible for issuing and managing user attributes, which can include roles, permissions, and other relevant information about users. These attributes are often used to determine what resources a user can access within the federated environment. The AA can enforce policies related to attribute issuance, ensuring that only authorized entities can request certain attributes and that they comply with organizational policies regarding data privacy and security. By standardizing how attributes are defined and shared across different communities, the AA facilitates interoperability. Providing an AA as a stand-alone application allows more complex processes for the management and more fine granular attributes. In the case of the JARDS incubator the outcome of a science led resource distribution.