Roaming Network Access Using Shibboleth
نویسندگان
چکیده
There are activities aiming at abling users to dock to a wireless or wired network while visiting organisations outside the premises of their usual connection to the network. These activities, known as roaming access to network, are usually based on well-known technologies, such as RADIUS, IEEE 802.1X, VPN or HTTP redirection. On the other hand, there are applications, usually on the web, that are supposed to be accessed across organisational boundaries. The required infrastructure, known as identity federation, takes care of user authentication and authorisation in the participating organisations. Federating software, based, for example, on XML and SOAP, is being developed in the Internet and academic communities. This research combines the two and implements roaming access to network on Shibboleth, a federating software developed in Internet2. As a result, a unified model was achieved for authentication and authorisation both for network and application access. The architecture makes rolebased authorisation easy and provides a single sign-on while preserving the user's privacy. A practical experiment is going on at the University of Helsinki.
منابع مشابه
An Authentication and Authorization Architecture for the Mobile Internet
The paper describes an authentication and authorization architecture for mobile Internet users. The architecture is based on the Shibboleth middleware that has been developed by the Middleware Architecture Committee for Education of the Internet2 Middleware Initiative. The initial goal of this middleware was access control to digital content available in the Internet. We propose to use this mid...
متن کاملDesign and Implementation of Web Forward Proxy with Shibboleth Authentication
We propose a web forward proxy server with authentication method using Shibboleth. With this proxy Single Sign-On would benefit a user and also authentication using Shibboleth protocol solves problems in basic access authentication and digest access authentication supported by existing web forward proxy servers. In order to realize it, the proxy needs to recognize attributes of shibboleth proto...
متن کاملUser and Machine Authentication and Authorization Infrastructure for Distributed Wireless Sensor Network Testbeds
The intention of an authentication and authorization infrastructure (AAI) is to simplify and unify access to different web resources. With a single login, a user can access web applications at multiple organizations. The Shibboleth authentication and authorization infrastructure is a standards-based, open source software package for web single sign-on (SSO) across or within organizational bound...
متن کاملThe GLASS Project: Supporting Secure Shibboleth-based Single Sign-On to Campus Resources
Higher and Further education institutions in the UK are in the process of migrating their IT infrastructures to exploit Shibboleth technologies for federated access management. Ease of use and secure access are paramount to the successful uptake of these technologies, both from the end user and system administrator perspective. The JISC-funded GLASS project is a one-year project investigating t...
متن کاملAnApproach for Shibboleth and Grid Integration
Grid environments involve complex scenarios where PKI-based authentication and authorization might have to be delegated across n-tier security domains. Shibboleth is an identity management system designed to exchange attributes across domains for the primary purpose of authorization and its architecture is highly dependent on PKI. Supported by a Registry Service, we propose a non-intrusive appr...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2004