...
首页> 外文期刊>International Journal of Spatial Data Infrastructures Research >Shibboleth Access Management Federations as an Organisational Model for SDI
【24h】

Shibboleth Access Management Federations as an Organisational Model for SDI

机译:Shibboleth访问管理联合会作为SDI的组织模型

获取原文
           

摘要

Shibboleth is an open source implementation of the OASIS standard Security Assertion Markup Language (SAML). Shibboleth Access Management Federations (AMFs) are used daily around the globe by millions of users – mainly in the academic realm – in order to securely exchange the identity information necessary to make authorisation decisions concerning protected web resources. AMFs are typically comprised of a number of entities, eg, organisations working together to achieve a set of shared objectives while each member retains control over its own internal affairs. There are three main categories of entities: identity management is devolved to individual member organisations who act as Identity Providers, Service Providers are established by organisations wanting to make protected resources available, and finally, there is a small Coordinating Centre. Principally through the European Spatial Data Infrastructure Network (ESDIN) project and the OGC Web Service (OWS) Shibboleth Interoperability Experiment, it has been established that Shibboleth provides a production strength, standards based, open source, interoperable mainstream IT solution to the problem of how to implement AMFs around the OWS central to SDI’s. Furthermore, it has been demonstrated using a prototype federation of INSPIRE compliant services established under ESDIN that this can be done without modifications to either mainstream Shibboleth or OWS. However, non browser based clients require adaptation. Various options exist as to how the main actors within a European SDI/Federation may organise themselves in order to realise the objective of allowing authorised users from key organisations, eg, EU bodies concerned with environmental policy formation, seamless access to harmonised protected geospatial information through OWS. This paper proposes that a parallel security infrastructure is necessary to realise SDI where protected resources are involved and gives an account of work undertaken demonstrating how Shibboleth based AMF’s meet this need.
机译:Shibboleth是OASIS标准安全性断言标记语言(SAML)的开源实现。 Shibboleth访问管理联盟(AMF)每天在全球范围内被数以百万计的用户(主要是在学术领域)使用,以安全地交换必要的身份信息,以做出有关受保护Web资源的授权决定。 AMF通常由许多实体组成,例如,为了实现一组共享目标而共同努力的组织,而每个成员都保留对其内部事务的控制权。实体主要分为三类:身份管理下放到充当身份提供者的单个成员组织,服务提供者由希望提供受保护资源的组织建立,最后是一个小型的协调中心。主要通过欧洲空间数据基础结构网络(ESDIN)项目和OGC Web服务(OWS)Shibboleth互操作性实验,已经确定Shibboleth提供了一种生产实力,基于标准,开源,可互操作的主流IT解决方案,以解决该问题。围绕ODI中心的OWS实施AMF。此外,已经证明,使用在ESDIN下建立的符合INSPIRE的服务的原型联盟,可以在不修改主流Shibboleth或OWS的情况下完成此工作。但是,非基于浏览器的客户端需要调整。关于欧洲SDI /联邦内部的主要参与者如何组织自身,以实现允许来自关键组织(例如,与环境政策形成有关的欧盟机构)的授权用户,通过以下方式无缝访问统一的受保护地理空间信息的目标,存在各种选择: OWS。本文提出,要在涉及受保护资源的情况下实现SDI,必须有并行的安全基础结构,并说明已开展的工作,以证明基于Shibboleth的AMF如何满足这一需求。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号