23
7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444) http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 1/23 Bring Your Own Credential Providing Access to Campus Services with Social Identities like Google, Facebook and Twitter Chris Keith, Brown University Catherine Zabriskie, Brown University Dedra Chamberlin, Cirrus Identity John Krienke, InCommon/Internet2

Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

Embed Size (px)

Citation preview

Page 1: Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 1/23

Bring Your Own Credential

Providing Access to Campus Services

with Social Identities likeGoogle, Facebook and Twitter 

Chris Keith, Brown UniversityCatherine Zabriskie, Brown University

Dedra Chamberlin, Cirrus Identity

John Krienke, InCommon/Internet2

Page 2: Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 2/23

John Krienke

 

Director, Internet2

Chief Operating Officer,

InCommon

Page 3: Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 3/23

Going Social in 50 minutes:

1. 05' What, Why, Who

2. 10' How Now, Brown… Use Case: LMS

3. 10' How Now, Brown… Use Case: UFunds

4. 10' Social Gateways: Social to SAML

5. 05' Remaining issues & Getting involved

6. 10' Questions

Page 4: Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 4/23

Social Identity for Campus Resources

What is a social identity? An existing account on asocial or email platform.

Q3 2013

http://janrain.com/blog/social-login-trends-across-the-web-for-q3-2013/

● 87% of  consumers are

aware of social

login, and more

than half havetried it. (janrain)

Page 5: Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 5/23

Low assurance, 'arms-length' relationships:

● Parents

● Highschool Students

● Continuing Ed, MOOCs

●  Applicants

● Research partners

● Visiting professors, lecturers from non-federated organizations

●  Alumni, conference guests, non-university

others ...

What are driving campus use cases?

Page 6: Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 6/23

Catherine Zabriskie

 

Director, Academic Technology

Services

Brown University

Page 7: Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 7/23

Community of users

● Pre-college

●  Adult learners● Non-Brown undergraduates

● Professionals

● Instructors

● Faculty●  Artists

●  Anyone

Brown University:

Instructional Technology 

Page 8: Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 8/23

● Distance learning for the delivery of less

commonly taught languages

● Students from consortium schoolsparticipate in Brown classes

● Access to course

tools as a student

Brown University:

Language Consortium

Page 9: Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 9/23

● Summer@Brown Instructor Training and

community development

● Summer institute for researchers: Public 

Health Bio Statistics and Applied Data Analysis

Brown University:

Continuing Education

Page 10: Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 10/23

Users 

no long-term relationship to Brown.

  no physical presence at Brown.  may not be associated with a higher-Ed

institution.

Use case requires no need to institutionallyvalidate the individual’s identity.

  No credit or grades offered

Brown University:

Criteria for use of social identity 

Page 11: Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 11/23

Christopher Keith

 

Director of InformationTechnology

Brown University

Page 12: Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 12/23

● UFunds resulted from a College-wide effort

to consolidate disparate systems for funding

opportunities.

● The system has evolved to support genericapplication processes.

● Most applications require some type of 

endorsement or recommendation.● Our current approach is to email the non-

Brown recommenders with token-based URL

specific to the recommendation.

Brown University:

Dean of the College: UFunds

Page 13: Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 13/23

Demonstration Video

Brown University:

UFunds Proof-of-Concept

Page 14: Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 14/23

● As adoption has increased, we have been

asked to extend access to community

partners in various capacities.

● Currently, the only option is to create aBrown-affiliate account.

● We intend to modify the application to allow

social identities to be given access to serveon award committees.

Brown University:

Future Work for UFunds

Page 15: Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 15/23

● Should non-institutional identities be

managed on a per-application basis or in

aggregate by the institution?

● Which identity providers should be allowedand with what levels of assurance?

● How do we manage the proliferation of 

discovery services across the institution toensure consistent user experience?

Brown University:

Questions resulting from POC

Page 16: Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 16/23

Dedra Chamberlin

 

Co-Founder and CEO

Cirrus Identity

Page 17: Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 17/23

Gateway Services and Discovery

Page 18: Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 18/23

Page 19: Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 19/23

Choosing an Identity Provider 

Configuring the User Experience

Discovery Service Demo

Page 20: Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 20/23

● Join Social Working Group (since 2011)

○ spaces.internet2.edu/display/socialid

○ many campuses involved in sharing common

requirements, issues● Trial period for Cirrus social-to-SAML gateway

○ cirrusidentity.com

● InCommon services in development

○ Basic solution: 100% coverage for federated

identities

○ Advanced solutions: discovery, invitation, beginning

service validation

○ incommon.org/participants

● Thanks to innovative leadership at Brown University

Social to SAML: Next for You

Page 21: Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 21/23

Seeding Questions & Issues

● Assurance of Identity: Are all social identities createdequal?

● Attributes: What do you get? Are they standard?

● Gateway Issues: Is it a bottleneck? How does it

change?● Privacy: Who cares about privacy of Nouns (PII) and

Verbs (transactions) and Correlations?

● Usability: How does a user know which identity to use

when?

● Policy and Technology: Are you comfortable relying onexternal identities, something we in HE ask our 

corporate partners to do with our own identities?

Page 22: Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 22/23

Thank you

John Krienke

 [email protected]

Catherine [email protected]

Chris Keith

[email protected]

Dedra Chamberlin

[email protected]

Page 23: Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)

http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 23/23

Seeding Questions & Issues (Detail)

● Assurance of Identity: Are social identities created equal?○ Identity Proofing

○ Credential Management: issuance, storage, transit, revocation, reassignment○ Token strength: Passwords, multiple factors

● Attributes○ Standards & schema○ Translation

○ Persistence

○ Permanence● Gateway Issues

○ Licensing terms for use○ Capacity○ Resilience for for change

● Privacy○ Personal information: the nouns○ Personal transactions: the verbs

○ Correlation● Usability

○ Discovery (discovery.refeds.org)○ Invitation○ Account linking

○ Permission & Consent● Policy and Technology: Tables are turned: Control and Reliance on External Identities