Upload
educause
View
214
Download
0
Embed Size (px)
Citation preview
7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)
http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 1/23
Bring Your Own Credential
Providing Access to Campus Services
with Social Identities likeGoogle, Facebook and Twitter
Chris Keith, Brown UniversityCatherine Zabriskie, Brown University
Dedra Chamberlin, Cirrus Identity
John Krienke, InCommon/Internet2
7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)
http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 2/23
John Krienke
Director, Internet2
Chief Operating Officer,
InCommon
7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)
http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 3/23
Going Social in 50 minutes:
1. 05' What, Why, Who
2. 10' How Now, Brown… Use Case: LMS
3. 10' How Now, Brown… Use Case: UFunds
4. 10' Social Gateways: Social to SAML
5. 05' Remaining issues & Getting involved
6. 10' Questions
7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)
http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 4/23
Social Identity for Campus Resources
What is a social identity? An existing account on asocial or email platform.
Q3 2013
http://janrain.com/blog/social-login-trends-across-the-web-for-q3-2013/
● 87% of consumers are
aware of social
login, and more
than half havetried it. (janrain)
7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)
http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 5/23
Low assurance, 'arms-length' relationships:
● Parents
● Highschool Students
● Continuing Ed, MOOCs
● Applicants
● Research partners
● Visiting professors, lecturers from non-federated organizations
● Alumni, conference guests, non-university
others ...
What are driving campus use cases?
7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)
http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 6/23
Catherine Zabriskie
Director, Academic Technology
Services
Brown University
7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)
http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 7/23
Community of users
● Pre-college
● Adult learners● Non-Brown undergraduates
● Professionals
● Instructors
● Faculty● Artists
● Anyone
Brown University:
Instructional Technology
7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)
http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 8/23
● Distance learning for the delivery of less
commonly taught languages
● Students from consortium schoolsparticipate in Brown classes
● Access to course
tools as a student
Brown University:
Language Consortium
7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)
http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 9/23
● Summer@Brown Instructor Training and
community development
● Summer institute for researchers: Public
Health Bio Statistics and Applied Data Analysis
Brown University:
Continuing Education
7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)
http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 10/23
Users
no long-term relationship to Brown.
no physical presence at Brown. may not be associated with a higher-Ed
institution.
Use case requires no need to institutionallyvalidate the individual’s identity.
No credit or grades offered
Brown University:
Criteria for use of social identity
7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)
http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 11/23
Christopher Keith
Director of InformationTechnology
Brown University
7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)
http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 12/23
● UFunds resulted from a College-wide effort
to consolidate disparate systems for funding
opportunities.
● The system has evolved to support genericapplication processes.
● Most applications require some type of
endorsement or recommendation.● Our current approach is to email the non-
Brown recommenders with token-based URL
specific to the recommendation.
Brown University:
Dean of the College: UFunds
7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)
http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 13/23
Demonstration Video
Brown University:
UFunds Proof-of-Concept
7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)
http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 14/23
● As adoption has increased, we have been
asked to extend access to community
partners in various capacities.
● Currently, the only option is to create aBrown-affiliate account.
● We intend to modify the application to allow
social identities to be given access to serveon award committees.
Brown University:
Future Work for UFunds
7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)
http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 15/23
● Should non-institutional identities be
managed on a per-application basis or in
aggregate by the institution?
● Which identity providers should be allowedand with what levels of assurance?
● How do we manage the proliferation of
discovery services across the institution toensure consistent user experience?
Brown University:
Questions resulting from POC
7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)
http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 16/23
Dedra Chamberlin
Co-Founder and CEO
Cirrus Identity
7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)
http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 17/23
Gateway Services and Discovery
7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)
http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 18/23
7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)
http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 19/23
Choosing an Identity Provider
Configuring the User Experience
Discovery Service Demo
7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)
http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 20/23
● Join Social Working Group (since 2011)
○ spaces.internet2.edu/display/socialid
○ many campuses involved in sharing common
requirements, issues● Trial period for Cirrus social-to-SAML gateway
○ cirrusidentity.com
● InCommon services in development
○ Basic solution: 100% coverage for federated
identities
○ Advanced solutions: discovery, invitation, beginning
service validation
○ incommon.org/participants
● Thanks to innovative leadership at Brown University
Social to SAML: Next for You
7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)
http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 21/23
Seeding Questions & Issues
● Assurance of Identity: Are all social identities createdequal?
● Attributes: What do you get? Are they standard?
● Gateway Issues: Is it a bottleneck? How does it
change?● Privacy: Who cares about privacy of Nouns (PII) and
Verbs (transactions) and Correlations?
● Usability: How does a user know which identity to use
when?
● Policy and Technology: Are you comfortable relying onexternal identities, something we in HE ask our
corporate partners to do with our own identities?
7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)
http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 22/23
Thank you
John Krienke
Catherine [email protected]
Chris Keith
Dedra Chamberlin
7/27/2019 Bring Your Own Credential: Providing Access to Campus Services with Social Identities (Google, Yahoo, Twitter) (177668444)
http://slidepdf.com/reader/full/bring-your-own-credential-providing-access-to-campus-services-with-social 23/23
Seeding Questions & Issues (Detail)
● Assurance of Identity: Are social identities created equal?○ Identity Proofing
○ Credential Management: issuance, storage, transit, revocation, reassignment○ Token strength: Passwords, multiple factors
● Attributes○ Standards & schema○ Translation
○ Persistence
○ Permanence● Gateway Issues
○ Licensing terms for use○ Capacity○ Resilience for for change
● Privacy○ Personal information: the nouns○ Personal transactions: the verbs
○ Correlation● Usability
○ Discovery (discovery.refeds.org)○ Invitation○ Account linking
○ Permission & Consent● Policy and Technology: Tables are turned: Control and Reliance on External Identities