2. Cyberinfra in the Netherlands
• All ICT activities for Higher Education and Research in the
Netherlands are brought under one umbrella
National Research & Commercial ICT Scientific Computing & Shared Professional and
Education Network Products & Services Storage Educational Services
Collaboration is Happening: Updates from the Field and Beyond - I2SMM12 - Arlington, VA 2
3. About SURFnet
• Development and exploitation of
- the Dutch National Network for Higher Education and Research
- innovative ICT platforms & services
• By and for the Dutch Higher Education and Research
community
- 160+ connected organizations, 1 million users
- Combines the demand of connected institutions
- 100% ownership SURF
- Not for profit, 85 employees
- Over 14,000 km dark fiber
Collaboration is Happening: Updates from the Field and Beyond - I2SMM12 - Arlington, VA 3
4. Changing Behaviors
Hierarchical Self Organizing
Secrecy Transparency
Loose Alliance Collaboration
Sluggish Urgency
Novelty Innovation
Tunnel Vision Didactic
Institution Individual
Single Discipline Source: Sir Ken Robison
Multi-Disciplinary
Collaboration is Happening: Updates from the Field and Beyond - I2SMM12 - Arlington, VA 4
5. Motive
• Cloud cloud cloud — data explosion
• Sharing sharing sharing — connectivity explosion
• Go go go — study + work + play + collaborate + organize
+ share + et cetera
• Collaboration is key to you and your team’s success!
Source: AMD
Collaboration is Happening: Updates from the Field and Beyond - I2SMM12 - Arlington, VA 5
6. New core business
• Modern universities are developing towards loose
conglomerates of (inter)discipline expertise
• Collaboration is therefore a core business
• Scientific collaboration involves groups of people in
multiple institutions, disciplines and countries
• Collaboration is about using shared services and
resources
• Virtual Organization = People + Groups + Resources +
Multi-Discipline + Services + Policies + Funding + ...
*a.k.a. Virtual Collaboration
Collaboration is Happening: Updates from the Field and Beyond - I2SMM12 - Arlington, VA 6
7. Collaborations and Partnerships
• Virtual Research Team
- Focused on doing research Virtual Laboratory
- Small scale Virtual Project
- Temporary and elastic Virtual Colla-
boration
- Little ICT awareness
- Users
Virtual Breeding Environment
• “Virtual” Infrastructure Provider
- Focussed on providing infrastructure for specific discipline
- Well-organized with grands and budgets
- Longer term
- Better ICT awareness
- Not virtual (ESFRI projects, CLARIN, Lifewatch, LOFAR, NBIC)
Collaboration is Happening: Updates from the Field and Beyond - I2SMM12 - Arlington, VA 7
8. Multi-Disciplinary Collaboration
ƒ
Enabled by
Collaboration is Happening: Updates from the Field and Beyond - I2SMM12 - Arlington, VA 8
9. OpenConext
• Provides the glue and lubrication middleware to make
campus, cloud based services and resources usable
for collaboration for both inter campus and virtual
collaboration scenarios
• OpenConext offers the Identity and Group
Infrastructure
• Offer the platform software for large, virtual
collaboration-type collaboration to run-you-own
• OpenConext allows you to create your own
collaboration environment that organizes your
(online) applications, services and resources
Collaboration is Happening: Updates from the Field and Beyond - I2SMM12 - Arlington, VA 9
10. Core Components
• Federated Identity Management — SAML
• Groups Management — Grouper
• Social Network 'Portal' technology — OpenSocial
• Collaboration Services and Resources
- Document Sharing
Virtual Organization
- Video Collaboration
- Learning Systems
- Data Storage
- Data Mining
- Workspaces 9000
CALORIES
- Workflows
- Et cetera 100%
SATISFACTION
Collaboration is Happening: Updates from the Field and Beyond - I2SMM12 - Arlington, VA 10
12. Simplified view
SAML2 ADFS TBD Identity Provider
SAML2 Federation
Web Portal Grouper Group Management
Gadget
OpenConext TBD Attribute Management
Engine
OpenSocial XACML Policy Management
Container OpenSocial
Rest
JANUS Service Registry
OpenSocial Rest SAML2 SP XACML SAML2 Metadata
OAuth
Online Service
* Developed by SURFnet
Collaboration is Happening: Updates from the Field and Beyond - I2SMM12 - Arlington, VA 12
13. Getting Organized
Infrastructure
Infrastructure and
Development of OpenConext
Development of OpenConext and exploitation
exploitation of SURFconext federated
of SURFconext federated identity and
identity and groups management
groups management middleware
middleware
Vendor Adoption
Adoption
Management Pilots to support the adoption of new
Pilots to support the adoption of new services
Online/cloud/collaboration services
Online/cloud/collaboration services supply services provided through
provided through SURFconext
chain
supply chain SURFconext
Collaboration is Happening: Updates from the Field and Beyond - I2SMM12 - Arlington, VA 13
14. It is about getting the product...
Source: Alaine Delorme
Collaboration is Happening: Updates from the Field and Beyond - I2SMM12 - Arlington, VA 14
15. ...to market
Source: Reuters
Collaboration is Happening: Updates from the Field and Beyond - I2SMM12 - Arlington, VA 15
16. Vendor Management
• Creating an eco-system of online services
• With the same conditions for whole community
• Both serving the short and long tail in service demand
- Collaboration services (e.g. Google Apps, Office365)
- Audio & video (conferencing) services (e.g. Cisco WebEx)
- Infrastructure as a Service (e.g. Amazon AWS, greenqloud)
- Niche services for specific research and education domains
Collaboration is Happening: Updates from the Field and Beyond - I2SMM12 - Arlington, VA 16
17. Lifecycle
Wish Lists, Demand
Assessment, and Market &
Launch Event, Periodic evaluation Phase 1: Domain Studies
of shared values, policies, etc., Prioritization Results: Shortlist per domain
strengthen relationship
Results: New Opportunities
Service
Management
Phase 5: Phase 2:
Exploitation Selection
Formal connection to
infrastructure (network,
SURFconext, etc.) Contact with Supplier
Result: Service available for Feasibility Study: Strategic,
Users Technical, Organization, Legal
Result: Go — No Go
Phase 4: Phase 3:
Realization Fitting
License Agreements,
Policy Framework, Shared
Values and Mutual
Expectations set
Results: Signed Contracts
Collaboration is Happening: Updates from the Field and Beyond - I2SMM12 - Arlington, VA 17
19. Service Pipeline 2012 YTD
Collaboration is Happening: Updates from the Field and Beyond - I2SMM12 - Arlington, VA 19
20. Challenges
• How to deal with different types of Service Providers,
Users and Business Models (at least 12 variants)
- Policies and license agreements, technical requirements, etc.
- Opt-in vs Opt-Out, International and multi-domain aspects
- Provisioning and deprovisioning
Business Service Provider Users
Profit One Distribution Channel
3rd Party
Non-Profit One or more institutions with bi-lateral contracts
Profit Limited to constituency
Institution
Non-Profit Open to all
Profit Limited to constituency
Virtual Organization
Non-Profit Open to all
Stakeholder Matrix
Collaboration is Happening: Updates from the Field and Beyond - I2SMM12 - Arlington, VA 20
21. Open Exchanges
• Open Exchanges is a stepping stone for open
collaborations (e.g. technical or organizational) where
trust plays important part
• Anyone may become a member of an Open Exchange
• Links may be connected to the Open Exchange
• All members are allowed to exchange any kind of traffic
• There’s no policy inside the Open Exchange
preventing any destination
or kind of data member member
member member
• “Policy is open”
member Open Exchange member
Collaboration is Happening: Updates from the Field and Beyond - I2SMM12 - Arlington, VA 21
22. Instances
• An Open Internet Exchange (e.g. AMS-IX and NYIIX) plays
a supporting role by offering a shared and open
infrastructure where multiple networks can meet at a
central location in order to exchange IP traffic
• Other variants Open Lightpath Exchanges (e.g. MAN LAN
and Netherlight), and Open Mobile Exchange
• An Open Collaboration Exchange (OCX) is an exchange
point (a service) where (inter)national IdPs and SPs can
be interconnected at the lowest “cost”
• Next to the technical infrastructure the exchange may
require a policy and is also likely to include a governance
body...
Collaboration is Happening: Updates from the Field and Beyond - I2SMM12 - Arlington, VA 22
23. OCX — Rationale
• Facilitate international collaborations and virtual
organizations
• Make it easier for global interconnection of IdPs and SPs
• Harmonizing attribute exchange that will result in more
SPs that potentially become (technically) available to
more individual (sets of) IdPs
• Ideally, for any participating country, SPs and IdPs will
have to ‘openconext’ only once to become part of the
exchange
• Add-on to eduGAIN
Collaboration is Happening: Updates from the Field and Beyond - I2SMM12 - Arlington, VA 23
24. Current Situation
Identity
Provider
IdP SP
in the Netherlands
IdP IdP
SURFconext Access
Federation
Service in the Netherlands
Provider
SP
from the USA
SP
IdP SP
Collaboration is Happening: Updates from the Field and Beyond - I2SMM12 - Arlington, VA 24
25. Current Situation
SP IdP
eduGAIN SP SP
Policy &
Metadata UK ACFED
Exchange
IdP IdP
IdP SP IN
A SP SP
G
IdP du
e IdP
SURFconext
SP
SP
IdP SP
Collaboration is Happening: Updates from the Field and Beyond - I2SMM12 - Arlington, VA 24
26. OCX Concept
IdP SP SP SP
IdP IdP
SP
SP openconext.org
SP
IdP IdP
SP IdP
OCX
Policy & Metadata
& Technical
IdP Exchange
Collaboration is Happening: Updates from the Field and Beyond - I2SMM12 - Arlington, VA 25
27. OCX Concept
IdP SP SP SP
IdP IdP
SP
SP openconext.org
SP
IdP IdP
SP IdP
IdP
Collaboration is Happening: Updates from the Field and Beyond - I2SMM12 - Arlington, VA 26
28. Scenarios — Distributed Exchange
SP SP
SP IdP
no.openconext.org
uk.openconext.org
SP nl.openconext.org
SP
SP
edu.openconext.org
IdP jp.openconext.org
IdP
fr.openconext.org
exchange.openconext.org
Collaboration is Happening: Updates from the Field and Beyond - I2SMM12 - Arlington, VA 27
29. Scenarios — Multiple Exchanges (1)
IdP SP SP
IdP
SP
ca.openconext.org nl.openconext.org SP
uk.openconext.org
SP
edu.openconext.org
com.openconext.org
IdP jp.openconext.org
IdP SP
fr.openconext.org
Collaboration is Happening: Updates from the Field and Beyond - I2SMM12 - Arlington, VA 28
30. Scenarios — Multiple Exchanges (1)
IdP SP SP
IdP
SP
ca.openconext.org nl.openconext.org SP
uk.openconext.org
SP
edu.openconext.org
com.openconext.org
IdP jp.openconext.org
IdP SP
fr.openconext.org
OpenConextExchange API
Collaboration is Happening: Updates from the Field and Beyond - I2SMM12 - Arlington, VA 28
31. Scenarios — Multiple Exchanges (2)
bamboo.openconext.org clarin.openconext.org
uk.openconext.org
SP
edu.openconext.org
jp.openconext.org
IdP
SP SP SP
fr.openconext.org
OpenConextExchange API
Collaboration is Happening: Updates from the Field and Beyond - I2SMM12 - Arlington, VA 29
32. Challenges
• Again, it is all about trust and its balance with usability
• For individual SP-IdP cases the eduGAIN policies might require
strengthening with bi-laterals which might lead to policy creep
• Stepping stone for SPs, but how to get the international VOs
involved
• Hierarchy of trust and policies
• Next steps — we would like to invite NRENs to work out both
OCX scenarios
- Organizational
- Technical
- Legal / policy wise
Collaboration is Happening: Updates from the Field and Beyond - I2SMM12 - Arlington, VA 30