Leave a comment

SWITCH edu-ID Now Speaks Italian

The user interface to create and manage a SWITCH edu-ID account was originally available in English. It was translated to French and German half a year ago.

We are happy to announce that the Italian translation of the user interface is ready and can be used as of today.

Together with the Italian user interface we have also translated and released the SWITCH edu-ID terms of use in French, German and Italian.

If you have comments or suggestions for translation enhancements please don’t hesitate to contact us.


Advanced Access Management with SWITCH edu-ID

The SWITCH aai identity federation is based on one important concept: The separation of identity management (IdM) and access management (AM). Identity providers are trusted sources of a set of well defined attributes. For each user trying to access a service, the service itself decides based on his/her attributes if access to the service is granted or denied.

shared-attributes-basic

The identity provider in its purest form only manages general user information like name, age, email address, membership status at a university etc. This information is general and not specific to services. The service specific part is the way how attribute information can be combined by a service to build complex access rules like: “This service accepts math students and staff members”.

What if a group of services needs to share additional information about a user that is not part of the standard attribute set? For this case SWITCH has developed the shared attribute service for the edu-ID.

shared-attributes-extension

The shared attribute service consists of a database where additional attributes can be stored for each SWITCH edu-ID user. The contents of this database are not managed by the SWITCH edu-ID Identity Provider. Some external entities can access to the shared attributes database via an API, and set or delete attribute values for selected edu-ID users. When a user accesses to a service provider the shared attribute for that user is added to the standard attributes and sent to the service.

What effectively happens with shared attributes is that one part of AM (the part that is common to a group of services) is extracted from the services and centralized

First application: National Licences

The first application to use shared attributes is the National Licenses service. In the context of the national licenses some publishers grant access to users who satisfy a complex access rule. The user has to be a Swiss citizen, has to accept specific terms, must have been active during the last year and must not be blocked due to service abuse.

shared-attributes-natlic

A specially developed national licenses service registration platform checks if a user meets all the requirements of a user. If the user does meet the requirements, the flag national-license-compliant is set in the shared attributes database for that user. Consequently, services participating in the national licenses program get the additional attribute and grant access to licensed publications.

If a user does not meet all requirements, the national-license-compliant flag is removed. The user gets an explanation on the registration service and some indications how he or she could re-gain access to the national licenses program.

Note: The shared attributes service has been developed by SWITCH to solve a specific problem and to gain experiences with the concept. It is possible that the service will be replaced in the future by a more general group management service.


Verify your Private Postal Address

The Swiss edu-ID is a user-centric identity. This means that the identity is managed by its owner who directly provides many pieces of identity information in the personal profile.

But can a user be trusted? Will users provide correct personal information for their Swiss edu-ID?

Although users rarely have a interest in providing wrong personal information about themselves, the answer to the above question is no. For this reason, Swiss edu-ID has implemented various processes to verify user information. All email addresses and mobile phone numbers are directly verified when a user enters them in the personal profile.

As of today, users also can have their private postal address verified.

Unverified addresses are marked by a grey verification icon with red question mark

Screen Shot 2016-09-01 at 13.37.30.png

Klicking the green arrow starts the verification process. A few days later, the user will receive a letter (yes – a real one on paper!) at the specified postal address with an activation code. After the user has entered the code in the Swiss edu-ID profile the address is verified. This is reflected with a golden verification icon in the profile

Screen Shot 2016-09-01 at 13.42.31.png

The first service relying on this new feature is the  National Licenses project of the Consortium of Swiss Academic Libraries. Their aim is to give private individuals access to scientific publications. The publishers of scientific publications require some sort of proof of a user, that he/she is living in Switzerland. By relying on the verifications done within the Swiss edu-ID the national licenses service does not have to implement its own verification processes.

Save


Final Report on Market Analysis of IdM Solutions

In SWITCHaai, identity management is entirely the responsibility of the organisations participating as identity providers in the federation. With its successor, the Swiss edu-ID, elements of identity management tasks will be performed by SWITCH. SWITCH has conducted a market analysis (RFI) with the aim to identify existing identity management products that fit the Swiss edu-ID requirements, to evaluate these products, and to make a recommendation on the next steps in the project.

Continue reading


Swiss edu-ID Detailed Architecture available now

The Swiss edu-ID Team is happy to announce the first revision of the Swiss edu-ID detailed architecture. It is a thorough description of the Swiss edu-ID federation, its participants and their roles, the information architecture, data models and identity management processes.

The architecture was developed based on the output of Swiss edu-ID working groups, the Swiss edu-ID high level architecture, and numerous presentations and follow-up discussions with university members during the past years. On this occasion we would like to express our gratitude for the great effort and support in our community!

The draft of the architecture document was reviewed by the Processes II Workgroup, subscribers of the Swiss edu-ID newsletter and external identity management experts. Of course, comments are still welcome at any time.

The document (direct PDF link) can be downloaded from the document section of the Swiss edu-ID website.