130 likes | 228 Views
Single Sign-On, Federated Authentication and Beyond at NIH. Dr. Peter Alterman National Institutes of Health. About NIH. National Institutes of Health (NIH) Operating division of the U.S. Department of Health & Human Services (HHS) Primary Federal agency for conducting
E N D
Single Sign-On, Federated Authentication and Beyond at NIH Dr. Peter Alterman National Institutes of Health
About NIH • National Institutes of Health (NIH) • Operating division of the U.S. Department of Health & Human Services (HHS) • Primary Federal agency for conducting and supporting biomedical research
External Users • NIH provides financial support to researchers around the world. • NIH invests over $28 billion in medical research each year. $5 Billion for Researchers Inside NIH 83% goes to almost 50,000 competitive grants that support over 325,000 researchers outside NIH. $23 Billion for Researchers Outside NIH
Authentication Services at NIH • NIH iTrust • Multifunction single sign-on (SSO) and federated authentication service consisting of: • NIH Login – links internal users at NIH to internal and departmental (HHS) applications and electronic resources • NIH Federated Login – links external users to NIH and departmental (HHS) applications and resources
NIH Login • In production since 2003 • Over 35,000 NIH users, 238 applications, 450 URLs • Over 2.5 million transactions per day • Single Sign-On (SSO), including use of Personal Identity Verification (PIV) Cards • Authenticated web services
NIH Federated Login – In Production Since 2007 • Leverages existing credentials • Expands support for up to 55,000 internal and 10 million external users: • Grants and research activities (wikis, SharePoint, Grids) • Library services • Acquisition services • Enterprise/departmental applications • Cross-agency, government-wide collaborations
Federated Partners:Authentication at All Four Levels of Assurance Government Departments and Agencies Any PKI cross-certified with the Federal PKI Architecture, directly or indirectly (via Bridge CAs). InCommon Federation – identity and access management federation for the higher education and research communities; 25 major universities access NIH resources through InCommon. Open Identity Exchange (OpenID and Information Card Foundations) are working with industry leaders such as AOL, Equifax, Google, PayPal, VeriSign, and Yahoo
Federated Authentication at NIH: OIX General Services Administration Trust framework provider Private-sector identity providers Assessors& auditors Disputeresolvers U.S. Government websites User
Federated Authentication at NIH: InCommon General Services Administration Trust framework provider U.S. government websites Universities Assessors& auditors Disputeresolvers InCommon Federation Provider websites User
Federated Authentication at NIH: PKI Trust Framework Provider: Federal PKI Architecture US Government websites Federal Agencies Assessors& auditors Disputeresolvers CertiPath SAFE-BioPharma HEBCA User Cross-certified CAs And PKI Bridges
Key Points Alignswith FICAM’s IdM reference segment architecture Integrateswith HHS Operating Divisions and other departments and agencies Promotesboth interoperability and standards Meetsthe needs of researchers and clinicians Savestime and money Offersquick implementation
For Further Information Dr. Peter Alterman Peter.alterman@nih.gov Debbie Bucci Debbie.Bucci@nih.gov NIH Integration Services Center NIHISCSupport@mail.nih.gov NIH Center for Information Technology www.cit.nih.gov