The Edugate federation is comprised of Irish Higher Education Institutions and Research Organisations that have agreed upon a standard procedure for exchanging information about users and resources to enable access and use of those resources and services. The Edugate federation is a service operated by HEAnet in co-operation with HEAnet client institutions [1]
Join the current members [2] of the Edugate federation by completing the membership forms below;
Agreements should be posted to;
Edugate Operator
HEAnet Ltd.
5 Georges Dock
Irish Financial Services Centre
Dublin 1
Ireland
The Edugate test federation may be used to test or trial Edugate federated access without completing the membership agreements. Requests to join the test federation should be sent to noc@heanet.ie [3]. The current members of the test federation are listed here [4]
| Attachment | Size |
|---|---|
| EDUGATE PROVIDER MEMBER AGREEMENT.doc [5] | 131 KB |
| EDUGATE IDENTITY MEMBER AGREEMENT.doc [6] | 134.5 KB |
| EDUGATE ASSOCIATE MEMBER CONTRACT.doc [7] | 118.5 KB |
Overview Edugate is an implementation of Federated Access, it works by a service provider and an identity provider agreeing a basis of trust between them, this trust is partly managed by the HEAnet, the operator of Edugate. The identity provider authenticates their users credentials and then provide basic user details to service providers. The service provider then decides what level of access the visitor is entitled to based on the users details.
A good overview of federated access can be obtained by watching the 5 minute video provided by JISC Access Management [8]
The diagram and accompanying steps outlined below explain the flow of events that enable federated access.
*The data may vary from an opaque identifier known only to the IdP and SP to the full set of data as described in the Edugate Technical Specification.
**The user may be prompted for consent by the IdP before the data is sent to the SP, in which case the users consent will be recorded in a database.
NOTE: Steps 1-4 can be skipped by the SP in any of the following cases;
a) the SP web-site is used by only one institution, in which case the SP can redirect users back to the IdP.
b) the SP users some other means to determine where the user is from (IP address ranges, etc.)
c) the SP has dedicated 'login links' on it's website for the IdP's it works with (only works if the list is relatively static)
d) the SP is able to handle IdP initiated SSO, or unsolicited authentication responses, generated by IdP's with that functionality
| Attachment | Size |
|---|---|
| HowEdugateWorks.gif [11] | 23.56 KB |
| HowEdugateWorksLG.jpg [9] | 37.72 KB |
Edugate is a local instant of a globabl initiative to establish identity federations worldwide.
Source: www.refeds.org [40]
Edugate is for the Irish Higher Education Community, it can be used in multple situations as outlined below;
Enable users to use the campus directory credential to access Edugate enabled web sites beyond the campus boundary from anywhere, whilst protecting the campus directory from unnecessary searches and the user credentials from use on web sites beyond your control.
Eliminate the need for sharing the entire campus population of userid's in bulk form with other campus departments by offering an authentication service that is highly secure and only shares the necessary amount of users data for the minimum set of users.
Reduce multiple account stores by leveraging the time and effort your department has invested in the campus directory. Significant helpdesk cost savings can be realised by reducing the number of credentials that are issued for each user. [Gartner estimates that a typical user calls their help desk 16 times per year, with a quarter of those calls related to password reset issues, each of these calls last an average of 42 minutes]
Consolidate user accounts onto on a single campus directory, users will remember their credentials thus allowing for stronger credential controls (e.g two-factor authentication or strong password policies).
Improve the productivity of campus users by eliminating multiple account provisioning processes and leveraging the single-sign-on capability of Edugate. [ Meta Group estimates that the elapsed time for a user account provisioning request can take anywhere between 6 and 29 hours, resulting in a 36% loss of productivity and 26% loss of efficiency] Many of the cloud service providers offering Software as a Service (SaaS) support federated access that is compatible with Edugate. Avail of such services in a more secure manner by ensuring user credentials never leave the campus.
Campus IT managers and IT security officers are increasingly reluctant to synchronise user credentials or open up campus directory services to applications that are hosted in the cloud. Even locally hosted managed applications that require the campus credential to be processed by the application present a security risk. Edugate is built on the open SAML federated access standard that is used in the financial services, aerospace and governmant eID and provides Single-Sign-On without the risks. The Cloud Security Alliance is an alliance of well known organisations in the ICT sector, they recommend SAML as the preferred access mechanism (see their white paper at www.clouldsecurtiyalliance.org [41])
When establishing any online service that will be used by multiple institutions, Edugate will provide a means to authorise access to the service by user, role or institution without having to issue usernames/passwords or other credentials to the users of the service.
Most research projects are collaborations and when it comes to hosting collaborative tools or sharing documents and data, Edugate enables the hosting partner to seamlessly grant access to the project content.
Example: NDLR Repository
Example: HEAR and DARE
Your patrons are individuals, not IP Addresses!
Enable publishers to provide users with a consistent and personalised experience regardless of their location or the device they are using.
Improve the end-user experience by providing Single-Sign-On and reducing the frequency of prompts for campus credentials.
Connect your patrons to your subscribed resources, even where the user finds the resource without using the library.
Restrict access to your club or society web-site to valid campus users without needing the campus IT department to provide you with access to the entire campus user database.
For student unions, Edugate enables online elections that can authenticate all students currently enrolled without needing to expose campus credentials or personal information.
Example: UL Students Union
e-Government
Whether it's a central or local government service that needs to validate that a student is a current student, Edugate can open up the potential for numerous e-Government services for students (e.g. Grants and Tax Credits)
e-Commerce
When offering a student discount online, relying on a campus email address leaves the offer open to abuse since many institutions offer 'email for life'. Edugate will allow you to know if a customer is a current student and which institution the customer is affiliated to.
Provide your suppliers with a means to interact with all campus members. Whether its parking management, physical access management, catering or sports facilities, Edugate can provide a secure means to validate staff and student status. Access cards or tokens can be issued online in a self-service manner, removing the some, if not all, of the paperwork.
Example: Apcoa Parking Management
Edugate provides a single access mechanism that can enable access to online resources supporting alliances, research collaboration, consortia and shared services. Now users can use the credentials issued by their institution to access Edugate enabled web-sites and benefit from a personalised and persistent experience, with privacy features that put the user in control.
Links:
[1] http://www.heanet.ie/about/member_institutions
[2] http://www.edugate.ie/content/edugate-federation-members
[3] mailto:noc@heanet.ie
[4] http://www.edugate.ie/content/edugate-test-federation-members
[5] http://www.edugate.ie/sites/default/files/EDUGATE PROVIDER MEMBER.doc
[6] http://www.edugate.ie/sites/default/files/EDUGATE IDENTITY MEMBER.doc
[7] http://www.edugate.ie/sites/default/files/EDUGATE ASSOCIATE MEMBER CONTRACT_0.doc
[8] http://www.jisc.ac.uk/whatwedo/themes/access_management/federation/animation
[9] http://www.edugate.ie/sites/default/files/HowEdugateWorks_0.jpg
[10] http://wayf.edugate.ie
[11] http://www.edugate.ie/sites/default/files/HowEdugateWorks.gif
[12] https://refeds.terena.org/index.php/FederationACOnet-AAI
[13] https://refeds.terena.org/index.php/FederationAAF
[14] https://refeds.terena.org/index.php/FederationCAFe
[15] https://refeds.terena.org/index.php/FederationCAF
[16] https://refeds.terena.org/index.php/FederationCARSI
[17] https://refeds.terena.org/index.php/FederationAaiEduHr
[18] https://refeds.terena.org/index.php/FederationEduIDcz
[19] https://refeds.terena.org/index.php/FederationWAYF
[20] https://refeds.terena.org/index.php/FederationHaka
[21] https://refeds.terena.org/index.php/FederationRENATER
[22] https://refeds.terena.org/index.php/FederationDFN-AAI
[23] https://refeds.terena.org/index.php/FederationGRNET
[24] https://refeds.terena.org/index.php/FederationNIIF
[25] https://refeds.terena.org/index.php/FederationEdugate
[26] https://refeds.terena.org/index.php/FederationIDEM
[27] https://refeds.terena.org/index.php/FederationGakuNin
[28] https://refeds.terena.org/index.php/FederationLAIFE
[29] https://refeds.terena.org/index.php/FederationSurfnet
[30] https://refeds.terena.org/index.php/FederationFeide
[31] https://refeds.terena.org/index.php/FederationTuakiri
[32] https://refeds.terena.org/index.php/FederationRCTSaai
[33] https://refeds.terena.org/index.php/FederationArnesAAI
[34] https://refeds.terena.org/index.php/FederationSwamid
[35] https://refeds.terena.org/index.php/FederationSIR
[36] https://refeds.terena.org/index.php/FederationSWITCHaai
[37] https://refeds.terena.org/index.php/FederationULAKAAI
[38] https://refeds.terena.org/index.php/FederationUkfed
[39] https://refeds.terena.org/index.php/FederationIncommon
[40] http://refeds.org
[41] http://www.clouldsecurtiyalliance.org
[42] https://www.edugate.ie/content/edugate-federation-members
[43] https://refeds.terena.org/index.php/Federations<br
[44] http://www.edugain.org