Abstract
CILogon provides a federated X.509 certification authority for secure access to cyberinfrastructure such as the Extreme Science and Engineering Discovery Environment. CILogon relies on federated authentication (Security Assertion Markup Language (OASIS, Burlington, MA (USA)) and OpenID) for determining user identities when issuing certificates. Federated authentication enables users to obtain certificates using existing identities (university, Google, etc.). Federated authentication also enables CILogon to serve a national-scale user community without requiring a large network of registration authorities performing manual user identification. CILogon supports multiple levels of assurance and custom interfaces for specific user communities. In this article, we introduce the CILogon service and describe experiences and lessons learned from the first 3years of operation.
Original language | English (US) |
---|---|
Pages (from-to) | 2225-2239 |
Number of pages | 15 |
Journal | Concurrency and Computation: Practice and Experience |
Volume | 26 |
Issue number | 13 |
DOIs | |
State | Published - Sep 10 2014 |
Keywords
- InCommon
- OAuth
- OpenID
- PKI
- SAML
- Shibboleth
- X.509
- XSEDE
- grid computing
- identity federation
ASJC Scopus subject areas
- Theoretical Computer Science
- Software
- Computer Science Applications
- Computer Networks and Communications
- Computational Theory and Mathematics