[email protected] J. Access Control to Video Resources TF-VVC.

12
[email protected] J. Access Control to Video Resources TF-VVC

Transcript of [email protected] J. Access Control to Video Resources TF-VVC.

Page 1: Jmaria.fontanillo@rediris.es J. Access Control to Video Resources TF-VVC.

[email protected]

J. Access Control to Video Resources

TF-VVC

Page 2: Jmaria.fontanillo@rediris.es J. Access Control to Video Resources TF-VVC.

TF-VVC

The bad way

Page 3: Jmaria.fontanillo@rediris.es J. Access Control to Video Resources TF-VVC.

TF-VVC

The bad way

Page 4: Jmaria.fontanillo@rediris.es J. Access Control to Video Resources TF-VVC.

TF-VVC

Page 5: Jmaria.fontanillo@rediris.es J. Access Control to Video Resources TF-VVC.

TF-VVC

Page 6: Jmaria.fontanillo@rediris.es J. Access Control to Video Resources TF-VVC.

TF-VVC

Page 7: Jmaria.fontanillo@rediris.es J. Access Control to Video Resources TF-VVC.

TF-VVC

Page 8: Jmaria.fontanillo@rediris.es J. Access Control to Video Resources TF-VVC.

TF-VVC

Page 9: Jmaria.fontanillo@rediris.es J. Access Control to Video Resources TF-VVC.

TF-VVC

AuthZ module

•AuthN have a private key and AuthZ have the public key

•AuthZ check that the assertion is signed by AuthN

•The assertion contains attributes, that allow implement policies

Example User id, Group id, time to live of assertion, role, project, institution, etc

Page 10: Jmaria.fontanillo@rediris.es J. Access Control to Video Resources TF-VVC.

TF-VVC

•Implementation for DSS

•Will be aligned with JRA5

•Improvements: Independent authorization service

• The client ask to authoritation service and it return a The client ask to authoritation service and it return a tokentoken

• The client contact with streaming server with this token The client contact with streaming server with this token as parameteras parameter

• The token (signed by authZ service) will open or not the The token (signed by authZ service) will open or not the access to video depending on small set of parameters: access to video depending on small set of parameters: token timeout, resource, session code…token timeout, resource, session code…

Page 11: Jmaria.fontanillo@rediris.es J. Access Control to Video Resources TF-VVC.

TF-VVC

Page 12: Jmaria.fontanillo@rediris.es J. Access Control to Video Resources TF-VVC.

TF-VVC

•Advantages: Centralized authZ policies More flexible portal to access to our video resources We separate two domains:

• AuthN server- home organizationAuthN server- home organization

• AuthZ server+video streaming servers – resources AuthZ server+video streaming servers – resources

ownerowner