<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta>
      <issn pub-type="ppub">1613-0073</issn>
    </journal-meta>
    <article-meta>
      <title-group>
        <article-title>Assurance in Research and Education Identity Federations</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Davide Vaghetti</string-name>
          <email>davide.vaghetti@garr.it</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Workshop</string-name>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Consortium GARR</institution>
          ,
          <addr-line>Via dei Tizii 6, 00185, Rome</addr-line>
          ,
          <country country="IT">Italy</country>
        </aff>
      </contrib-group>
      <fpage>43</fpage>
      <lpage>47</lpage>
      <abstract>
        <p>This paper explores the current landscape of identity federations within research and education networks, concentrating on the trust flow and identity assurance, with a specific focus on the international and the Italian case. It delves into the role of National Research and Education Networks (NRENs), Identity Federations, and the eduGAIN global trust infrastructure. It will also provide a quick overview of the REFEDS Assurance Framework and some details of its implementation in the Italian research and education identity federation IDEM GARR AAI.</p>
      </abstract>
      <kwd-group>
        <kwd>Federation</kwd>
        <kwd>identity assurance</kwd>
        <kwd>research and education</kwd>
        <kwd>trust</kwd>
        <kwd>eduGAIN</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>In the modern digital landscape of research and education, secure and seamless access to online
resources is crucial for collaboration and innovation. Identity federations have emerged as a
solution to provide access to services and resources for students and researchers across
institutions globally. Research and Education (R&amp;E) federations rely on a network of trust between</p>
    </sec>
    <sec id="sec-2">
      <title>2. NRENs and R&amp;E Identity Federations</title>
      <p>the United States, or GARR in Italy, are pivotal in establishing and maintaining national
identity federations for research and education. These federations connect universities, research
institutions, and other academic entities to Service Providers in order to facilitate access to
digital resources such as academic journals, online ofice suites, sync and share services, cloud
CEUR</p>
      <p>
        ceur-ws.org
computing instances, student mobility resources, etc. The governance model of these
federations is typically community-driven, with an emphasis on open standards and interoperability.
Key characteristics of these federations include multilateralism, trusted third-party validation,
signed metadata, and the participation in the global inter-federation service eduGAIN.
Identity federations operate on the principles outlined by the Secure Assertion Markup Language
(SAML). SAML 2.0 core specification [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ] defines protocols for authentication and attribute
sharing between users’ Home Organizations and providers of services, or Identity Providers
and relying parties. SAML 2.0 metadata specification [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ] also plays a critical role by providing a
standardized format, called metadata, for sharing information about federation members, such
as their endpoints, supported attributes, and cryptographic keys.
      </p>
    </sec>
    <sec id="sec-3">
      <title>3. Trust Flow in Identity Federations</title>
      <p>Trust within R&amp;E identity federations is a hierarchical and multi-faceted concept. At the
foundational level, users trust their Home Organizations, which are typically universities or
research institutions. These Home Organizations, technically acting as Identity Providers,
are responsible for authenticating their users and asserting their identities and afiliation
attributes toward services within the federation. Services and resources are published in the
federation by Service Providers, either commercial, such as academic journals publishers, or
public funded, such as research projects resources. Federations act as trusted third parties
between Home Organizations and Service Providers, publishing cryptographically signed
metadata that provides both an efective way to exchange technical configuration details among
the federation participants, as well as a mean to prove the authenticity and the validity of
those information. Signed metadata are the fundamental building block of trust in identity
federations.</p>
    </sec>
    <sec id="sec-4">
      <title>4. eduGAIN: Enabling Global Interfederation</title>
      <p>The trust extends beyond national borders through eduGAIN, the inter-federation service that
connects research and education identity federations globally. eduGAIN can be considered a
federation of federations, operating on the same technical specifications employed by national
federations with the role to simplify access to resources and services at the international level,
avoiding the registration of services in multiple federations.</p>
      <p>eduGAIN collects and validates metadata about the entities of each participating identity
federation. Collected metadata are then aggregated, cryptographically signed to prove the
authenticity and the validity, and finally published so that participating federations can import
and redistribute them to their constituency.</p>
      <p>
        eduGAIN enhances the global interoperability of identity federations by connecting 80
federations and over 9,000 entities among Identity and Service Providers. The eduGAIN SAML
Profile [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ] establishes requirements for metadata management, registration authority, validity
period, cryptographic signature, and publication rules, ensuring that federations worldwide can
communicate securely and eficiently. The success of eduGAIN lies in its ability to enforce a
consistent standard across diverse federations, allowing users to access resources internationally
without compromising on security or trust.
      </p>
    </sec>
    <sec id="sec-5">
      <title>5. REFEDS Assurance Framework</title>
      <p>To mitigate the risks associated with federated identity management, R&amp;E federations implement
assurance frameworks that provide clarity on the reliability of identity assertions. The REFEDS
Assurance Framework is an identity assurance framework that has been developed by the
federation operators community, providing a global standard for the research and education
environment. It specifies how Identity Providers should communicate assurance information to
Service Providers, including the uniqueness of identifiers, the identity proofing level, and the
quality of attributes provided.</p>
      <sec id="sec-5-1">
        <title>5.1. Identifier Uniqueness</title>
        <p>Within the REFEDS Assurance Framework, the uniqueness of a user’s identifier is paramount.
Unique identifiers must represent one natural person within the Home Organization, must not
be reassigned to other person at any time, and must be asserted using one of the provided SAML
or OpenID Connect protocol identifiers provided in the specification.</p>
      </sec>
      <sec id="sec-5-2">
        <title>5.2. Identity Proofing Levels</title>
        <p>The framework defines diferent levels of identity proofing and authenticator issuance, renewal
and replacement processes (IAP), ranging from low to high, which reflect the confidence in
the identity vetting process conducted by the Identity Provider. These levels guide Service
Providers in assessing the reliability of the identity assertions they receive, allowing them to
make informed decisions about granting access to sensitive resources. The framework defines
three levels:
• IAP/low means that asserted identity corresponds to a person with a self-asserted identity.
• IAP/medium can be used for reasonably validated and verified identities.</p>
        <p>• IAP/high is reserved for well validated and verified identity.</p>
        <p>Each level also defines strict rules for the credentials issuance, renewal and replacement.</p>
      </sec>
      <sec id="sec-5-3">
        <title>5.3. Attribute Quality and Freshness</title>
        <p>Attribute assurance deals with the quality and timeliness of user attributes beyond the unique
identifier. Currently, it is limited to the freshness of the afiliation attributes and defines two
values:
• ATP/ePA-1m, afiliation updated within one month since the change.
• ATP/ePA-1d, afiliation updated within one day since the change.</p>
      </sec>
    </sec>
    <sec id="sec-6">
      <title>6. The Italian Case: IDEM Assurance Profiles</title>
      <p>
        IDEM is the Italian Research and Education identity federation that has been set up by GARR
to provide a trust infrastructure for the Italian researches and students. Currently, IDEM serves
over 2 million students, researchers, and staf across Italian universities and research centers. In
order to provide support for national and international use cases with assurance requirements,
IDEM elaborated a set of assurance profiles (IDEM-P0 to IDEM-P3) that define specific criteria
for identifier uniqueness, identity vetting, attribute quality, and authentication methods [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ].
      </p>
      <p>
        IDEM assurance profiles are an implementation of the REFEDS Assurance Framework at
a national level, also providing references to the eIDAS level of assurance [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ] and the Italian
eGOV-ID system SPID [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ].
6.1. IDEM Assurance Profiles
• IDEM-P0: The basic level with minimal identity vetting, suitable for low-risk applications.
• IDEM-P1: Requires identity proofing based on identity documents, with updated
afiliations checked within one month.
• IDEM-P2: Involves the verification of identity documents, along with Multi-Factor
Authentication (MFA) as defined by the REFEDS MFA Profile [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ], ensuring a higher level of
identity assurance.
• IDEM-P3: The highest level, requiring an electronic identity card or passport for
verification, as well as Multi-Factor Authentication.
      </p>
      <p>These profiles ensure that the federation meets diverse assurance needs, from basic access to
high-security applications, and align with the broader European and global standards based on
the REFEDS Assurance Framework.</p>
      <sec id="sec-6-1">
        <title>6.2. Signal, Request, Assertion</title>
        <p>
          In addition to the identity assurance assertions based on the REFEDS Assurance Framework, the
IDEM assurance profiles provide methods to signal support and adherence to specific assurance
profiles directly in the metadata of the Identity Provider, implementing the SAML identity
assurance profile specification [
          <xref ref-type="bibr" rid="ref11">11</xref>
          ].
        </p>
        <p>Home Organizations that want to assert support for an assurance profile, must submit
a compliance declaration targeting a specific assurance profile (i.e. IDEM-P2) to the IDEM
federation operator. After the due verification process, the IDEM federation operator will add
the IDEM profile support information in the entity metadata, resigning it to provide authenticity
and validity. Moreover, the IDEM assurance profiles explicitly define how to request and process
assurance information in a federated authentication flow.</p>
      </sec>
    </sec>
    <sec id="sec-7">
      <title>7. Conclusion</title>
      <p>The trust and identity assurance mechanisms in research and education identity federations are
fundamental to the secure and eficient operation of digital resources for the global scientific
community. As the eduGAIN inter-federation service and national federations continue to
expand and integrate more diverse entities, the adoption of specifications like REFEDS Assurance
Framework will be critical. These frameworks enhance security and trust in identity federations,
enabling the support of advanced use cases, such as e-health and life sciences, high performance
computing, and the like.</p>
      <p>The ongoing eforts to refine and expand these standards reflect the dynamic nature of
digital identity management in research and education, as well as the continually evolving
technological landscape. By adhering to robust specifications and fostering trust at all levels,
research and education federations will be able to support both current advanced use cases and
new identity paradigms, like verifiable credentials and distributed identities.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1] eduGAIN,
          <year>2024</year>
          . URL: https://edugain.org.
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <surname>REFEDS</surname>
          </string-name>
          , REFEDS Assurance Framework,
          <year>2023</year>
          . URL: https://refeds.org/assurance.
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <surname>Consortium</surname>
            <given-names>GARR</given-names>
          </string-name>
          ,
          <source>IDEM GARR AAI</source>
          ,
          <year>2024</year>
          . URL: https://www.idem.garr.it/.
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>OASIS</given-names>
            <surname>Open</surname>
          </string-name>
          ,
          <article-title>Assertions and Protocols for the OASIS Security Assertion Markup Language (SAML) V2.0</article-title>
          ,
          <string-name>
            <given-names>OASIS</given-names>
            <surname>Standard</surname>
          </string-name>
          ,
          <year>2005</year>
          . URL: http://docs.oasis-open.org/security/saml/v2.0/ saml-core-
          <volume>2</volume>
          .0-os.pdf.
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>OASIS</given-names>
            <surname>Open</surname>
          </string-name>
          ,
          <article-title>Metadata for the OASIS Security Assertion Markup Language (SAML) V2.0</article-title>
          ,
          <string-name>
            <given-names>OASIS</given-names>
            <surname>Standard</surname>
          </string-name>
          ,
          <year>2005</year>
          . URL: https://docs.oasis-open.org/security/saml/v2.0/ saml-metadata-
          <volume>2</volume>
          .0-os.pdf.
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6] eduGAIN,
          <source>eduGAIN SAML Profile</source>
          ,
          <year>2018</year>
          . URL: https://wiki.geant.org/display/eduGAIN/ eduGAIN+SAML+Profile.
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <surname>IDEM</surname>
          </string-name>
          ,
          <article-title>Profili di garanzia delle identità digitali della Federazione IDEM,</article-title>
          <year>2023</year>
          . URL: https://wiki.idem.garr.it/wiki/File:Profili_
          <article-title>di_garanzia_delle_identit%C3%A0_digitali_ della_Federazione_IDEM-v1</article-title>
          .
          <fpage>pdf</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>European</given-names>
            <surname>Union</surname>
          </string-name>
          , Implementing Regulation (EU)
          <year>2015</year>
          /1502, in:
          <source>Oficial Journal of the European Union, volume OJ L 235/7</source>
          ,
          <year>2015</year>
          . URL: https://data.europa.eu/eli/reg_impl/
          <year>2015</year>
          / 1502/oj.
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>AGID</given-names>
            ,
            <surname>Sistema</surname>
          </string-name>
          <string-name>
            <surname>Pubblico</surname>
          </string-name>
          <source>di Identità Digitale (SPID)</source>
          ,
          <year>2024</year>
          . URL: https://www.spid.gov.it/.
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <surname>REFEDS</surname>
          </string-name>
          ,
          <source>REFEDS MFA Profile - Version 1.2</source>
          ,
          <year>2023</year>
          . doi:
          <volume>10</volume>
          .5281/zenodo.10135577.
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>OASIS</given-names>
            <surname>Open</surname>
          </string-name>
          ,
          <source>SAML V2.0 Identity Assurance Profiles Version 1</source>
          .0,
          <string-name>
            <surname>Committee</surname>
            <given-names>Specification</given-names>
          </string-name>
          ,
          <year>2010</year>
          . URL: http://docs.oasis-open.org/security/saml/Post2.
          <article-title>0/ sstc-saml-assurance-profile-cs-01.pdf</article-title>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>