Identity and Access Management

The IAM service provides a layer where identities, enrolment,  group membership,  attributes  and  policies  to  access  distributed  resources  and services can be managed in a homogeneous and interoperable way. It supports the federated authentication mechanisms behind the INDIGO AAI.

The IAM service provides user identity and policy information to services so that consistent authorization decisions can be enforced across distributed services.

Identity and Access Management is provided through multiple methods (SAML, OpenID Connect and X.509) by leveraging  on the credentials provided by the existing Identity Federations (i.e. IDEM, EDUGAIN, etc ). Distributed authorization policies and Token Translation Service will guarantee selected access to the resources as well as data protection and privacy

Authentication and Authorization