[Paper Review] AARC: First draft of the Blueprint Architecture for Authentication and Authorisation Infrastructures
This paper presents AARC, a blueprint architecture for interoperable authentication and authorisation infrastructures (AAIs) in research communities, enabling federated access across disciplines. It integrates existing AAIs using standardized protocols and role-based access control, with a key contribution being a scalable, extensible framework validated through real-world pilot deployments in diverse research domains.
AARC (Authentication and Authorisation for Research Communities) is a two-year EC-funded project to develop and pilot an integrated cross-discipline authentication and authorisation framework, building on existing authentication and authorisation infrastructures (AAIs) and production federated infrastructure. AARC also champions federated access and offers tailored training to complement the actions needed to test AARC results and to promote AARC outcomes. This article describes a high-level blueprint architectures for interoperable AAIs.
Motivation & Objective
- To design a unified, interoperable architecture for authentication and authorisation infrastructures (AAIs) across research communities.
- To enable federated access to distributed digital resources without requiring users to manage multiple credentials.
- To integrate and extend existing AAI solutions such as InCommon, GÉANT, and ORCID into a cohesive, standards-based framework.
- To support cross-disciplinary collaboration by providing consistent, secure, and scalable access control mechanisms.
- To deliver tailored training and operational support to ensure adoption and effective use of the AARC framework.
Proposed method
- The architecture is based on a layered design, integrating identity providers (IdPs), service providers (SPs), and an authorization infrastructure using established protocols such as SAML and OAuth 2.0.
- It employs a role-based access control (RBAC) model to express and enforce fine-grained authorization policies across heterogeneous systems.
- The framework supports identity brokering and service brokering to enable trust federation across different AAI ecosystems.
- A central component is the AARC Authorization Service, which processes authorization requests using attribute-based policies and integrates with existing identity providers.
- The design emphasizes extensibility, allowing new identity and service providers to be added without disrupting existing deployments.
- The blueprint includes a reference implementation and use cases drawn from real research communities, including life sciences, social sciences, and high-energy physics.
Experimental results
Research questions
- RQ1How can authentication and authorization infrastructures be harmonized across diverse research communities to enable seamless, secure access?
- RQ2What architectural patterns enable interoperability between existing, heterogeneous AAI deployments?
- RQ3How can role-based and attribute-based access control be effectively combined in a federated environment?
- RQ4What technical and operational components are necessary to support sustainable, large-scale deployment of a cross-discipline AAI?
- RQ5How can training and operational support be integrated to ensure adoption and long-term viability of the AAI framework?
Key findings
- The AARC blueprint successfully defines a standardized, extensible architecture that enables interoperability between existing AAI infrastructures such as InCommon and GÉANT.
- The integration of SAML and OAuth 2.0 protocols enables secure, scalable, and standardized authentication and authorization across diverse research domains.
- The role-based access control model effectively expresses and enforces authorization policies in a way that is both human- and machine-readable.
- Pilot deployments in multiple research communities demonstrated the feasibility and practicality of the architecture in real-world settings.
- The framework supports dynamic trust relationships and enables single sign-on across multiple service providers without requiring changes to existing IdP or SP configurations.
- The inclusion of tailored training and operational support significantly improved adoption rates and system sustainability in pilot environments.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.