eduroam
Purpose | International authentication infrastructure |
---|---|
Region served | Worldwide |
Website | eduroam |
eduroam (/ˈɛdʒəroʊm, -ʊ-/ EDGE-ə-rohm, -uu-; education roaming) is an international Wi-Fi internet access roaming service for users in research, higher education and further education. It provides researchers, teachers, and students network access when visiting an institution other than their own. Users are authenticated with credentials from their home institution, regardless of the location of the eduroam access point. Authorization to access the Internet and other resources are handled by the visited institution. Users do not have to pay to use eduroam.
In some countries, Internet access via eduroam is also available at other locations than the participating institutions, e.g. in libraries, public buildings, railway stations, city centres and airports.[1][2]
History
[edit]The eduroam initiative started in 2002 when during the preparations for the creation of TERENA's task force TF-Mobility, Klaas Wierenga of SURFnet shared the idea of combining a RADIUS-based infrastructure with IEEE 802.1X technology to provide roaming network access across research and education networks.[3] Initially, the service was joined by institutions in the Netherlands, Germany, Finland, Portugal, Croatia and the United Kingdom.[4] Later, other NRENs in Europe embraced the idea and started joining the infrastructure, which was then called eduroam.[5] Since 2004, the European Union co-funded further research and development work related to the eduroam service through the GN2[6] and GN3[7] projects.[8] From September 2007, the European Union also funded through these projects the continued operation and maintenance of the eduroam service at the European level.[9]
The first non-European country to join eduroam was Australia, in December 2004.[10] In Canada, eduroam started as an initiative of the University of British Columbia, which was later taken over by CANARIE as a service of its Canadian Access Federation.[11] In the United States, eduroam was initially a pilot project between the National Science Foundation and the University of Tennessee (UTK). In 2012, Internet2 announced the addition of eduroam to its NET+ service offerings.[12] AnyRoam LLC, a private company, was formed by former UTK staff to serve as an Internet2 active corporate member administering the top-level servers.
Technology
[edit]The eduroam service uses IEEE 802.1X as the authentication method and a hierarchical system of RADIUS servers.[13] The hierarchy consists of RADIUS servers at the participating institutions, national RADIUS servers run by the National Roaming Operators, and regional top-level RADIUS servers for individual world regions. When a user visits a remote institution, the user's mobile device presents their credentials to the local RADIUS server. That RADIUS server discovers that it is not responsible for the realm of the user's home institution and proxies the access request to the national RADIUS server. If the visited institution is in a different country than the home institution, the request is in turn proxied to the regional top-level RADIUS server, and then to the national RADIUS server of the user's home country. That national server forwards the credentials to the home institution, where they are verified. The 'acknowledge' travels back over the proxy-hierarchy to the visited institution and the user is granted access.
Because the user's credentials travel via a number of intermediate servers, not under the control of the home institution of the user, it is important that the credentials be protected. This requirement limits the types of authentication methods that can be used. There are two categories of useful authentication methods: those that use credentials in the form of some public-key mechanism with certificates and those that use so-called tunnelled authentication. Most institutions use a tunnelled authentication method that only requires server certificates. These server certificates are used to set up a secure tunnel between the mobile device and the authentication server, through which the user credentials are securely transported.
A complication arises if the user's home institution does not use a two-letter country-code top-level domain as part of its realm, but a generic top-level domain such as .edu or .org. By inspection of such realms, it is not possible to determine which national RADIUS server the request should be routed to. Such domains will thus, by default, fail to work in international roaming. The workaround for this problem involves the creation of exceptions in the international RADIUS request routing tables; however, this workaround does not scale as the number of exception entries grows. Several solutions have been proposed to eliminate this workaround in the future, the most promising of which is RADIUS over TLS with Dynamic Discovery, which does not rely on static routing tables inside a RADIUS server configuration to route requests to their proper destination.[14] Instead, the participating institution adds one NAPTR DNS resource record to its own domain's DNS zone, which states by which server eduroam authentication for the domain is handled.[15]
Governance
[edit]GÉANT has established a lightweight global governance structure.[16] Recognising the large variety in the organisation and funding of research and education (networking) in different countries and regions, rules imposed on the operations of eduroam are limited to technical and administrative requirements that are necessary to ensure the smooth and secure operations of eduroam worldwide. Moreover, the eduroam operators have the leading role in creating and maintaining the rules of the global eduroam governance.
The Global eduroam Governance Committee (GeGC) has the central role in the global eduroam governance structure. While its structure has evolved over time, it presently has three representatives from each of five regions — mirroring those used by the Regional Internet registries — serving a two-year term. In addition, GÉANT may appoint one or more experts as non-voting members of the GeGC.
Geographical deployment
[edit]eduroam is available at selected locations in countries with a National Roaming Operator that has signed the eduroam Compliance Statement.[17] Those sixty-seven countries are listed below. In addition, there may be pilot deployments in countries that are in the process of joining eduroam.
Europe
[edit]The NRENs that are members of the consortium of the GN3 project[7] have joined the European eduroam confederation by signing the confederation's policy[18] that requires its members to comply with a set of technical and organisational requirements, which are more specific than those in the global eduroam Compliance Statement.
As a consequence, eduroam is deployed in the following countries:
- Austria (ACOnet)
- Belgium (Belnet)
- Bosnia and Herzegovina (University of Sarajevo)
- Bulgaria (BREN)
- Croatia (CARNET)
- Cyprus (CYNET)
- Czech Republic (CESNET)
- Denmark (NORDUnet, operated by DeIC)
- Estonia (EENet)
- Finland (NORDUnet, operated by FUNET)
- France (RENATER)
- Germany (DFN)
- Greece (GRNET)
- Hungary (NIIF)
- Iceland (NORDUnet, operated by RHnet)
- Ireland (HEAnet)
- Israel (IUCC)
- Italy (GARR)
- Latvia (SigmaNet)
- Lithuania (LITNET)
- Luxembourg (RESTENA)
- North Macedonia (MARNET)
- Malta (University of Malta)
- Montenegro (MREN)
- Netherlands (SURFnet)
- Norway (NORDUnet, operated by UNINETT)
- Poland (PSNC)
- Portugal (FCCN)
- Romania (RoEduNet)
- Serbia (AMRES)
- Slovakia (SANET)
- Slovenia (ARNES)
- Spain (RedIRIS)
- Sweden (NORDUnet, operated by SUNET)
- Switzerland (SWITCH)
- Turkey (ULAKBIM)
- United Kingdom (Janet)
In addition, three NRENs that are associate members of the consortium of the GN3 project without voting rights joined the European eduroam confederation; they represent Belarus (UIIP), Moldova (RENAM) and Russia (Joint Supercomputer Center of the Russian Academy of Sciences).
Finally, five NRENs not involved in the GN3 project joined the European eduroam confederation on a voluntary basis, enabling the deployment of the service in:
- Andorra (Universitat d'Andorra)
- Armenia (ASNET-AM)
- Azerbaijan (AzScienceNet)
- Kazakhstan (KazRENA)
- Kyrgyzstan (KRENA)
The European top-level RADIUS servers are operated by SURFnet and Forskningsnettet.
Asia-Pacific
[edit]eduroam is deployed in the following countries and economies:
- Australia (AARNet)
- China (CSTNET and CERNET)
- Fiji (Fiji National University)
- Hong Kong (Harnet)
- India (ERNET)
- Indonesia (UII, UGM)
- Japan (NII)
- Macau (University of Macau)
- Malaysia (MYREN)
- New Zealand (REANNZ)
- Philippines (University of the Philippines Diliman)
- Pakistan (Higher Education Commission)
- Singapore (SingAREN)
- South Korea (KREONET)
- Sri Lanka (Lanka Education and Research Network, University of Kelaniya, University of Moratuwa)
- Taiwan (Ministry of Education)
- Thailand (UniNet)
The Asia-Pacific top-level RADIUS servers are operated by AARNet and by the University of Hong Kong.
North America
[edit]eduroam is deployed in:
- Canada (CANARIE)
- United States (Internet2)
- Mexico
- Costa Rica
- Trinidad and Tobago (UWI)
Latin America
[edit]eduroam is deployed in:
Middle East
[edit]eduroam is deployed in:
Africa
[edit]eduroam is deployed in:
- Burkina Faso (FASOREN)
- Cote d'Ivoire (Riter)
- Ethiopia (EthERNet)
- Ghana (GARNET)
- Kenya (KENET)
- Madagascar (i RENALA)
- Malawi (MAREN)
- Mauretania (Rimer)
- Morocco (MARWAN)
- Mozambique (MoRENet)
- Namibia (via TENET)
- Nigeria (NgREN/Eko-Konnect)
- Somalia (SomaliREN)
- South Africa (TENET)
- Tanzania (TERNET)
- Togo (TogoRER)
- Uganda (RENU)
- Zambia (ZAMREN)
The inter-African RADIUS servers are operated by West-African research and education network WACREN, the UbuntuNet Alliance and TENET.
See also
[edit]References
[edit]- ^ "600,000 students and researchers in Sweden go mobile with eduroam and the Cloud". 2 October 2012. Retrieved 17 September 2016.
- ^ "eduroam at Norwegian airports". 4 July 2013. Archived from the original on 12 July 2014. Retrieved 23 August 2013.
- ^ "eduroam® celebrates a decade of providing secure roaming Internet access for users". 24 May 2012. Retrieved 24 August 2013.
- ^ Carol de Groot (2004). TERENA Annual Report 2003 (PDF). TERENA. p. 34. Archived from the original (PDF) on 2007-02-05.
- ^ Wierenga, Klaas; Florio, Licia (2005). "eduroam: past, present and future". Computational Methods in Science and Technology. 11 (2): 169–173. doi:10.12921/cmst.2005.11.02.169-173.
- ^ "Multi-gigabit European academic network (GN2)". 1 September 2004. Archived from the original on 27 September 2013. Retrieved 12 August 2012.
- ^ a b "Multi-gigabit european research and education network and associated services (GN3)". 1 April 2009. Archived from the original on 17 April 2012. Retrieved 20 July 2012.
- ^ Carol de Groot (2006). TERENA Annual Report 2005 (PDF). TERENA. pp. 32–33.
- ^ de Groot, Carol; Durnford, Laura; Vietsch, Karel (2010). TERENA Annual Report 2009 (PDF). TERENA. p. 31.
- ^ "eduroam goes global" (PDF). 15 December 2004. Archived from the original (PDF) on 5 July 2011. Retrieved 23 August 2013.
- ^ "A million times a month, CANARIE enables mobile research and learning" (PDF). 29 November 2012. Archived from the original (PDF) on 24 December 2013. Retrieved 24 August 2013.
- ^ "Over 220 Universities and Research Labs Gain Easy and Secure Wi-Fi Access to the Internet". 2 October 2012. Archived from the original on 24 December 2013. Retrieved 23 August 2013.
- ^ Grayson, Mark; Shatzkamer, Kevin; Wierenga, Klaas (2011). Building the Mobile Internet. Cisco Press. pp. 45–48. ISBN 978-1-58714-243-7.
- ^ RFC 6614
- ^ "Advisory: NAPTR records – Improving Efficiency of International Authentication through utilisation of RadSec at National Level". 3 October 2012.
- ^ Karel Vietsch (2010). Global eduroam Governance (PDF). TERENA.
- ^ eduroam Compliance Statement (PDF). TERENA. 2011. Archived from the original (PDF) on 2016-01-21. Retrieved 2013-08-23.
- ^ Milinović, Miroslav; Rauschenbach, Jürgen; Winter, Stefan; Florio, Licia; Simonsen, David; Howlett, Josh (2008). eduroam Service Definition and Implementation Plan (PDF). DANTE. Archived from the original (PDF) on 26 December 2010.
- ^ "Home". cedia.org.ec.