Identity & access management
About identity and access management
Essentially, identity and access management is about organising and securing digital identities and managing access to systems and data. At its core, it involves answering, determining and recording two questions:
- Who are you? Identity: this concerns recognition – being able to prove, securely and reliably, who you are and what characteristics belong to you. This is also known as authentication.
- What are you authorised to access? Access: this concerns what you can and are permitted to do digitally, in line with your digital identity or role. This is also known as authorisation.
To organise this securely, reliably and scalably within the education and research sector, joint agreements are needed. This ensures that users can log in to multiple organisations and systems using a single account. This is known as a federated system of agreements.
The first step is to record users’ identities and access rights and link them to a user account. The second is to share the user’s attributes confidentially with the applications to which they have access during the login process, without duplicating data or creating new, separate accounts for each application.
Within a fixed framework, organisations can themselves manage who gains access to which applications and data. This ensures that the right person can access the right applications and data at the right time. These two steps form the basis for secure collaboration, data protection and ease of use.
Why is IAM important for the sector?
More and more students and learners want greater flexibility in how they progress through their studies, both nationally and internationally. They want to be able to start, progress, switch or undertake further learning easily, regardless of sector or institution. Researchers and lecturers, too, are increasingly working across multiple institutions and need to be able to collaborate without obstacles. That is why we need a sector-wide infrastructure, for which IAM is a key prerequisite.
IAM is essential for:
- Flexible education: Start, switch or develop your skills as a learner without administrative red tape.
- Collaboration: Researchers and lecturers work seamlessly across multiple institutions.
- Lifelong learning: A single digital identity for all your studies and training courses.
- Efficiency: Less manual work, fewer errors and fewer systems, leaving more time for teaching and research.
IAM is relevant to staff within institutions, such as researchers, lecturers and other staff: it enables them to access the digital services offered by their organisation securely and easily. At an organisational level, IAM is also important for various stakeholders within the education and research sector:
- Executives and CIOs – for strategic management, risk management and compliance.
- IT architects and security specialists – for setting up secure and future-proof infrastructure.
- Functional administrators – for granting and managing access rights.
- Privacy and security officers – for protecting personal data and ensuring compliance with legislation.
- Suppliers – for secure integrations with institutional systems.
The future of IAM and innovations in this field are moving towards a situation where users increasingly take control of their own data. This allows them to decide for themselves which data is shared, with whom, for how long and for what purposes. This is also known as Self-Sovereign Identity (SSI). Identity wallets (digital wallets containing personal data) facilitate this.
Developments at European level are significant, such as the European eIDAS 2.0 Regulation, under which EU Member States will soon be obliged to offer a wallet to their citizens. The Higher Education Sector Architecture in the field of identity and access management (HOSA-IAM) also demonstrates that SSI is set to become one of the architectural principles of the future. SURF is closely monitoring developments in education and research and identifying opportunities, in consultation with the sector.
What does SURF do?
SURF enables institutions to manage their identity and access management effectively. This is achieved across institutional boundaries through the digital sector services SURF Access and eduID. We also share expertise on IAM and bring people together to exchange knowledge and insights. In doing so, SURF is committed to federated agreement frameworks for future-proof IAM infrastructure within the sector and to aligning with new European developments and regulations. We are committed to open standards and public values. SURF safeguards privacy, security and mutual trust, whilst ensuring that institutions retain the freedom to choose their own IAM arrangements.
One example is the further development of eduID. Within Npuls, SURF is working together with vocational education (MBO), higher professional education (HBO) and university education (WO) to further develop and implement the new way of working with eduID. This involves not only technical changes within institutions, but also organisational and process changes.
To organise this effectively, we are looking beyond our own national borders. For a successful Dutch digital educational identity for eduID in vocational education (mbo) and higher education (hbo and wo), it is important to align with developments in Europe and beyond. In Europe, countries handle educational identities in different ways. Together with developers from other countries, SURF is exploring how different variants can be streamlined or made compatible with one another. This is to ensure that IAM within European education and research is properly organised and that there are clear mutual agreements on its implementation.