Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Table of Contents
maxLevel1
stylenone

eduroam GEANT operations

eduroam core service (to-do)

logs of ETLR servers (contain IPaddress, MAC address, outer-identity, CUI, ON, ...)

eduroam F-ticks

Dataset description:

Data needed for eduroam authentication for end users.

Usage log messages for each international and national roaming authentication request.

Purpose of processing:

Enable eduroam users to use WiFi service when visit another organization or federation using their home identity.

Log data provides basic statistical information about service usage. It provides statistics about the number of logins for national and international roaming. The data is used for generation of usage statistics that are publicly available at https://monitor.eduroam.org and for reporting to EC and other stakeholders.

Data source:

NROs Federation top level Radius servers. IdPs and SPs can optionally send F-ticks data as well.

Data storage and access:

Authentication data are not stored.

F-ticks data are stored in the SQL database that is operated in the infrastructure provided by CARNet. The raw data is accessible only by the personnel of eduroam operations team.

Data transfer:

Authentication data are forwarded to appropriate Federation level RADIUS server in encrypted form.

F-ticks data are not transferred to any other party or system.

Data retention:F-ticks data are kept permanently. (question)
Personal data processed:Yes

Dataset content


Data itemIs personal data (DPO fills in)
1REALM - As in users EPPN used for the authentication (for example “@education.lu”) - contains the user’s country of origin and the institution of originNo ?
2Calling-Station-Id - User’s device MAC addressNo ?
3Viscountry - ISO country code of the NRO that generated the log messageNo ?
4Visinst - Identifier of visited institution i.e. operator-name RADIUS attributeNo ?
5Result - Authentication outcome: OK / FAILNo ?

eduroam Database - NRO information

Dataset description:National Roaming Operator information.
Purpose of processing:Data is used to feed the central data repository for eduroam service. It provides information about National Roaming Operators that participate in the eduroam service. The data is used for providing public available information about eduroam service, available at https://monitor.eduroam.org/.
Data source:The eduroam database has been build as a central database with the mechanism that enables automatic data collection from (National) Roaming Operators - (N)ROs. (N)ROs should provide general data in the defined XML or JSON format. The data should be available at the specific, predefined URLs: http://www.eduroam.<tld>/general/<dataset-name>.
Data storage and access:Data is stored in the SQL database that is operated in the infrastructure provided by CARNet. The raw data is accessible only by the personnel of eduroam operations team.
Data transfer:Data is not transferred to any other party or system.
Data retention:Data is kept permanently.
Personal data processed:Yes

Dataset content


Data itemIs personal data (DPO fills in)Comment
1ROid - Unique identifier provided by the database operator during the RO registrationNo
2country - two letter country codeNo
3stage - 0=preproduction/test, 1=activeNo
4org_name - (N)RO corporate nameNo
5address_street - (N)RO addressNo
6address_city - (N)RO addressNo
7coordinates - longitude, latitude, altitudeNo
8contact_name - (N)RO contact: nameYesIf contact is person
9contact_email - (N)RO contact: e-mailYesIf contact is person
10contact_phone - (N)RO contact: phone no.YesIf contact is person
11contact_type - 0=person, 1=service/departmentNo
12contact_privacy - 0=private, 1=publicNo
13info_URL - (N)RO web page URLNo
14policy_URL - (N)RO Policy URLNo
15ts - date: last changedNo

eduroam Database - Institution information

Dataset description:Institution information (IdP or SP)
Purpose of processing:Data is used to feed the central data repository for eduroam service. It provides information about Institutions that participate in the eduroam service as IdPs and SPs. The data is used for providing public available information about eduroam service, available at https://monitor.eduroam.org/.
Data source:The eduroam database has been build as a central database with the mechanism that enables automatic data collection from (National) Roaming Operators - (N)ROs. (N)ROs should provide general data in the defined XML or JSON format. The data should be available at the specific, predefined URLs: http://www.eduroam.<tld>/general/<dataset-name>
Data storage and access:Data is stored in the SQL database that is operated in the infrastructure provided by CARNet. The raw data is accessible only by the personnel of eduroam operations team.
Data transfer:Data is not transferred to any other party or system.
Data retention:Data is kept permanently.
Personal data processed: Yes

Dataset content


Data itemIs personal data (DPO fills in)Comment
1instid - provided by the NRONo
2ROid - Unique identifier provided by the database operator during the RO registrationNo
3type - IdP, SP, IdP+SPNo
4stage - 0=preproduction/test, 1=activeNo
5inst_realm - (only for IdP or IdP+SP)No
6inst_name - institution’s corporate nameNo
7address_street - institution’s addressNo
8address_city - institution’s address: cityNo
9coordinates - longitude, latitude, altitude of institution’s locationNo
10inst_type - IEEE 802.11-2012, clause 8.4.1.34 Venue InfoNo
11contact_name - institution’s contact: nameYesIf contact is person
12contact_email - institution’s contact: e-mailYesIf contact is person
13contact_phone - institution’s contact: phone no.YesIf contact is person
14contact_type - 0=person, 1=service/departmentNo
15contact_privacy - 0=private, 1=publicNo
16info_URL - institution’s web page with the information related to the serviceNo
17policy_URL - institution’s PolicyNo
18ts - date: last changedNo

eduroam Database - Service Location information

Dataset description:Service Location information
Purpose of processing:Data is used to feed the central data repository for eduroam service. It provides information about Service Locations that are provided in eduroam by participating SPs. The data is used for providing public available information about eduroam service, available at https://monitor.eduroam.org/.
Data source:The eduroam database has been build as a central database with the mechanism that enables automatic data collection from (National) Roaming Operators - (N)ROs.(N)ROs should provide general data in the defined XML or JSON format. The data should be available at the specific, predefined URLs: http://www.eduroam.<tld>/general/<dataset-name>.
Data storage and access:Data is stored in the SQL database that is operated in the infrastructure provided by CARNet. The raw data is accessible only by the personnel of eduroam operations team.
Data transfer:Data is not transferred to any other party or system.
Data retention:Data is kept permanently.
Personal data processed: Yes

Dataset content


Data itemIs personal data (DPO fills in)Comment
1instid - provided by the NRO

No


2ROid - Unique identifier provided by the database operator during the RO No
3locationid - provided by the NRONo
4coordinates - longitude, latitude, altitudeNo
5stage - 0=preproduction/test, 1=activeNo
6type - 0=single spot; 1=area; 2=mobileNo
7loc_name - location’s nameNo
8address_street - location’s address No
9address_city - location’s address: cityNo
10location_type - IEEE 802.11-2012, clause 8.4.1.34 Venue InfoNo
11contact_name - on site contact: nameYesIf contact is person
12contact_email - on site contact: e-mailYesIf contact is person
13contact_phone - on site contact: phone no.YesIf contact is person
14contact_type - 0=person, 1=service/departmentNo
15contact_privacy - 0=private, 1=publicNo
16SSID - SSID usedNo
17enc_level - supported encryption levelsNo
18AP_no - number of APsNo
19wired_no - number of enabled sockets for wired accessNo
20tag - specific characteristic(s): port_restrict, transp_proxy, IPv6, NAT, HS2.0No
21availability - 0=default, 1=physical access restrictionsNo
22operation_hours - If service is not available 24 hours per dayNo
23info_URL - info page with additional info in case of any restrictions No
24ts - date: last changedNo

eduroam CAT (todo)

Dataset description:
Purpose of processing:
Data source:
Data storage and access:
Data transfer:
Data retention:
Personal data processed:

eduroam NRO

eduroam F-ticks

Dataset description:

Usage log messages for each international and national roaming authentication request.

Purpose of processing:

Log data provides basic statistical information about service usage. It provides statistics about the number of logins for national and international roaming. The data is sent to the GEANT central operations as requested by the eduroam service definition. Depending on the NRO practices, the data can processed by the NRO for creating usage statistics.

Data source:

NROs Federation top level Radius servers. IdPs and SPs can optionally send F-ticks data as well.

Data storage and access:

Authentication data are not stored.

F-ticks data are stored in the SQL database that is operated in the infrastructure provided by CARNet. The raw data is accessible only by the personnel of eduroam operations team.

Data transfer:

Authentication data are forwarded to appropriate Federation level RADIUS server in encrypted form.

F-ticks data are not transferred to any other party or system.

Data retention:F-ticks data are kept permanently. (question)
Personal data processed:Yes


Dataset content


Data itemIs personal data (DPO fills in)
1

2

3

...