SESAM Services Standards for the Automotive: Federation Services.



Similar documents
SAML SSO Configuration

BMW Group Central IT. Team B2X.

OSOR.eu eid/pki/esignature Community Workshop in Brussels, 13. November 2008 IT Architect Søren Peter Nielsen - spn@itst.dk

HOL9449 Access Management: Secure web, mobile and cloud access

Enabling Federation and Web-Single Sign-On in Heterogeneous Landscapes with the Identity Provider and Security Token Service Supplied by SAP NetWeaver

Agenda. How to configure

HP Software as a Service. Federated SSO Guide

The Primer: Nuts and Bolts of Federated Identity Management

The increasing popularity of mobile devices is rapidly changing how and where we

Authentication Integration

PingFederate. SSO Integration Overview

Single Sign On. SSO & ID Management for Web and Mobile Applications

HP Software as a Service

Microsoft Office 365 Using SAML Integration Guide

PingFederate. Salesforce Connector. Quick Connection Guide. Version 4.1

Getting Started with AD/LDAP SSO

Masdar Institute Single Sign-On: Standards-based Identity Federation. John Mikhael ICT Department

Easy as 1-2-3: The Steps to XE. Mark Hoye Services Portfolio Consultant

Federated single sign-on (SSO) and identity management. Secure mobile access. Social identity integration. Automated user provisioning.

Authentication and Single Sign On

Single-Sign-On between On-Premises and the Cloud: Leveraging Windows Azure Active Directory to authenticate custom solutions and Apps

UNIVERSITY OF COLORADO Procurement Service Center INTENT TO SOLE SOURCE PROCUREMENT CU-JL SS. Single Sign-On (SSO) Solution

Ameritas Single Sign-On (SSO) and Enterprise SAML Standard. Architectural Implementation, Patterns and Usage Guidelines

The Top 5 Federated Single Sign-On Scenarios

Step-by-Step guide for SSO from MS Sharepoint 2010 to SAP EP 7.0x

managing SSO with shared credentials

ABOUT TOOLS4EVER ABOUT DELOITTE RISK SERVICES

The Challenges of Web single sign-on

SAM Context-Based Authentication Using Juniper SA Integration Guide

Security Services. Benefits. The CA Advantage. Overview

Web Applications Access Control Single Sign On

SAML 101. Executive Overview WHITE PAPER

Implementation Guide SAP NetWeaver Identity Management Identity Provider

The Role of Federation in Identity Management

Hosting topology SMS PASSCODE 2015

Flexible Identity Federation

Federated Identity Management Solutions

INTEGRATION GUIDE. IDENTIKEY Federation Server for Juniper SSL-VPN

PortWise Access Management Suite

The Primer: Nuts and Bolts of Federated Identity Management

Biometric Single Sign-on using SAML Architecture & Design Strategies

Identity Federation: Bridging the Identity Gap. Michael Koyfman, Senior Global Security Solutions Architect

CONFIGURATION GUIDE WITH MICROSOFT ACTIVE DIRECTORY FEDERATION SERVER

Using Shibboleth for Single Sign- On

Enabling SAML for Dynamic Identity Federation Management

Evaluation of different Open Source Identity management Systems

Interwise Connect. Working with Reverse Proxy Version 7.x

API-Security Gateway Dirk Krafzig

Identity Federation Broker for Service Cloud

Manage all your Office365 users and licenses

SINGLE & SAME SIGN-ON ASPECTS

PingFederate. Integration Overview

SAML Federated Identity at OASIS

CA Federation Manager

SharePoint 2013 Infrastructure Planning

Biometric Single Sign-on using SAML

Product overview. CA SiteMinder lets you manage and deploy secure web applications to: Increase new business opportunities

INUVIKA OPEN VIRTUAL DESKTOP FOUNDATION SERVER

Protect Everything: Networks, Applications and Cloud Services

Federation At Fermilab. Al Lilianstrom National Laboratories Information Technology Summit May 2015

TrustedX - PKI Authentication. Whitepaper

Identity Management in Liferay Overview and Best Practices. Liferay Portal 6.0 EE

white paper 5 Steps to Secure Internet SSO Overview

SEC100 Secure Authentication and Data Transfer with SAP Single Sign-On. Public

Extend and Enhance AD FS

SAP NetWeaver Single Sign-On. Product Management SAP NetWeaver Identity Management & Security June 2011

Secure Collaboration within Organizations, B2B and B2C.

JOSSO 2.4. Ws-Federation Integration Tutorial

An Oracle White Paper Dec Oracle Access Management Security Token Service

Overview of Microsoft Enterprise Mobility Suite (EMS) Cloud University

OPENIAM ACCESS MANAGER. Web Access Management made Easy

Identity Management in Telcos. Jörg Heuer, Deutsche Telekom AG, Laboratories. Munich, April 2008

About Me. Software Architect with ShapeBlue Specialise in. 3 rd party integrations and features in CloudStack

Azure Active Directory

Mobile Identity and Edge Security Forum Sentry Security Gateway. Jason Macy CTO, Forum Systems

PortWise Access Management Suite

Cloud SSO and Federated Identity Management Solutions and Services

Identity. Provide. ...to Office 365 & Beyond

External Authentication with Windows 2003 Server with Routing and Remote Access service Authenticating Users Using SecurAccess Server by SecurEnvoy

CERN Single Sign On solution

A viable alternative to TMG / UAG Web Application security, acceleration and authentication with DenyAll s DA-WAF

Single Sign-on (SSO) technologies for the Domino Web Server

PingFederate. Windows Live Cloud Identity Connector. User Guide. Version 1.0

Security solutions Executive brief. Understand the varieties and business value of single sign-on.

Cloud Single Sign-On and On-Premise Identity Federation with SAP NetWeaver Cloud White Paper

DualShield SAML & SSO. Integration Guide. Copyright 2011 Deepnet Security Limited. Copyright 2011, Deepnet Security. All Rights Reserved.

Transcription:

Page 1 SESAM Services Standards for the Automotive: Federation Services. Business Scenarios Leveraging Federation Services Standards for the Automotive Industry.

Page 2 Agenda. The Challenges for the Automotive Industry Business scenarios using Federation Services Technical Aspects and Influences of Federation Services Classification of Federation Scenarios Federation Patterns Discussion

Page 3. Premium Brands BMW, MINI and Rolls-Royce.

Page 4. Company Information. 2007 2006 2005 workforce 107,539 106,575 105,798 revenues (in Mio. ) 56,018 48,999 46,656 car deliveries 1,500,678 1,373,970 1,327,992 profit (in Mio. ) 3,873 4,124 3,287

Page 5. IT Community. Facts 3 GDCs (Americas/Asia/EMEA) 13 locations on all continents Approx. 3,000 employees 80,000 clients, 40% Notebooks More than 6,000 servers 3 mainframe installations Thousands of (web-)applications 3 main portals (B2B, B2D, B2E) Several federated/trusted local portal solutions

Page 6 Challenges. Business processes and relationships are changing fast: Trend towards Cooperations Enormous efforts for developing new components (e.g. engines) Trend towards Components-based assembly & development Flexible usage of On-Demand capacities Fast integration of Mergers & Acquisitions Time-To: fast integration into existing Infrastructure/Processes In the past, this was mainly focused on integrating infrastructures, now it is a question of process integration (what it should be). Flexibility & Cost reduction Fast service integration is a major topic SAAS promises flexibility without too tight integration

Page 7 Challenges & Consequences. IT must be flexible and adaptive towards new business needs. User-centric process chain integration with external partners, Online Services, or SAAS providers Trend towards SAAS (software-as-a-service) models All of those challenges result in process-oriented integration of various systems, across different companies: Collaborative engineering, design, development and manufacturing X-As-A-Service Models Flexible Customer services Federation can help solving the user-centric process & application integration challenge.

Page 8 Federation Business Scenarios. User-centric process integration for Joint Ventures & Cooperations Process Step Process Step Process Step BMW Federated SSO External Process Step Process Step Process Step Partner

Page 9 Federation Business Scenarios. Hosted Services & Applications (e.g. SAAS) WS-Federation Token Claim Group Claims Custom Claims External Service User Role Store Federation Server Mapping FEDERATION TRUST BMW Federation Services Internet B2X-User Login with c-account Intranet B2X-User Login with q-account Internet LAAS BMW Corporate Network

Page 10 Federation Business Scenarios. Internal Federation Gateways B2X User B2X User Windows User FEDERATION TRUST LDAP Mapping BMW Corporate Network Active Directory

Page 11 Federation Business Scenarios. Hosted Customer and Vehicle Online Services BMW Vehicle Online Services BMW Customer Online Services Application 1 Application 1 Application 1 Application 3 Application 2 Application 2 Application 4 Application 4 Application 3 BMW Federated SSO Application 4 Federated SSO BMW Customer Third Party Service

Page 12 Federation Services in Everyday Life.

Tobias Frech ic Consult Page 13 Speaker Change. TOBIAS FRECH tobias.frech@ic-consult.de www.ic-consult.de ic Consult GmbH Keltenring 14 82041 Oberhaching

Tobias Frech ic Consult Page 14 Federation Services. Employee Company A SAML 1.x SAML 2.0 WS-Federation Company B (IdP) Federation Token FEDERATION TRUST Service (SP) Authentication Authorization Management Application

Tobias Frech ic Consult Page 15 Federation Deployment Scenarios. Single IdP to single SP Cooperation Joint-Ventures SSO Integration of different security infrastructures Service Service Service Many IdP to single SP Collaboration Platforms SAAS Platforms Service Service Single IdP to many SP Portal Integration of external Services External hosted Applications Service Service Real Life Deployments Mixed infrastructures with different federation products and protocols Company A Company B Service Company C

Tobias Frech ic Consult Page 16 Requirements and Federation Protocols. What are the requirements? What fits best for your needs? What protocols are supported by the partner? Different Federation Protocols for different requirements Most Common WS-Federation SharePoint Open Source Microsoft Compatible Outlook Web Access Enhanced Features Enhanced Security SAML 1.x Wide Distributed Metadata Support SAML 2.0

Tobias Frech ic Consult Page 17 Impact on IdM & Supporting Processes. Management Application Integration Permission Management User Helpdesk Incident Management Auditing Requires Standardizations for Federation Integration for efficient federation deployments

Tobias Frech ic Consult Page 18 Federation Patterns. Standardization with Patterns IdP managed Permissions SP managed Permissions Service Permission Management Permission Management

Tobias Frech ic Consult Page 19 IdP managed Permissions. Federation Token Claim Attribute 1 Attribute 2 Service Attribute Management Permission 1 Permission 2 Authorization Directory Permission Management Permission Application

Tobias Frech ic Consult Page 20 IdP managed Permissions. Permissions transferred with Federation Token Impact on IdP side: Permissions management for SP applications Impact on SP side: No external accounts needed Requires strong trust relationship to IdP EAM infrastructure must handle federated user sessions Typical scenario: External hosted Applications

Tobias Frech ic Consult Page 21 SP managed Permissions. Federation Token Claim Service Directory with Shadow- Accounts Management User Mapping Management Authorization Directory Permission Management Application

Tobias Frech ic Consult Page 22 SP managed Permissions. Permissions are attached to Shadow Accounts at SP side Impact on IdP side: Only Claim is transferred with Federation Token Impact on SP side: Requires Shadow-Account on SP side Permission management at Shadow-Account Claim is mapped to Shadow-Account How to map identities: Account Mapping, Account Linking, Pseudonym Linking, Typical scenario: Confidential Collaboration Platforms

Tobias Frech ic Consult Page 23 Other Federation Challenges. Legal Issues and Requirements Service Quality Contracts Security Policies Organizational Issues Support Responsibilities and Incident Management Monitoring of Federation Services How to organize incident management in federation deployments? Different SLAs/Timezones, Technical Issues How to transport authentication type/level (e.g. strong authentication)? Session Handling (SSO, SLO, Timeouts) How to ensure privacy? (Pseudonyms, Encryption)

Page 24 BMW Federation Engagements & Projects. SESAM is also an official project at the Odette (www.odette.org). SESAM is about: making Federation Services useful for the Automotive Industry. agreeing on names, trust, and organisational and legal best practices. VTS Virtual Team Spaces : Integrating internal portals with different security infrastructures and different identity stores. External Hosted Dealer Applications Integrating external applications into existing dealer portal, without tight application integration.

Page 25 Contact. wolfgang.jodl@bmw.de +49-(0)89-382-31997 Daniel Schneider daniel.schneider@bmw.de +49-(0)89-382-34954

Page 26 Thank you for your attention. Imprint: Editor Communication IT 80788 München Reproduction, even in parts, must be approved by Bayerische Motorenwerke Aktiengesellschaft, München. Patents may be pending on some concepts. 2008 Bayerische Motorenwerke Aktiengesellschaft