The Role of Federation in Identity Management



Similar documents
Secure the Web: OpenSSO

Identity Management in Liferay Overview and Best Practices. Liferay Portal 6.0 EE

managing SSO with shared credentials

White paper December Addressing single sign-on inside, outside, and between organizations

The Primer: Nuts and Bolts of Federated Identity Management

OPENIAM ACCESS MANAGER. Web Access Management made Easy

CA Federation Manager

OpenSSO: Simplify Your Single-Sign-On Needs. Sang Shin Java Technology Architect Sun Microsystems, inc. javapassion.com

Federated Identity in the Enterprise

Enabling Federation and Web-Single Sign-On in Heterogeneous Landscapes with the Identity Provider and Security Token Service Supplied by SAP NetWeaver

Open Source Identity Integration with OpenSSO

SAP NetWeaver Single Sign-On. Product Management SAP NetWeaver Identity Management & Security June 2011

Securing WebFOCUS A Primer. Bob Hoffman Information Builders

Connecting Users with Identity as a Service

Security Services. Benefits. The CA Advantage. Overview

The Primer: Nuts and Bolts of Federated Identity Management

Evaluation of different Open Source Identity management Systems

Adding Stronger Authentication to your Portal and Cloud Apps

SAML Security Option White Paper

Web Services Security: OpenSSO and Access Management for SOA. Sang Shin Java Technology Evangelist Sun Microsystems, Inc. javapassion.

Oracle Identity Management for SAP in Heterogeneous IT Environments. An Oracle White Paper January 2007

Masdar Institute Single Sign-On: Standards-based Identity Federation. John Mikhael ICT Department

Get Cloud Ready: Secure Access to Google Apps and Other SaaS Applications

Federated single sign-on (SSO) and identity management. Secure mobile access. Social identity integration. Automated user provisioning.

SAML SSO Configuration

EXTENDING SINGLE SIGN-ON TO AMAZON WEB SERVICES

Getting Started with AD/LDAP SSO

Web Access Management and Single Sign-On

Easy as 1-2-3: The Steps to XE. Mark Hoye Services Portfolio Consultant

White Paper. What is an Identity Provider, and Why Should My Organization Become One?

Sun and Oracle: Joining Forces in Identity Management

Federated Identity for Cloud Computing and Cross-organization Collaboration

An Oracle White Paper August Oracle OpenSSO Fedlet

Authentication Integration

Case Study: SSO for All: SSOCircle Makes Single Sign-On Available to Everyone

Biometric Single Sign-on using SAML Architecture & Design Strategies

PingFederate. SSO Integration Overview

Biometric Single Sign-on using SAML

UNIVERSITY OF COLORADO Procurement Service Center INTENT TO SOLE SOURCE PROCUREMENT CU-JL SS. Single Sign-On (SSO) Solution

Oracle IDM Integration with E-Business Suite & Middleware Technologies

ELM Manages Identities of 4 Million Government Program Users with. Identity Server

Single Sign-On: Reviewing the Field

An Oracle White Paper July Oracle Identity Federation

An Oracle White Paper Dec Oracle Access Management Security Token Service

Identity Management Basics. OWASP May 9, The OWASP Foundation. Derek Browne, CISSP, ISSAP

Interoperate in Cloud with Federation

How To Get A Single Sign On (Sso)

Can We Reconstruct How Identity is Managed on the Internet?

Entrust Secure Web Portal Solution. Livio Merlo Security Consultant September 25th, 2003

Flexible Identity Federation

CA Single Sign-On r12.x (CA SiteMinder) Implementation Proven Professional Exam

A Technical Roadmap for Oracle Fusion Middleware, E-Business Suite Release 12 and Oracle Fusion Applications

CERN, Information Technology Department

This way, Bluewin will be able to offer single sign-on for service providers within the circle.

Federated Identity Management Solutions

white paper 5 Steps to Secure Internet SSO Overview

White Paper Delivering Web Services Security: The Entrust Secure Transaction Platform

Oracle Fusion Middleware 11g Release 1 IDM Suite

Oracle Platform Security Services & Authorization Policy Manager. Vinay Shukla July 2010

BYE BYE PASSWORDS. The Future of Online Identity. Hans Zandbelt Sr. Technical Architect. CTO Office - Ping Identity

NetworkingPS Federated Identity Solution Solutions Overview

Product overview. CA SiteMinder lets you manage and deploy secure web applications to: Increase new business opportunities

Cloud SSO and Federated Identity Management Solutions and Services

The Emerging Infrastructure for Identity and Access Management

Agenda. How to configure

OpenAM All-In-One solution to securely manage access to digital enterprise and customer services, anytime and anywhere.

SAML 101. Executive Overview WHITE PAPER

IDENTITY INFORMATION MANAGMENT ARCHITECTURE SUMMARY Architecture and Standards Branch Office of the CIO Province of BC People Collaboration Innovation

Federation At Fermilab. Al Lilianstrom National Laboratories Information Technology Summit May 2015

Enabling Single Sign-On for Oracle Applications Oracle Applications Users Group PAGE 1

Extend and Enhance AD FS

Oracle Identity Management Concepts and Architecture. An Oracle White Paper December 2003

Identity opens the participation age. Dr. Rainer Eschrich. Program Manager Identity Management Sun Microsystems GmbH

Canadian Access Federation: Trust Assertion Document (TAD)

INTEGRATION GUIDE. IDENTIKEY Federation Server for Juniper SSL-VPN

STRONGER AUTHENTICATION for CA SiteMinder

White Paper Cybercom & Axiomatics Joint Identity & Access Management (R)evolution

Canadian Access Federation: Trust Assertion Document (TAD)

IBM Tivoli Federated Identity Manager

Integrating IBM Cognos 8 BI with 3rd Party Auhtentication Proxies

The Top 5 Federated Single Sign-On Scenarios

Single-Sign-On between On-Premises and the Cloud: Leveraging Windows Azure Active Directory to authenticate custom solutions and Apps

Service Virtualization: Managing Change in a Service-Oriented Architecture

The Challenges of Web single sign-on

Transcription:

The Role of Federation in Identity Management August 19, 2008 Andrew Latham Solutions Architect Identity Management 1

The Role of Federation in Identity Management Agenda Federation Backgrounder Federation in Identity Management OpenSSO CAUDIT 2

By 2009, outsourced application hosting services and SaaS providers that do not support identity federation will lose at least 25% of their business to service providers that do support federation. Gartner Predicts 2008: Mobility and Outsourcing are Changing Secure Business Enablement 3

Federation Backgrounder SUN CONFIDENTIAL

Everybody Knows Your Name An integrated technology and trust model where a user's authenticated identity is asserted across security boundaries. With respect to the systems participating in the federated infrastructure, everybody knows your name. 5

Circles of Trust 6

Federation Evolution Liberty ID FF 1.1 SAML 1.0 Liberty ID FF 1.2 SAML 1.1 SAML 2.0 Shibboleth 1.x Profiles 2002 2003 2004 7

SAML SAML has become the standard protocol for building federated systems. SAML assertions are the building blocks for loosely coupled systems, supporting the passing of secure messages between trusted parties without a need to understand the internal details of each organization. Include information about identity, authority,status of keys, and policy claims 8

Shibboleth Help higher education institutions comply with the Family Educational Rights and Privacy Act of 1974 (FERPA). FERPA is a federal law that protects student's education records. Emphases access control based on the exchange of user attributes Shibboleth enables user privacy (users can control which information is released in particular, their permanent identity), and supports fine-grained access policies. Uses SAML as a foundation for its XML-based messaging framework in support of identity assertions. 9

Project Liberty Each federated domain maps its local identity and security interfaces and formats to the agreed-upon identityfederation standards, without need to divulge sensitive user or customer data externally. Interoperating domains choose to honor each other s security decisions and trust each other s security assertions, but always within the context of their respective local policies. 10

Project Liberty Specifications for federated identity management, single sign-on (SSO), account linking, and global logout in online e-business environments. Membership in the Alliance, now more than 170, continues to expand, and includes many end-user organizations, which is unusual in the standards development process. 11

Comparison of Approaches Liberty - A user passes identity to the target, and then worries about the target s privacy policy. To comply with privacy, targets have significant regulatory requirements. The user has no control, and no responsibility. > we know who you are, albeit in two different but federated contexts Shibboleth - Users release the attributes to the target that are appropriate and necessary. If the attributes are personally identifiable, the user decides whether to release them. The user has control, along with commensurate responsibility. > we may not know who you are but we'll find out enough about you to make a policy decision 12

OpenID Establishes trust Like SAML No prior arrangement required Not Enterprise-class - User-Centric Rapidly becoming the basis for lowassurance authentication on the Internet. Allows for noncoordinated growth of clients, providers, and RPs. RPs don t need to establish trust relationships with providers in a coordinated fashion; 13

Federation in Identity Management SUN CONFIDENTIAL

Interoperability Challenges Remembering separate passwords for every single application Authenticating users identities across organizational boundaries (and often having to deal with multiple types of identity information for a single user in the process) The federated solution: > An SSO that provides access across applications in multiple domains > Portability of identity information across security domains > Leveraging of trust relationships to accept that a user has already been authenticated by a trusted partner 15

Information Security Challenges > Applying security policies across multiple organizations > Keeping private information private from a multitude of sources The federated solution: > A framework for interoperability in which a user is authenticated only once, but can be authorized as appropriate at the service provider > Implementation of the latest standards and technologies to provide sound security policies and strengthen authentication credentials, > Clear user control over which external partners can link to a company s identities, and what personal attributes are provided 16

Cost Control > Managing identities on an unprecedented scale without incurring untenable infrastructure costs > Reducing costs by making authentication and authorization portable and reusable across large provider networks in which identities may be owned by external partners The federated solution: > The ability to accept a trusted partner s authentication of a user s credentials, while efficiently mapping authorizations to those trusted credentials > Automation of identity management tasks to eliminate costs for manual processes 17

Quality of Service Streamlining navigation between internal applications and those hosted by partner Securely delivering new services to internal and external users The federated solution: > SSO for multiple applications hosted in multiple domains > Management and authentication of identities where they are owned, enabling new services to be introduced at an accelerated pace 18

OpenSSO SUN CONFIDENTIAL

20

What Makes OpenSSO Unique? 100% Java The Fedlet Virtual Federation Multi-Protocol Federation Hub Security Token Service Identity Services 21

Multi Protocol Hub Kerberos Tokens 22

Security Token Service Centralize Management & Translation of Web Service Tokens Validate, issue and translate standardsbased tokens and proprietary tokens including Oracle Access Manager & CA Siteminder tokens 23

New Model Open Source Code New model supports commercial builds and stable builds. Customers will have ability to adopt new features upon availability. 24

OpenSSO Support Model: How it Works Sun will issue patches and hot-fixes for Sun Access Manager commercial builds only. To receive a fix or enhancement for an OpenSSO Stable Build a customer must upgrade to the next stable build that contains that fix or enhancement. Sun will support the two most recent OpenSSO stable builds. Issues, bugs and/or RFEs are submitted via the same support channel as all other Sun products. 25

Learn More... Access. Federation http://www.opensso.org http://www.sun.com/identity/federation 26

CAUDIT SUN CONFIDENTIAL

The Sun CAUDIT stack Presentation Layer Portal Web Application Platform App Server JMS Directory Services LDAP IDM WAM Collaboration Email Calendar IM Data Centre Prov Cluster Mgt Ctr Grid NetConnect 28

Thank You andrew.latham@sun.com 29 29