RealMe. Technology Solution Overview. Version 1.0 Final September 2012. Authors: Mick Clarke & Steffen Sorensen



Similar documents
How to Implement Enterprise SAML SSO

DualShield SAML & SSO. Integration Guide. Copyright 2011 Deepnet Security Limited. Copyright 2011, Deepnet Security. All Rights Reserved.

Leveraging SAML for Federated Single Sign-on:

HP Software as a Service

HP Software as a Service. Federated SSO Guide

Swivel Secure and the Cloud

Glossary of Key Terms

Introduction to SAML

White Paper. FFIEC Authentication Compliance Using SecureAuth IdP

SAML SSO Configuration

IMPLEMENTING SINGLE SIGN- ON USING SAML 2.0 ON JUNIPER NETWORKS MAG SERIES JUNOS PULSE GATEWAYS

How To Create Trust Online

Evaluation of different Open Source Identity management Systems

nexus Hybrid Access Gateway

SAML for EPCS (Electronic Prescription of Controlled Substances)

EXTENDING SINGLE SIGN-ON TO AMAZON WEB SERVICES

Siebel CRM On Demand Single Sign-On. An Oracle White Paper December 2006

DocuSign Single Sign On Implementation Guide Published: March 17, 2016

Biometric Single Sign-on using SAML

Business Banking Customer Login Experience for Enhanced Login Security

IDENTITY MANAGEMENT. February The Government of the Hong Kong Special Administrative Region

Digital Identity Management

Enhancing Web Application Security

Federation At Fermilab. Al Lilianstrom National Laboratories Information Technology Summit May 2015

The Top 5 Federated Single Sign-On Scenarios

These Frequently Asked Questions include information about both the Remote Identity Proofing (RIDP) and

Cloud Authentication. Getting Started Guide. Version

Improving Security and Productivity through Federation and Single Sign-on

Flexible Identity Federation

PingFederate. Windows Live Cloud Identity Connector. User Guide. Version 1.0

Federal Identity, Credential, and Access Management Trust Framework Solutions. Relying Party Guidance For Accepting Externally-Issued Credentials

Zendesk SSO with Cloud Secure using MobileIron MDM Server and Okta

FCCX Briefing. Information Security and Privacy Advisory Board. June 13, 2014

OPENIAM ACCESS MANAGER. Web Access Management made Easy

WHITE PAPER Usher Mobile Identity Platform

Biometric Single Sign-on using SAML Architecture & Design Strategies

SAP NetWeaver Single Sign-On. Product Management SAP NetWeaver Identity Management & Security June 2011

USING FEDERATED AUTHENTICATION WITH M-FILES

CA Performance Center

This chapter describes how to use the Junos Pulse Secure Access Service in a SAML single sign-on deployment. It includes the following sections:

The increasing popularity of mobile devices is rapidly changing how and where we

Deriving a Trusted Mobile Identity from an Existing Credential

Guide for Setting Up Your Multi-Factor Authentication Account and Using Multi-Factor Authentication. Mobile App Activation

TIB 2.0 Administration Functions Overview

CBIO Security White Paper

PARTNER INTEGRATION GUIDE. Edition 1.0

Virtual Code Authentication User s Guide. June 25, 2015

LIBERTY ALLIANCE. Case Study: Aetna Enhances Secure Provider Portal with SSO and SAML 2.0. The Company. Key Objectives

Single Sign-On: Reviewing the Field

SAM Context-Based Authentication Using Juniper SA Integration Guide

SWIFT: Advanced identity management

idp Connect for OutSystems applications

Implementation Guide SAP NetWeaver Identity Management Identity Provider

PingFederate. IWA Integration Kit. User Guide. Version 3.0

REMOTE ACCESS USER GUIDE

Step-up-authetication as a service

EmpLive Technical Overview

Identity and Access Management Policy

Alternative authentication what does it really provide?

Single Sign On Business Case

Information Security Basic Concepts

PingFederate. Salesforce Connector. Quick Connection Guide. Version 4.1

Microsoft Office 365 Using SAML Integration Guide

Configuring Single Sign-on from the VMware Identity Manager Service to WebEx

Federated Identity Management Solutions

Configuring EPM System for SAML2-based Federation Services SSO

Integration Guide. SafeNet Authentication Service. Using SAS as an Identity Provider for Salesforce

Authentication Integration

DualShield Authentication Platform

SAML Security Option White Paper

Identity Management: Key Technologies

Microsoft Azure Multi-Factor authentication. (Concept Overview Part 1)

Guide for Setting Up Your Multi-Factor Authentication Account and Using Multi-Factor Authentication

Getting Started with AD/LDAP SSO

Vidder PrecisionAccess

CA Adapter. Installation and Configuration Guide for Windows. r2.2.9

Single Sign On (SSO) Implementation Manual. For Connect 5 & MyConnect Sites

2 FACTOR + 2. Authentication WAY

Implementation Guide for. Juniper SSL VPN SSO with OWA. with. BlackShield ID

Protect Everything: Networks, Applications and Cloud Services

Entrust IdentityGuard Comprehensive

PCI Self-Assessment: PCI DSS 3.0

WebLogic Server 7.0 Single Sign-On: An Overview

Single Sign On at Colorado State. Ron Splittgerber

Configuring User Identification via Active Directory

Extending DigiD to the Private Sector (DigiD-2)

Two-Factor Authentication and Swivel

Mobile Identity: Improved Cybersecurity, Easier to Use and Manage than Passwords. Mika Devonshire Associate Product Manager

Google Apps Deployment Guide

Attribute-Based Access Control Solutions: Federating Authoritative User Data to Support Relying Party Authorization Decisions and Requirements

NISTIC Pilot - Attribute Exchange Network. Biometric Consortium Conference

An Oracle White Paper Dec Oracle Access Management Security Token Service

Protected Trust Directory Sync Guide

Introduction PriorFX LTD Right to Privacy Information

Transcription:

RealMe Technology Solution Overview Version 1.0 Final September 2012 Authors: Mick Clarke & Steffen Sorensen 1

What is RealMe? RealMe is a product that offers identity services for people to use and manage online. A user will have a RealMe Account that will provide the following functions: Authentication: Logon Service A single username and password to access online services. People will be able to sign-in or log in with RealMe at a wide range of websites; People can use RealMe to provide a second factor when accessing online services. This maybe a one-time SMS code or a secure token. Online data provision: Assertion Service A means to collate information that various organisations hold about them and provide it securely online to other organisations; In particular they can provide the attributes held within the igovt identity verification service (IVS), namely, full name, date of birth, place of birth and gender, that assures their identity has been established to a high standard. 2

RealMe Context 3

RealMe Principles Ease of Use Ensure that RealMe is easy to use. Privacy Protection Ensure that the solution protects an individual s privacy by design. Information Security Ensure that the solution is secure and any data is suitably protected to a high level. 4

RealMe Account Protecting an individual s privacy Usage Reports Privacy Domains 5

RealMe Authentication - Logon Pseudonymous Authentication Provides Managed authentication service; No single identifier. 6

RealMe Verified Data - Assertion Providing verified data to client organisations Provides A secure, privacy-centric data exchange; A clear consent model; An extensible data set across multiple providers. 7

RealMe Identity Attribute Providers Provides Consistent integration that will scale to enable future IAPs Access to data held with multiple providers; A means of aggregating data in real-time. 8

How is RealMe Used? Service usage Function Example Usage Status Logon only Extended Logon Assert only Enables a RealMe customer to authenticate at an integrated client site. Enables a RealMe customer to authenticate at one integrated client site and then navigate seamlessly to another participating client site without requiring reauthentication. Enables a RealMe customer to provide identity data at an integrated client site. When a customer wants to use an online service securely, they can use their RealMe Account to do so using the same username and password they use at many other online services. In some cases the online service requires a greater level of security; RealMe can provide this by means of a second factor by means of a one time SMS code or via a secure token they possess. RealMe provides customers a username and password that can be used across a number of online services. In some cases if a customer is signed-in at one service they will not be required to enter their username and password to access another service. This works well for those services that are linked in a business sense, or are part of a suite of services within a single organisation. A customer wants to enrol for an online service or apply for, say, a home loan online; they need to provide information about themselves and provide proof of identity. They can do this using their RealMe Account. They would log into RealMe and consent to provide information about themselves for the service they require. The data is then securely sent, including data that proves who they are. This replaces the need for a customer to have to prove their identity face to face and allows them to complete the transaction wholly online. Existing igovt solution (2012) Existing igovt solution (2012) New solution (2013) 9

How is RealMe Used? Service usage Function Example Usage Status Assert then Logon Logon then Assert Federated Logon Enables a RealMe customer to provide identity data at an integrated client site and pass back a valid logon service token to allow future re-authentication for that online service. Enables a RealMe customer to authenticate at an integrated client site and then seamlessly provide identity data to that client within the same session. Enables a RealMe customer to authenticate at a client site using the client-centric credentials, then to seamlessly use their RealMe authentication credentials for second factor, or verification purposes. A customer enrols or applies for an online service and provides information about themselves and proves their identity online. They can also provide their logon, or sign-in key to the service provider at this point. This enables the customer who has applied for a home loan, to later logon, or sign-in, with RealMe to view securely the status of their loan application. A customer would have used their RealMe Account to logon to an online service, say, for example, Internet Banking. They may also need to use their RealMe Account to prove their identity to authorise a transaction (say, a high value payment). They would already be logged into with RealMe, but would require a second factor step-up, say an SMS code sent to their mobile phone in order to prove their identity. This scenario would be supported by RealMe. Some organisations would like to retain their own authentication mechanisms, such as Internet Banking. RealMe intends to support this by enabling organisations joining RealMe as Identity Providers (IDPs). In this case, if a customer were to log onto their Internet Banking site, they would also be logged onto the RealMe domain, enabling access to the RealMe services as if logged in through RealMe directly. New RealMe solution (2013) Roadmap item - may require new SAML message profile. Roadmap item 10

RealMe Architecture Overview 11

Integrating to RealMe Common means of integration Clients choose the RealMe services they require; Integration configurations are provided supporting each service. 12

RealMe Standards Aligned with Government Enterprise Architecture of NZ (GEA-NZ) Standards-based, compliant solution: GEANZ (e-gif) standards NZ SAMS (an OASIS SAML 2.0 Profile) SP initiated SSO flow. NZ Secure Web Services Standards (a WS-I Basic/OASIS WS-Trust/WS-Security/SOAP Profile) Issue and Validate binding. NZ CIQ (an OASIS CIQ v3 Profile) Identity information message format Authentication Key Strengths (and the subset Password) Standard (amendments) New Zealand Government Web Standards V2.0; New Zealand Security Manual (NZISM) general security and specifically cryptography Security in the Government Sector (SIGS) 13

Non-Functional Requirements Top Level for Day One 2013 Availability 99.95% (including planned outages); Performance sub-second response times; Capacity 30 requests per second. Solution Platform Dual site, geographically separated; Active-active, fully redundant configuration; Scalable infrastructure to meet future demand. 14

RealMe Solution Hosting 15

RealMe Solution Platform Re-use and extension of established platform 16

RealMe - Roadmap Add the missing services Logon then Assert flow (new SAML profile); Fully Federated Logon support for third-party IDPs. Additional IAPs government-held identity attributes, such as IRD number or drivers license details; Banks. Online banking Transaction authorisation; Verification. Technical Capabilities Additional mechanisms for multi-factor authentication; Full mobile support; Voice biometrics support. 17

RealMe - Detailed Solution Questions. 18