51
Bring Your Own Iden/ty (BYOID) Prabath Siriwardena (@prabath) Director of Security WSO2

WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

  • Upload
    wso2

  • View
    249

  • Download
    0

Embed Size (px)

DESCRIPTION

 

Citation preview

Page 1: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

Bring  Your  Own  Iden/ty  (BYOID)  

Prabath  Siriwardena  (@prabath)  Director  of  Security  

WSO2  

Page 2: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges
Page 3: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges
Page 4: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

Gartner  predicts,  by  the  end  of  2015,  50%  of  all  new  retail  customer  iden<<es  will  be  

based  on  social  network  iden<<es.    

Page 5: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

Facebook  is  only  second  to  China  and  India  in  terms  of  its  user  base.  

 

Page 6: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

Facebook  vs.  Internet  User  vs.  World  Popula<on  

Page 7: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

Facebook  vs.  China  vs.  India  

Page 8: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

Enterprise  Iden<ty  ßà  Social  Iden<ty    

Page 9: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

IT  consumeriza<on  is  an  emerging  topic  or  trend  for  last  few  years.  

Page 10: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

The  ini<al  consumeriza<on  hype  was  focused  on  the  bring  your  own  

device  (BYOD)  trend.  

Page 11: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

Bring  Your  Own  Device  (BYOD)    à    

Bring  Your  Own  Iden<ty  (BYOID)    

Page 12: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

The  rise  of  BYOID  is  being  driven  by  users'  "iden<ty  fa<gue”.  

 

Page 13: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

 The  analyst  firm  Quocirca  confirms  that  in  Europe  58  percent  transact  directly  with  users  from  other  

businesses  and/or  consumers;  for  the  UK  alone  the  figure  is  65  percent.  

 

Page 14: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

In  U.S  only,    mergers  and  acquisi<ons  volume  totaled  to  $865.1  billion  in  the  first  nine  months  of  2013,  

according  to  Dealogic.    

Page 15: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

What  drives  BYOID?    

Page 16: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

SAML  2.0  /  OpenID  /  OAuth  2.0  /  OpenID  Connect    

Page 17: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

SAML  1.0  à  Nov  2002  |  SAML  1.1  à  Sept  2003  |  SAML  2.0  à  2005  

Page 18: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

OpenID  was  ini<ated  by  the  founder  of  LiveJournal,  Brad  Fitzpatrick.  

Page 19: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

By  the  end  of  2009  –  there  were  more  than  one  billion  OpenID  accounts.  

Page 20: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

OpenID  started  to  fade  due  to  OAuth  2.0    and  OpenID  Connect.  

Page 21: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

OpenID  Connect  is  a  profile  built  on  top  OAuth  2.0.  

Page 22: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

OAuth  is  not  about  authen<ca<on    –  but,  delegated  authoriza<on.    

Page 23: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

The  standard  based  iden<ty  federa<on  is  the  entry  point  to  BYOID.  

Page 24: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

Internet  Iden<ty  always  -­‐  has  an  unsolved  problem    

Page 25: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

SAML  2.0  dominated  Iden<ty  Federa<on  in  last  decade  –  OpenID  Connect  and  JWT    

possibly  lead  the  next.    

Page 26: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

Any  iden<ty  management  system  to  qualify  to  support  BYOID  -­‐  should  simply  go  beyond  standard  

support  for  Iden<ty  Federa<on  protocols.    

Page 27: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

How  would  you  mediate,  transform  iden<ty  tokens  between  different  standards  or  protocols  ?  

 

Page 28: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

WSO2  Iden<ty  Server  is  an  open  source  Iden<ty  and  En<tlement  management  server,  which  supports  SAML  2.0,  OpenID,  OAuth  2.0,  OpenID  Connect,  

XACML  3.0,  SCIM,  WS-­‐Federa<on  (passive)  and  many  other  iden<ty  federa<on  palerns.  

Page 29: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

Ope

rators  

Service  Providers  

Page 30: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

Ope

rators  

Service  Providers  SAML  2.0  

OpenID  Connect  /  SAML  2.0  

OpenID  Connect  

OpenID  Connect  

Page 31: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

SAML  2.0  OpenID  Connect  /  SAML  2.0  

Page 32: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

SAML  2.0  

SAML  2.0  

SAML  2.0  

SAML  2.0  

Page 33: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

Ope

rators  

Service  Providers  

Page 34: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

1   Scenario - 1

http://ebuy.federationdemo.com:9766/ebuy/

Page 35: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

2  

OpenID  Connect  Request  

Scenario - 1

1502808989  

Page 36: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

3  

OpenID  Connect  Request  

Scenario - 1

Page 37: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

4  

<  creden?als  >  

Scenario - 1

User  :  tom_imobile  Password:  tom_imobile  

Page 38: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

4   Scenario - 1

Page 39: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

5  

OpenID  Connect  Response  

Scenario - 1

Page 40: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

6  

OpenID  Connect  Response  

Scenario - 1

Page 41: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

7   Scenario - 1

Page 42: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

1   Scenario - 2

http://azone.federationdemo.com:9766/azone/

9477808989  

Page 43: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

2  

OpenID  Connect    Request  

Scenario - 2

Page 44: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

3  

SAML2.0  Request  

Scenario - 2

Page 45: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

3  

OAuth  2.0  

Scenario - 2

Page 46: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

4  

<  creden?als  >  

Scenario - 2

Page 47: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

4  

OAuth  2.0  response  

Scenario - 2

Page 48: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

5  

SAML2  Response  

Scenario - 2

Page 49: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

6  

OpenID  Connect  Response  

Scenario - 2

Page 50: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

7   Scenario - 2

Page 51: WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges

Thank  You..!!!