75
heterogeneity and distance Mark Diodati modern identity:

Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

Embed Size (px)

DESCRIPTION

Keynote from Cloud Identity Summit 2014 (July 21). Focusing on modern identity's two primary attributes: heterogeneity and distance. Discusses the requirement for adaptive and local biometric authentication in the modern identity era, with specifics on OAuth/OpenID Connect, federation, and WAM.

Citation preview

Page 1: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

heterogeneity and distance

Mark Diodati

modern identity:

Page 2: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

CIS Survival Guide

Page 3: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

99 sessions

Page 4: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

48 possible workshops

Page 5: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

12 hours of workshops

Page 6: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

60 remaining sessions

Page 7: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

24 sessions

Page 8: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

12 hours of sessions

Page 9: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

2 social events

Page 10: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)
Page 11: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)
Page 12: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)
Page 13: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

caffeinate

Page 14: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

hydrate

Page 15: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

take your vitamins

Page 16: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

get some rest

Page 17: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

take good notes

Page 18: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

get outside

Page 19: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

make a friend

Page 20: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

modern identity

Page 21: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

applications services

user constituencies devices

Page 22: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

heterogeneity

Page 23: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

distance

Page 24: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

distance: span of control

Page 25: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

on-premises

in the cloud

applications

Page 26: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

self-managed

partner-managed

SaaS-managed

applications

Page 27: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

IaaS

SaaS

PaaS

applications

Page 28: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

traditional IAM

IDaaS

identity bridge

services

Page 29: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

self-managed

partner-managed

services

Page 30: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

employees

partners

contractors

users

customers

Page 31: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

AD-joined PC/Mac COPE devices

devices

BYOD devices PC/Mac

mobile devices

Page 32: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

authentication: what matters

Page 33: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

application support

4 things that matter

Page 34: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

identity assurance

4 things that matter

Page 35: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

identity assurance

cost

4 things that matter

Page 36: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

$10,000 barn

$5,000 horse

Page 37: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

4 things that matter

usability

Page 38: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

eternal truths

Page 39: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

first eternal truth

identity assurance

cost and decreased usability

your app’s assurance requirement

“sweet” spot

Page 40: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

costs too much

Page 41: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

identity assurance

session duration

second eternal truth

Page 42: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

not good enough

Page 43: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

reset expectations?

Page 44: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

my career in heavy metal music

Page 45: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

wristwatch

Page 46: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

modern authentication

requires

adaptive and local biometrics

Page 47: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

die darwin

Page 48: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

adaptive origins

Page 49: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

conventional

primary authentication

password

smart card one-time

password (OTP)

SMS

Page 50: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

adaptive device ID

• ____ • ____ • ____

IP blacklist

• Bill pay $349 • Bill pay $610 • EFT $2,000,000

behavioral

geolocation

primary authentication

Page 51: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

assurance over time

identity assurance

session duration

higher assurance

Page 52: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

modern adaptive

Page 53: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

53

degree of difficulty

distance

modern adaptive

Page 54: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

prim

ary

adap

tive

adaptive server

resources resources

browser

adaptive: traditional

Page 55: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

adaptive: WAM

(3) yes/no or risk score

adaptive server

(1) prim

ary

WAM policy enforcement point

WAM policy decision point

browser

adaptive: WAM

Page 56: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

(3) yes/no

service provider identity provider adaptive server

(1) prim

ary

browser

adaptive: federation

Page 57: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

resource server OpenID Provider authorization server user info endpoint

client/relying party/app

API

Page 58: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

58

client/relying party/ app

client registration (admintime)

OpenID Provider/ authorization server

token refresh (runtime)

resource server token presentation (runtime)

frequency adaptive: API

Page 59: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

mobile biometric

Page 60: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

biometric reader in every pocket

Page 61: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

adaptive enhanced device ID

A

privacy

playlists

Page 62: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

eternal truths redux

Page 63: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

first new eternal truth

identity assurance

cost and decreased usability

app requirement

Page 64: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

first new eternal truth

identity assurance

cost and decreased usability

app requirement

Page 65: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

identity assurance

session duration

second new eternal truth

app requirement

Page 66: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

identity assurance

session duration

second new eternal truth

app requirement

Page 67: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

identity assurance

session duration

continuous: our best aspiration

continuous

app requirement

Page 68: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

heterogeneous, distant, continuous

authentication?

Page 69: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

monitor adaptive

developments

Page 70: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

layer authentication techniques to raise

assurance

Page 71: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

plan for multiple authentication

types

Page 72: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

get your proofing right

Page 73: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

iden

tity ass

uran

ce

password mobile smart card

proofing matters proofing

Page 74: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)

tune your engine

Page 75: Modern Identity: Heterogeneity and Distance (Cloud Identity Summit Keynote)