cloud identity webinar

75
Identity in the Cloud

Upload: wso2

Post on 12-May-2015

3.106 views

Category:

Technology


1 download

TRANSCRIPT

Page 1: Cloud Identity Webinar

Identity in the Cloud

Page 2: Cloud Identity Webinar

Prabath Siriwardena

Security Architect & Product Manager(Identity Server), WSO2

Apache Axis2/Rampart committer

6 years industry experience

Page 3: Cloud Identity Webinar

Founded in 2005 by acknowledgedleaders in XML, Web ServicesTechnologies & Standards and Open Source

Producing entire middleware platform 100%open source under Apache license

Business model is to sell comprehensivesupport & maintenance for our products

Venture funded by Intel Capital

Global corporation with offices in USA, UK& Sri Lanka

80+ employees and growing

Page 4: Cloud Identity Webinar

WSO2 SOA Platform

Page 5: Cloud Identity Webinar

WSO2 Cloud Computing

• Cloud virtual machines: software virtual machines

– WSO2 products as Amazon EC2, VMWare & KVM images

• Cloud connectors: connecting the cloud to the enterprise

– Cloud Services Gateway

– Service Accelerator

• Cloud services: SOA software as a service

– Governance as a Service

– Identity as a Service

• Cloud middleware: building multi-tenant services & applications

Page 6: Cloud Identity Webinar

Engagement Model

• Quick Start– Combination of consulting, training and POC development in

one week by WSO2 on-site team working hand-in-hand with your team

• Development Support– On-going support for your engineering teams

• Production Support– Full 24x7x365 enterprise support– Regular service packs and updates to keep your system

secure and robust

Page 7: Cloud Identity Webinar
Page 8: Cloud Identity Webinar
Page 9: Cloud Identity Webinar

IDENTITY goes hand in hand with TRUST

Page 10: Cloud Identity Webinar

What makes my IDENTITY?

Page 11: Cloud Identity Webinar
Page 12: Cloud Identity Webinar

My AGE is part of my IDENTITY

Page 13: Cloud Identity Webinar

My NAME is part of my IDENTITY

Page 14: Cloud Identity Webinar

My PHONE NUMBER is part of my IDENTITY

Page 15: Cloud Identity Webinar

My e-MAIL is part of my IDENTITY

Page 16: Cloud Identity Webinar

My SSN is part of my IDENTITY

Page 17: Cloud Identity Webinar

Who needs my IDENTITY?

Page 18: Cloud Identity Webinar

My HR MANAGER

Page 19: Cloud Identity Webinar

My FINANCE MANAGER

Page 20: Cloud Identity Webinar

My PROJECT MANAGER

Page 21: Cloud Identity Webinar

PARTNERS of my company

Page 22: Cloud Identity Webinar

WHO Else ?

Page 23: Cloud Identity Webinar
Page 24: Cloud Identity Webinar
Page 25: Cloud Identity Webinar
Page 26: Cloud Identity Webinar

How do we share data related to IDENTITY ???

Page 27: Cloud Identity Webinar

Directory Services AD/LDAP

Page 28: Cloud Identity Webinar

Directory Services AD/LDAP

IDENTITY attributes maintained in a central repo

Page 29: Cloud Identity Webinar

Directory Services AD/LDAP

IDENTITY attributes shared across multiple applications within the same domain

Page 30: Cloud Identity Webinar

Directory Services AD/LDAP

Enterprise SSO can be established within participating applications

Page 31: Cloud Identity Webinar

Directory Services AD/LDAP

Directory awareness at the individual application level

Page 32: Cloud Identity Webinar
Page 33: Cloud Identity Webinar
Page 34: Cloud Identity Webinar

IDENTITY as a service

Page 35: Cloud Identity Webinar

IDENTITY as a service

Integrates IDENTITY services into application development

Page 36: Cloud Identity Webinar

IDENTITY as a service

Decouples IDENTITY related logic from individual application business logic

Page 37: Cloud Identity Webinar

IDENTITY as a service

Decouples IDENTITY related logic from individual application business logic

Page 38: Cloud Identity Webinar

IDENTITY as a service

User, IDENTITY related data externalized from the applications themselves

Page 39: Cloud Identity Webinar

IDENTITY as a service

Adheres to SOA standards

Page 40: Cloud Identity Webinar

IDENTITY SERVICES

Page 41: Cloud Identity Webinar

IDENTITY PROVIDER

Externalize IDENTITY attributes

Page 42: Cloud Identity Webinar

IDENTITY PROVIDER

Information Cards

Page 43: Cloud Identity Webinar

IDENTITY PROVIDER

OpenID

Page 44: Cloud Identity Webinar

IDENTITY PROVIDER

Identity Governance Framework [IGF]

Page 45: Cloud Identity Webinar

Authentication

User name / password

Page 46: Cloud Identity Webinar

Authentication

User centric identity : Information cards/OpenID

Page 47: Cloud Identity Webinar

Authorization

Manages authorization logic

Page 48: Cloud Identity Webinar

Authorization

XACML

Page 49: Cloud Identity Webinar

Authorization - XACML

A general purpose authorization policy language

Page 50: Cloud Identity Webinar

Provisioning

Supports administration of IDENTITY & ACCESS Management

Page 51: Cloud Identity Webinar

Provisioning

Provides centralized policy administration and controls

Page 52: Cloud Identity Webinar

Provisioning

SPML

Page 53: Cloud Identity Webinar

Auditing

Audit all IDENTITY events

Page 54: Cloud Identity Webinar

Auditing - XDAS

Distribute Audit Service

Page 55: Cloud Identity Webinar

Auditing - XDAS

The principle of accountability

Page 56: Cloud Identity Webinar

Auditing - XDAS

Detection of security policy violations

Page 57: Cloud Identity Webinar

Identity Services

Page 58: Cloud Identity Webinar

On-premise Identity Management

Page 59: Cloud Identity Webinar

Moving to the cloud….

Page 60: Cloud Identity Webinar

Powered By

Page 61: Cloud Identity Webinar
Page 62: Cloud Identity Webinar

Identity

Page 63: Cloud Identity Webinar

Identity

Page 64: Cloud Identity Webinar

Identity

OpenID

Page 65: Cloud Identity Webinar

Identity

OpenIDInfoCard

Page 66: Cloud Identity Webinar

Identity

OpenIDInfoCard

STS

Page 67: Cloud Identity Webinar

Identity

OpenIDInfoCard

STSSAML2

Page 68: Cloud Identity Webinar

Identity

OpenIDInfoCard

STSSAML2

OpenID

Page 69: Cloud Identity Webinar

WSO2 Cloud Identity

1

Internal user tries to login to Liferay / Drupal running on intranet

1

Page 70: Cloud Identity Webinar

WSO2 Cloud Identity

2

OpenID relying party plug-in redirects the user to WSO2 Cloud Identity OpenID provider for authentication

2

1

Page 71: Cloud Identity Webinar

WSO2 Cloud Identity

3

After authentication user redirected back to Liferay / Drupal

3

2

1

Page 72: Cloud Identity Webinar

Identity

OpenIDInfoCard

STSSAML2

SAML 2.0

Page 73: Cloud Identity Webinar
Page 74: Cloud Identity Webinar

Entitlement

OpenIDInfoCard

STSSAML2

Entitlement

XACML

Page 75: Cloud Identity Webinar

Thank You…!!!

http://wso2.com

http://wso2.com/about/contact

[email protected]

[email protected]

[email protected]