#iiw 13th report at #idcon 10th

19
@nov

Upload: nov-matake

Post on 05-Dec-2014

1.986 views

Category:

Technology


7 download

DESCRIPTION

 

TRANSCRIPT

Page 1: #iiw 13th report at #idcon 10th

@nov

Page 2: #iiw 13th report at #idcon 10th

IIW #13, 18-21 OCT 2011

Page 3: #iiw 13th report at #idcon 10th
Page 5: #iiw 13th report at #idcon 10th
Page 6: #iiw 13th report at #idcon 10th

OAUTH 2.0

• Service Chaining With Oauth Bearer Tokens

• Federated Authorization w/ OAuth2

•OAuth Web Authentication Where the Protocol is and What’s Next

• Identity Layer 4 OAuth 2 and Multi-Protocol Support Discussion

Page 7: #iiw 13th report at #idcon 10th

FEDERATED AUTHORIZATION W/ OAUTH2

Client Resource ServerFederated

AuthZ ServerAuth Grant

JWT Token

JWT as Bearer

Validate JWT(OPTIONAL)

Resource

Page 8: #iiw 13th report at #idcon 10th

FEDERATED AUTHORIZATION W/ OAUTH2

Client Resource ServerFederated

AuthZ ServerAuth Grant

JWT Token

JWT as Bearer

Validate JWT(OPTIONAL)

Resource

Page 9: #iiw 13th report at #idcon 10th

OAUTH WEB AUTHENTICATIONWHAT’S NEXT

•OAuth 2.0 RFC expected in Nov 2011

• Identity layer in OAuth not in OpenID Connect?

•OAuth WG Rechartering

[OAuth WG]JWT, SWD, OAuth Assertions, OAuth SAML profile,Token Revocation, OAuth JWT profile

[JOSE WG]JWS, JTE, JWK

Page 10: #iiw 13th report at #idcon 10th

JOSE WG

OAuth WG

Page 11: #iiw 13th report at #idcon 10th

•OpenID Connect Intro

•OpenID Connect Spec Work Client Registration

•OpenID Connect Spec Work Session

•OpenID Connect Editing Session

•OpenID Connect Flows and Levels of Assurance

• Smart OpenID Connect Chip to Cloud via OpenID Connect

OPENID CONNECT

Page 12: #iiw 13th report at #idcon 10th

•OpenID Connect Intro

•OpenID Connect Spec Work Client Registration

•OpenID Connect Spec Work Session

•OpenID Connect Editing Session

•OpenID Connect Flows and Levels of Assurance

• Smart OpenID Connect Chip to Cloud via OpenID Connect

OPENID CONNECT

MAINLY SPEC WORKS,BUT LOTS OF MENTIONS AROUND

Page 13: #iiw 13th report at #idcon 10th

OPENID WORKSHOP

• 10/17 at AOL (the day before IIW#13 started)

• Interop Review

•@ritou, @nov, NRI US (Edmund)

•Discussion about Implementers Dra3

•Open Issues Review

Page 14: #iiw 13th report at #idcon 10th

MONETIZING STREET IDENTITY &MOBILE AUTHENTICATION ‘LMNOP’

$1.00verify

http://j.mp/street_identity

verified address

$x.xx

RPs

verifiedaddress

Page 15: #iiw 13th report at #idcon 10th

OPEN TRANSACT

Page 16: #iiw 13th report at #idcon 10th
Page 17: #iiw 13th report at #idcon 10th

• 1st F2F meet-up w/ @pelleb & @tomwiththeweath

• Spec Updates

• 1st formal-ish document (opentransact.org/core)

•OAuth 2.0 based (will be OpenID Connect based)

•Receipt format, Discovery etc.

Page 18: #iiw 13th report at #idcon 10th

•OAuth 2.0 spec is going to next phase

•More extensions, federation, service-chaining etc.

•OpenID Connect is hot

• Implementers Dra3 coming soon..

•Open Identity Attribute Exchange Summit(11/09-10 in Washington, D.C.)

Page 19: #iiw 13th report at #idcon 10th

OPEN TRANSACT

[HOMEWORK]MAKE THIS OPENID CONNECT BASED