SlideShare ist ein Scribd-Unternehmen logo
1 von 8
Issues with Externalized Identity

An Internet Identity Workshop session proposed by
                    GE and Cisco
Agenda
• Overview:
  – Currently the identity externalization trend is forcing
    enterprises to continue enabling point-to-point
    connections from enterprise to cloud / business
    partner
  – We believe this may be headed towards scalability
    issues and is complicating provisioning
    processes, AuthZ and persona collisions
• Goal:
  – Understand 2012 direction from the identity industry
    leaders and service providers to help develop practical
    direction while longer term solutions unfold
Issues
• Point-to-Point federated identity and the cost and complexity of
  establishing connections
• Full life-cycle management for provisioning and de-provisioning
  user access to SaaS, and changing permissions within that lifecycle
• Synchronizing enterprise data between the enterprise and the SaaS
• Defining, distributing and executing policy consistently in the
  enterprise and in SaaS
• Second to n tier SaaS integration for federated identity,
  authorization, data synchronization and provisioning life cycle
• Visibility and auditing for all tiers of SaaS for federated identity,
  authorization, data synchronization, provisioning life cycle and
  network access
• Collision of external and enterprise identity
Point-to-Point Federated Identity
• Each connection is bespoke
   – Could we have some agreement on attribute sets?
   – How do we enable SAML re-use with persistent identities
     (routable identity)
   – When does point-to-point tip over?
• Legal contracts differ without potential for reuse
   – Could we have some standard Ts&Cs for identity
     exchange?
   – Is there a standard model for dispute resolution?
• IdP connection configuration process is complex
   – What scope is there for automation?
   – How do we make the protocol meaningful to the business?
Full life-cycle management for
    provisioning and de-provisioning
• Every federation is different!
   – Different APIs, CSVs, TDFs, Excel, spreadsheets, emails,
     pieces of paper, faxes, web pages …
• Three logical models
   – JIT – implicit lifecycle, BUT don’t persist attributes in
     service
   – Sync – complicated technology and privacy
   – Query – Opening up LDAP to external queries,
     transactionally expensive
• Privacy of identity data synchronized across SaaS
  providers
Defining, distributing and executing
 policy in the enterprise and in a SaaS
• How do we enforce enterprise policy at SaaS
  – XACML? Not interoperable in practice
  – Agree XACML on a per SaaS basis, see “Point-to-
    Point federated identity cost and complexity”
• Distributed Policy Management
  – Each provider has their own PAP/PDP, some on
    premise, some allows API but most different
Second to n tier SaaS integration for
         federated identity
• How do I enforce what services my SaaS uses?
• How do I enforce which users can use which
  SaaS leveraged service?
• What visibility do I have of services leveraged
  by SaaS providers?
• Who can consume data provided by services
  leveraged by my SaaS provider?
• Where did my data go?
Collision of external and enterprise
                 identity
• Potential for personal identities to bypass
  policies on enterprise Identities on the same
  SaaS service
• Users can store enterprise data on personal
  SaaS service offerings
• Duplicating (convoluting) identity between
  point-to-point federations

Weitere ähnliche Inhalte

Was ist angesagt?

SOA Reference Architecture
SOA Reference ArchitectureSOA Reference Architecture
SOA Reference ArchitectureRajan Ramanujam
 
What is a Service Taxonomy and Why Do I Need One?
What is a Service Taxonomy and Why Do I Need One?What is a Service Taxonomy and Why Do I Need One?
What is a Service Taxonomy and Why Do I Need One?Evergreen Systems
 
5 Surefire Ways To Make Your Soa A Success
5 Surefire Ways To Make Your Soa A Success5 Surefire Ways To Make Your Soa A Success
5 Surefire Ways To Make Your Soa A SuccessDavid Linthicum
 
Service Oriented Architecture (SOA)
Service Oriented Architecture (SOA)Service Oriented Architecture (SOA)
Service Oriented Architecture (SOA)Biniam Asnake
 
Soa Taking Theory Into Real World Application
Soa Taking Theory Into Real World ApplicationSoa Taking Theory Into Real World Application
Soa Taking Theory Into Real World ApplicationDavid Linthicum
 
DEVNET-1132 Create B2B Exchanges with Cisco Connected Processes
DEVNET-1132	Create B2B Exchanges with Cisco Connected ProcessesDEVNET-1132	Create B2B Exchanges with Cisco Connected Processes
DEVNET-1132 Create B2B Exchanges with Cisco Connected ProcessesCisco DevNet
 
SOA in a nutshell by Abhilash
 SOA in a nutshell by Abhilash SOA in a nutshell by Abhilash
SOA in a nutshell by AbhilashAbhilash Juluri
 
Understanding The Concept of SOA in Computer Programming
Understanding The Concept of SOA in Computer ProgrammingUnderstanding The Concept of SOA in Computer Programming
Understanding The Concept of SOA in Computer ProgrammingTafariSiphno
 
Web 2 0 To The Universal Soa
Web 2 0 To The Universal SoaWeb 2 0 To The Universal Soa
Web 2 0 To The Universal SoaDavid Linthicum
 
Service Oriented Infrastructure
Service Oriented InfrastructureService Oriented Infrastructure
Service Oriented InfrastructureHumberto Ramos
 
Service Oriented Architecture (SOA)
Service Oriented Architecture (SOA)Service Oriented Architecture (SOA)
Service Oriented Architecture (SOA)Mazhar Ishaq Khokhar
 

Was ist angesagt? (19)

SOA Reference Architecture
SOA Reference ArchitectureSOA Reference Architecture
SOA Reference Architecture
 
What is a Service Taxonomy and Why Do I Need One?
What is a Service Taxonomy and Why Do I Need One?What is a Service Taxonomy and Why Do I Need One?
What is a Service Taxonomy and Why Do I Need One?
 
What is service
What is serviceWhat is service
What is service
 
5 Surefire Ways To Make Your Soa A Success
5 Surefire Ways To Make Your Soa A Success5 Surefire Ways To Make Your Soa A Success
5 Surefire Ways To Make Your Soa A Success
 
Service Oriented Architecture (SOA)
Service Oriented Architecture (SOA)Service Oriented Architecture (SOA)
Service Oriented Architecture (SOA)
 
Service oriented architecture 27 May 2014
Service oriented architecture 27 May 2014Service oriented architecture 27 May 2014
Service oriented architecture 27 May 2014
 
Soa Taking Theory Into Real World Application
Soa Taking Theory Into Real World ApplicationSoa Taking Theory Into Real World Application
Soa Taking Theory Into Real World Application
 
DEVNET-1132 Create B2B Exchanges with Cisco Connected Processes
DEVNET-1132	Create B2B Exchanges with Cisco Connected ProcessesDEVNET-1132	Create B2B Exchanges with Cisco Connected Processes
DEVNET-1132 Create B2B Exchanges with Cisco Connected Processes
 
12 Steps To Soa Final
12 Steps To Soa Final12 Steps To Soa Final
12 Steps To Soa Final
 
SOA in a nutshell by Abhilash
 SOA in a nutshell by Abhilash SOA in a nutshell by Abhilash
SOA in a nutshell by Abhilash
 
Microservices Decomposition Patterns
Microservices Decomposition PatternsMicroservices Decomposition Patterns
Microservices Decomposition Patterns
 
Soa To The Rescue
Soa To The RescueSoa To The Rescue
Soa To The Rescue
 
Soa overview
Soa overviewSoa overview
Soa overview
 
Understanding The Concept of SOA in Computer Programming
Understanding The Concept of SOA in Computer ProgrammingUnderstanding The Concept of SOA in Computer Programming
Understanding The Concept of SOA in Computer Programming
 
Web 2 0 To The Universal Soa
Web 2 0 To The Universal SoaWeb 2 0 To The Universal Soa
Web 2 0 To The Universal Soa
 
Service Oriented Infrastructure
Service Oriented InfrastructureService Oriented Infrastructure
Service Oriented Infrastructure
 
Service Oriented Architecture (SOA)
Service Oriented Architecture (SOA)Service Oriented Architecture (SOA)
Service Oriented Architecture (SOA)
 
Introduction to SOA
Introduction to SOAIntroduction to SOA
Introduction to SOA
 
Chap 1
Chap 1Chap 1
Chap 1
 

Andere mochten auch

Iiw13 identifying with_your_bank
Iiw13 identifying with_your_bankIiw13 identifying with_your_bank
Iiw13 identifying with_your_bankSteve Sidner
 
בועז ארד מיה מחשבים
בועז ארד מיה מחשביםבועז ארד מיה מחשבים
בועז ארד מיה מחשביםAnochi.com.
 
העצמה של ניהול סיכונים (2) zalman el ani
העצמה של ניהול סיכונים (2) zalman el aniהעצמה של ניהול סיכונים (2) zalman el ani
העצמה של ניהול סיכונים (2) zalman el aniAnochi.com.
 
תפקידו של האנליסט בחברה עסקית אוּרי עייק
תפקידו של האנליסט בחברה עסקית   אוּרי עייקתפקידו של האנליסט בחברה עסקית   אוּרי עייק
תפקידו של האנליסט בחברה עסקית אוּרי עייקAnochi.com.
 
Jmp by wayne levin
Jmp by wayne levinJmp by wayne levin
Jmp by wayne levinAnochi.com.
 
תשובת משיבים 1 3
תשובת משיבים 1 3תשובת משיבים 1 3
תשובת משיבים 1 3Anochi.com.
 
Running with Sciccors! : Team Dynamics in Open Source
Running with Sciccors! : Team Dynamics in Open SourceRunning with Sciccors! : Team Dynamics in Open Source
Running with Sciccors! : Team Dynamics in Open SourceAmye Scavarda
 
管理原则与组织效
管理原则与组织效管理原则与组织效
管理原则与组织效卜家
 
התחממות גלובלית פלדור
התחממות גלובלית פלדורהתחממות גלובלית פלדור
התחממות גלובלית פלדורAnochi.com.
 
Quantity demanded for new dwellings january 2013
Quantity demanded for new dwellings january 2013Quantity demanded for new dwellings january 2013
Quantity demanded for new dwellings january 2013Anochi.com.
 
5 strategi pembelajaran_berbasis_tik
5 strategi pembelajaran_berbasis_tik5 strategi pembelajaran_berbasis_tik
5 strategi pembelajaran_berbasis_tikMASHANS
 
Westfield Health Care Reform Webinar Power Point
Westfield Health Care Reform Webinar Power PointWestfield Health Care Reform Webinar Power Point
Westfield Health Care Reform Webinar Power Pointjkoppenheffer
 
כלכלה מסביב לעולם - שבדיה
כלכלה מסביב לעולם - שבדיהכלכלה מסביב לעולם - שבדיה
כלכלה מסביב לעולם - שבדיהAnochi.com.
 
Hawaii linkedin social media bootcamp v1.pptx
Hawaii linkedin social media bootcamp v1.pptxHawaii linkedin social media bootcamp v1.pptx
Hawaii linkedin social media bootcamp v1.pptxMargo Rose
 
חגי גולדמן מיה מחשבים
חגי גולדמן מיה מחשביםחגי גולדמן מיה מחשבים
חגי גולדמן מיה מחשביםAnochi.com.
 
Radical privatization
Radical privatizationRadical privatization
Radical privatizationAnochi.com.
 

Andere mochten auch (20)

Iiw13 identifying with_your_bank
Iiw13 identifying with_your_bankIiw13 identifying with_your_bank
Iiw13 identifying with_your_bank
 
Pcitf iiw10
Pcitf   iiw10Pcitf   iiw10
Pcitf iiw10
 
בועז ארד מיה מחשבים
בועז ארד מיה מחשביםבועז ארד מיה מחשבים
בועז ארד מיה מחשבים
 
Fido and Touch ID
Fido and Touch IDFido and Touch ID
Fido and Touch ID
 
העצמה של ניהול סיכונים (2) zalman el ani
העצמה של ניהול סיכונים (2) zalman el aniהעצמה של ניהול סיכונים (2) zalman el ani
העצמה של ניהול סיכונים (2) zalman el ani
 
תפקידו של האנליסט בחברה עסקית אוּרי עייק
תפקידו של האנליסט בחברה עסקית   אוּרי עייקתפקידו של האנליסט בחברה עסקית   אוּרי עייק
תפקידו של האנליסט בחברה עסקית אוּרי עייק
 
Zoranje School
Zoranje SchoolZoranje School
Zoranje School
 
Jmp by wayne levin
Jmp by wayne levinJmp by wayne levin
Jmp by wayne levin
 
תשובת משיבים 1 3
תשובת משיבים 1 3תשובת משיבים 1 3
תשובת משיבים 1 3
 
Running with Sciccors! : Team Dynamics in Open Source
Running with Sciccors! : Team Dynamics in Open SourceRunning with Sciccors! : Team Dynamics in Open Source
Running with Sciccors! : Team Dynamics in Open Source
 
管理原则与组织效
管理原则与组织效管理原则与组织效
管理原则与组织效
 
התחממות גלובלית פלדור
התחממות גלובלית פלדורהתחממות גלובלית פלדור
התחממות גלובלית פלדור
 
Quantity demanded for new dwellings january 2013
Quantity demanded for new dwellings january 2013Quantity demanded for new dwellings january 2013
Quantity demanded for new dwellings january 2013
 
5 strategi pembelajaran_berbasis_tik
5 strategi pembelajaran_berbasis_tik5 strategi pembelajaran_berbasis_tik
5 strategi pembelajaran_berbasis_tik
 
Westfield Health Care Reform Webinar Power Point
Westfield Health Care Reform Webinar Power PointWestfield Health Care Reform Webinar Power Point
Westfield Health Care Reform Webinar Power Point
 
כלכלה מסביב לעולם - שבדיה
כלכלה מסביב לעולם - שבדיהכלכלה מסביב לעולם - שבדיה
כלכלה מסביב לעולם - שבדיה
 
Hawaii linkedin social media bootcamp v1.pptx
Hawaii linkedin social media bootcamp v1.pptxHawaii linkedin social media bootcamp v1.pptx
Hawaii linkedin social media bootcamp v1.pptx
 
חגי גולדמן מיה מחשבים
חגי גולדמן מיה מחשביםחגי גולדמן מיה מחשבים
חגי גולדמן מיה מחשבים
 
Radical privatization
Radical privatizationRadical privatization
Radical privatization
 
Racissmee
RacissmeeRacissmee
Racissmee
 

Ähnlich wie IIW 13 - Scalability Point to Point Federation

Cloud Services Brokerage Demystified
Cloud Services Brokerage DemystifiedCloud Services Brokerage Demystified
Cloud Services Brokerage DemystifiedZach Gardner
 
Aws dev ops saif ahmed
Aws dev ops   saif ahmedAws dev ops   saif ahmed
Aws dev ops saif ahmedsaifam
 
Cloud Catalog Management – Services Aggregation and Delivery Best Practices
Cloud Catalog Management – Services Aggregation and Delivery Best PracticesCloud Catalog Management – Services Aggregation and Delivery Best Practices
Cloud Catalog Management – Services Aggregation and Delivery Best Practicesjamcracker4677
 
Shared Services Canada - A Transformational Journey Through Enterprise Initia...
Shared Services Canada - A Transformational Journey Through Enterprise Initia...Shared Services Canada - A Transformational Journey Through Enterprise Initia...
Shared Services Canada - A Transformational Journey Through Enterprise Initia...KBIZEAU
 
Building the Agile Enterprise - Cloud Computing
Building the Agile Enterprise - Cloud ComputingBuilding the Agile Enterprise - Cloud Computing
Building the Agile Enterprise - Cloud ComputingSrinivas Koushik
 
Model Confidence for Master Data with David Loshin
Model Confidence for Master Data with David LoshinModel Confidence for Master Data with David Loshin
Model Confidence for Master Data with David LoshinEmbarcadero Technologies
 
The Emerging Data Lake IT Strategy
The Emerging Data Lake IT StrategyThe Emerging Data Lake IT Strategy
The Emerging Data Lake IT StrategyThomas Kelly, PMP
 
SAS 70 in a Post-Sarbanes, SaaS World: Quest Session 52070
SAS 70 in a Post-Sarbanes, SaaS World: Quest Session 52070SAS 70 in a Post-Sarbanes, SaaS World: Quest Session 52070
SAS 70 in a Post-Sarbanes, SaaS World: Quest Session 52070retheauditors
 
South Florida HDI Event, Managing Service Delivery
South Florida HDI Event, Managing Service DeliverySouth Florida HDI Event, Managing Service Delivery
South Florida HDI Event, Managing Service DeliveryEddie Vidal
 
Practical soa for business and researchers
Practical soa for business and researchersPractical soa for business and researchers
Practical soa for business and researchersMustafa Gamal
 
SOA - Unit 2 - Service Oriented Architecture
SOA - Unit   2 - Service Oriented ArchitectureSOA - Unit   2 - Service Oriented Architecture
SOA - Unit 2 - Service Oriented Architecturehamsa nandhini
 
Empower Your Support Ecosystem with Cisco ServiceGrid
Empower Your Support Ecosystem with Cisco ServiceGridEmpower Your Support Ecosystem with Cisco ServiceGrid
Empower Your Support Ecosystem with Cisco ServiceGridCisco Services
 
Overcoming Barriers to the Cloud
Overcoming Barriers to the Cloud Overcoming Barriers to the Cloud
Overcoming Barriers to the Cloud Andy Milsark
 
MuCon 2015 - Microservices in Integration Architecture
MuCon 2015 - Microservices in Integration ArchitectureMuCon 2015 - Microservices in Integration Architecture
MuCon 2015 - Microservices in Integration ArchitectureKim Clark
 
CIS13: Cloud, Identity Bridges, and ITSM: Three is Not a Crowd
CIS13: Cloud, Identity Bridges, and ITSM: Three is Not a CrowdCIS13: Cloud, Identity Bridges, and ITSM: Three is Not a Crowd
CIS13: Cloud, Identity Bridges, and ITSM: Three is Not a CrowdCloudIDSummit
 
I T E007 Warner 091807
I T E007  Warner 091807I T E007  Warner 091807
I T E007 Warner 091807Dreamforce07
 
Radu crahmaliuc 23feb2012
Radu crahmaliuc 23feb2012Radu crahmaliuc 23feb2012
Radu crahmaliuc 23feb2012Agora Group
 
Sso security&business tool_2018_issa_infosecsummit_grant_reveal_final
Sso security&business tool_2018_issa_infosecsummit_grant_reveal_finalSso security&business tool_2018_issa_infosecsummit_grant_reveal_final
Sso security&business tool_2018_issa_infosecsummit_grant_reveal_finalGrant Reveal
 
AWS Summit 2013 | Singapore - Service Orchestration – Managing the Cloud Disr...
AWS Summit 2013 | Singapore - Service Orchestration – Managing the Cloud Disr...AWS Summit 2013 | Singapore - Service Orchestration – Managing the Cloud Disr...
AWS Summit 2013 | Singapore - Service Orchestration – Managing the Cloud Disr...Amazon Web Services
 

Ähnlich wie IIW 13 - Scalability Point to Point Federation (20)

Cloud Services Brokerage Demystified
Cloud Services Brokerage DemystifiedCloud Services Brokerage Demystified
Cloud Services Brokerage Demystified
 
Aws dev ops saif ahmed
Aws dev ops   saif ahmedAws dev ops   saif ahmed
Aws dev ops saif ahmed
 
Cloud Catalog Management – Services Aggregation and Delivery Best Practices
Cloud Catalog Management – Services Aggregation and Delivery Best PracticesCloud Catalog Management – Services Aggregation and Delivery Best Practices
Cloud Catalog Management – Services Aggregation and Delivery Best Practices
 
Shared Services Canada - A Transformational Journey Through Enterprise Initia...
Shared Services Canada - A Transformational Journey Through Enterprise Initia...Shared Services Canada - A Transformational Journey Through Enterprise Initia...
Shared Services Canada - A Transformational Journey Through Enterprise Initia...
 
Building the Agile Enterprise - Cloud Computing
Building the Agile Enterprise - Cloud ComputingBuilding the Agile Enterprise - Cloud Computing
Building the Agile Enterprise - Cloud Computing
 
Model Confidence for Master Data with David Loshin
Model Confidence for Master Data with David LoshinModel Confidence for Master Data with David Loshin
Model Confidence for Master Data with David Loshin
 
The Emerging Data Lake IT Strategy
The Emerging Data Lake IT StrategyThe Emerging Data Lake IT Strategy
The Emerging Data Lake IT Strategy
 
SAS 70 in a Post-Sarbanes, SaaS World: Quest Session 52070
SAS 70 in a Post-Sarbanes, SaaS World: Quest Session 52070SAS 70 in a Post-Sarbanes, SaaS World: Quest Session 52070
SAS 70 in a Post-Sarbanes, SaaS World: Quest Session 52070
 
South Florida HDI Event, Managing Service Delivery
South Florida HDI Event, Managing Service DeliverySouth Florida HDI Event, Managing Service Delivery
South Florida HDI Event, Managing Service Delivery
 
Practical soa for business and researchers
Practical soa for business and researchersPractical soa for business and researchers
Practical soa for business and researchers
 
Security - A Digital Transformation Enabler
Security - A Digital Transformation EnablerSecurity - A Digital Transformation Enabler
Security - A Digital Transformation Enabler
 
SOA - Unit 2 - Service Oriented Architecture
SOA - Unit   2 - Service Oriented ArchitectureSOA - Unit   2 - Service Oriented Architecture
SOA - Unit 2 - Service Oriented Architecture
 
Empower Your Support Ecosystem with Cisco ServiceGrid
Empower Your Support Ecosystem with Cisco ServiceGridEmpower Your Support Ecosystem with Cisco ServiceGrid
Empower Your Support Ecosystem with Cisco ServiceGrid
 
Overcoming Barriers to the Cloud
Overcoming Barriers to the Cloud Overcoming Barriers to the Cloud
Overcoming Barriers to the Cloud
 
MuCon 2015 - Microservices in Integration Architecture
MuCon 2015 - Microservices in Integration ArchitectureMuCon 2015 - Microservices in Integration Architecture
MuCon 2015 - Microservices in Integration Architecture
 
CIS13: Cloud, Identity Bridges, and ITSM: Three is Not a Crowd
CIS13: Cloud, Identity Bridges, and ITSM: Three is Not a CrowdCIS13: Cloud, Identity Bridges, and ITSM: Three is Not a Crowd
CIS13: Cloud, Identity Bridges, and ITSM: Three is Not a Crowd
 
I T E007 Warner 091807
I T E007  Warner 091807I T E007  Warner 091807
I T E007 Warner 091807
 
Radu crahmaliuc 23feb2012
Radu crahmaliuc 23feb2012Radu crahmaliuc 23feb2012
Radu crahmaliuc 23feb2012
 
Sso security&business tool_2018_issa_infosecsummit_grant_reveal_final
Sso security&business tool_2018_issa_infosecsummit_grant_reveal_finalSso security&business tool_2018_issa_infosecsummit_grant_reveal_final
Sso security&business tool_2018_issa_infosecsummit_grant_reveal_final
 
AWS Summit 2013 | Singapore - Service Orchestration – Managing the Cloud Disr...
AWS Summit 2013 | Singapore - Service Orchestration – Managing the Cloud Disr...AWS Summit 2013 | Singapore - Service Orchestration – Managing the Cloud Disr...
AWS Summit 2013 | Singapore - Service Orchestration – Managing the Cloud Disr...
 

Kürzlich hochgeladen

Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobeapidays
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxRustici Software
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...apidays
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWERMadyBayot
 
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Jeffrey Haguewood
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processorsdebabhi2
 
Cyberprint. Dark Pink Apt Group [EN].pdf
Cyberprint. Dark Pink Apt Group [EN].pdfCyberprint. Dark Pink Apt Group [EN].pdf
Cyberprint. Dark Pink Apt Group [EN].pdfOverkill Security
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyKhushali Kathiriya
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherRemote DBA Services
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Victor Rentea
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoffsammart93
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...apidays
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...apidays
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...DianaGray10
 
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Orbitshub
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDropbox
 
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamDEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamUiPathCommunity
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...Zilliz
 
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...Zilliz
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusZilliz
 

Kürzlich hochgeladen (20)

Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
 
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
Cyberprint. Dark Pink Apt Group [EN].pdf
Cyberprint. Dark Pink Apt Group [EN].pdfCyberprint. Dark Pink Apt Group [EN].pdf
Cyberprint. Dark Pink Apt Group [EN].pdf
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamDEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
 
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with Milvus
 

IIW 13 - Scalability Point to Point Federation

  • 1. Issues with Externalized Identity An Internet Identity Workshop session proposed by GE and Cisco
  • 2. Agenda • Overview: – Currently the identity externalization trend is forcing enterprises to continue enabling point-to-point connections from enterprise to cloud / business partner – We believe this may be headed towards scalability issues and is complicating provisioning processes, AuthZ and persona collisions • Goal: – Understand 2012 direction from the identity industry leaders and service providers to help develop practical direction while longer term solutions unfold
  • 3. Issues • Point-to-Point federated identity and the cost and complexity of establishing connections • Full life-cycle management for provisioning and de-provisioning user access to SaaS, and changing permissions within that lifecycle • Synchronizing enterprise data between the enterprise and the SaaS • Defining, distributing and executing policy consistently in the enterprise and in SaaS • Second to n tier SaaS integration for federated identity, authorization, data synchronization and provisioning life cycle • Visibility and auditing for all tiers of SaaS for federated identity, authorization, data synchronization, provisioning life cycle and network access • Collision of external and enterprise identity
  • 4. Point-to-Point Federated Identity • Each connection is bespoke – Could we have some agreement on attribute sets? – How do we enable SAML re-use with persistent identities (routable identity) – When does point-to-point tip over? • Legal contracts differ without potential for reuse – Could we have some standard Ts&Cs for identity exchange? – Is there a standard model for dispute resolution? • IdP connection configuration process is complex – What scope is there for automation? – How do we make the protocol meaningful to the business?
  • 5. Full life-cycle management for provisioning and de-provisioning • Every federation is different! – Different APIs, CSVs, TDFs, Excel, spreadsheets, emails, pieces of paper, faxes, web pages … • Three logical models – JIT – implicit lifecycle, BUT don’t persist attributes in service – Sync – complicated technology and privacy – Query – Opening up LDAP to external queries, transactionally expensive • Privacy of identity data synchronized across SaaS providers
  • 6. Defining, distributing and executing policy in the enterprise and in a SaaS • How do we enforce enterprise policy at SaaS – XACML? Not interoperable in practice – Agree XACML on a per SaaS basis, see “Point-to- Point federated identity cost and complexity” • Distributed Policy Management – Each provider has their own PAP/PDP, some on premise, some allows API but most different
  • 7. Second to n tier SaaS integration for federated identity • How do I enforce what services my SaaS uses? • How do I enforce which users can use which SaaS leveraged service? • What visibility do I have of services leveraged by SaaS providers? • Who can consume data provided by services leveraged by my SaaS provider? • Where did my data go?
  • 8. Collision of external and enterprise identity • Potential for personal identities to bypass policies on enterprise Identities on the same SaaS service • Users can store enterprise data on personal SaaS service offerings • Duplicating (convoluting) identity between point-to-point federations

Hinweis der Redaktion

  1. But