SlideShare ist ein Scribd-Unternehmen logo
1 von 14
AOL Concordia Use Cases
George Fletcher
Chief Architect
Identity Services
AOL LLC
AOL Concordia use cases 2
Agenda
Historical Background
AOL’s Perspective
Use Cases
AOL Concordia use cases 3
Historical Background
Customer has always been first
AOL users skew toward less tech-savy
Started with closed identity: one client, one host
• Identity was all about dial-up users and supporting
multiple identities as part of a single account
Added many additional “kinds” of identities
• AIM, ICQ, ONS, …
Complexity impacts on identity infrastructure
AOL Concordia use cases 4
AOL’s Perspective
Open AOL
• Seamless user experience
• Protect the user
• Multi-client, multi-host
• Support 3rd party services
• Support 3rd party identities
Looking to standard protocols to simplify implementation
and integration
Unfortunately the existing standards don’t currently work
well together for the consumer
AOL Concordia use cases 5
Current consumer confusion
AOL Concordia use cases 6
Use Cases
Seamless Sign-In/Sign-Out experience
• Consumer should be able to login once and be able to
seamlessly be authenticated (under user control) to
any desired web site
Identity Agents to hide protocol issues
• Leverage identity agents to provide the seamless
experience across web sites/apps that use different
identity protocols
Service invocation across protocols
• Use a consumers authenticated session to invoke
identity based services regardless of protocol
AOL Concordia use cases 7
Seamless Sign-In/Sign-Out experience
Bob turns on his computer to check his upcoming class
schedule
Bob uses his university ID and SAML IdP to login to the
web site
• Bob probably doesn’t know he’s using SAML
Bob notices that his math exam has been moved to
Friday
With some extra time on his hands, Bob decides to write
a story for ficlets
AOL Concordia use cases 8
Seamless Sign-In/Sign-Out experience
Bob “points” his browser to the ficlets site and is
seamlessly logged in
Bob writes his story and then logs out
Bob is logged out of both ficlets as well as his university
authenticated session
AOL Concordia use cases 9
Identity Agents to hide protocol issues
Alice wakes up Monday morning ready to face the day
She fires up her computer and logs into her OS user
account
The first task of the day is to check email
• The email client invokes Alice’s identity agent to
authenticate Alice to her email provider
–Email could be web based or client based
AOL Concordia use cases 10
Identity Agents to hide protocol issues
Alice authenticates by selecting one of her existing
identities
• Authenticating to the OS unlocked (to her identity
agent) her previously stored identities
• The selected identity was provisioned by Alice’s
online identity provider
• No password or pin is required because the
credentials are unique to the identity and device
Alice reads her email and sees a message from a friend
recommending a cheesecake recipe
AOL Concordia use cases 11
Identity Agents to hide protocol issues
Alice clicks the link in the email which opens her browser
As the browser loads the page, it notices that the site
supports OpenID
The browser communicates with the Identity Agent and
determines that Alice’s currently authenticated identity
also supports OpenID
The Identity Agent asks Alice if she would like to sign
into the web site using her current identity
Alice goes ahead and signs into the site using the
current identity
AOL Concordia use cases 12
Identity Agents to hide protocol issues
Since this is the first time Alice has logged into this web
site, the Identity Agent presents to additional options for
Alice
• Remember the mapping between identity and web site
• Automatically sign in the next time Alice goes to this
web site
Alice chooses to remember the identity mapping
between the identity and the web site, but not to
automatically sign on
AOL Concordia use cases 13
Service invocation across protocols
Alice wants to try AOL’s streaming radio client
However, Alice doesn’t have an AOL account
Alice notices that she can use her existing OpenID with
the radio client
Alice downloads and installs the client
Alice provides the client her OpenID
After authenticating to her OpenID provider, Alice is able
to listen to the radio streams
• AOL radio API uses Liberty ID-WSF
AOL Concordia use cases 14
Questions
Contact Information
• George Fletcher
• George.Fletcher@corp.aol.com
• 703-265-2544

Weitere ähnliche Inhalte

Ähnlich wie AOL - Concordia use cases

[OPD 2019] Inter-application vulnerabilities
[OPD 2019] Inter-application vulnerabilities[OPD 2019] Inter-application vulnerabilities
[OPD 2019] Inter-application vulnerabilities
OWASP
 
Mashing Up with User-centric Identity
Mashing Up with User-centric IdentityMashing Up with User-centric Identity
Mashing Up with User-centric Identity
kkjjkevin03
 

Ähnlich wie AOL - Concordia use cases (20)

[OPD 2019] Inter-application vulnerabilities
[OPD 2019] Inter-application vulnerabilities[OPD 2019] Inter-application vulnerabilities
[OPD 2019] Inter-application vulnerabilities
 
The red matrix
The red matrixThe red matrix
The red matrix
 
Open Id, O Auth And Webservices
Open Id, O Auth And WebservicesOpen Id, O Auth And Webservices
Open Id, O Auth And Webservices
 
Benefits and Risks of a Single Identity - IBM Connect 2017
Benefits and Risks of a Single Identity - IBM Connect 2017Benefits and Risks of a Single Identity - IBM Connect 2017
Benefits and Risks of a Single Identity - IBM Connect 2017
 
CyberSecurity - Computers In Libraries 2024
CyberSecurity - Computers In Libraries 2024CyberSecurity - Computers In Libraries 2024
CyberSecurity - Computers In Libraries 2024
 
Cybersecurity - Defense Against The Dark Arts Harry Potter Style
Cybersecurity - Defense Against The Dark Arts Harry Potter StyleCybersecurity - Defense Against The Dark Arts Harry Potter Style
Cybersecurity - Defense Against The Dark Arts Harry Potter Style
 
Enjoy Safer Technology and Defeat Cyber Criminals
Enjoy Safer Technology and Defeat Cyber CriminalsEnjoy Safer Technology and Defeat Cyber Criminals
Enjoy Safer Technology and Defeat Cyber Criminals
 
InfoSecurity Europe 2015 - Identities Exposed by David Johansson
InfoSecurity Europe 2015 - Identities Exposed by David JohanssonInfoSecurity Europe 2015 - Identities Exposed by David Johansson
InfoSecurity Europe 2015 - Identities Exposed by David Johansson
 
Mashing Up with User-centric Identity
Mashing Up with User-centric IdentityMashing Up with User-centric Identity
Mashing Up with User-centric Identity
 
Web application security part 02
Web application security part 02Web application security part 02
Web application security part 02
 
Data Breach Detection: Are you ready for GDPR?
Data Breach Detection: Are you ready for GDPR?Data Breach Detection: Are you ready for GDPR?
Data Breach Detection: Are you ready for GDPR?
 
Patterns to Bring Enterprise and Social Identity to the Cloud
Patterns to Bring Enterprise and Social Identity to the Cloud Patterns to Bring Enterprise and Social Identity to the Cloud
Patterns to Bring Enterprise and Social Identity to the Cloud
 
Building the Social Web with OpenID
Building the Social Web with OpenIDBuilding the Social Web with OpenID
Building the Social Web with OpenID
 
TheCyberThreatAndYou2_deck.pptx
TheCyberThreatAndYou2_deck.pptxTheCyberThreatAndYou2_deck.pptx
TheCyberThreatAndYou2_deck.pptx
 
Tips and Tricks to Stay Out of the Spam Folder
Tips and Tricks to Stay Out of the Spam FolderTips and Tricks to Stay Out of the Spam Folder
Tips and Tricks to Stay Out of the Spam Folder
 
JDD2015: Security in the era of modern applications and services - Bolesław D...
JDD2015: Security in the era of modern applications and services - Bolesław D...JDD2015: Security in the era of modern applications and services - Bolesław D...
JDD2015: Security in the era of modern applications and services - Bolesław D...
 
CIS 2015- User-Authorized Discovery- George Fletcher
CIS 2015- User-Authorized Discovery- George FletcherCIS 2015- User-Authorized Discovery- George Fletcher
CIS 2015- User-Authorized Discovery- George Fletcher
 
Computer and internet fraud
Computer and internet fraudComputer and internet fraud
Computer and internet fraud
 
SharePoint Saturday Austin - Share point authentication and authorization
SharePoint Saturday Austin - Share point authentication and authorizationSharePoint Saturday Austin - Share point authentication and authorization
SharePoint Saturday Austin - Share point authentication and authorization
 
The No Good, Terrible, Very Bad Web Form — HighEdWeb 2014
The No Good, Terrible, Very Bad Web Form — HighEdWeb 2014The No Good, Terrible, Very Bad Web Form — HighEdWeb 2014
The No Good, Terrible, Very Bad Web Form — HighEdWeb 2014
 

Kürzlich hochgeladen

Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort ServiceCall Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
9953056974 Low Rate Call Girls In Saket, Delhi NCR
 
💚😋 Salem Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
💚😋 Salem Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋💚😋 Salem Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
💚😋 Salem Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
nirzagarg
 
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRLLucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
imonikaupta
 
VIP Call Girls Pollachi 7001035870 Whatsapp Number, 24/07 Booking
VIP Call Girls Pollachi 7001035870 Whatsapp Number, 24/07 BookingVIP Call Girls Pollachi 7001035870 Whatsapp Number, 24/07 Booking
VIP Call Girls Pollachi 7001035870 Whatsapp Number, 24/07 Booking
dharasingh5698
 
pdfcoffee.com_business-ethics-q3m7-pdf-free.pdf
pdfcoffee.com_business-ethics-q3m7-pdf-free.pdfpdfcoffee.com_business-ethics-q3m7-pdf-free.pdf
pdfcoffee.com_business-ethics-q3m7-pdf-free.pdf
JOHNBEBONYAP1
 
Thalassery Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call G...
Thalassery Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call G...Thalassery Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call G...
Thalassery Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call G...
Call Girls In Delhi Whatsup 9873940964 Enjoy Unlimited Pleasure
 
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
Chandigarh Call girls 9053900678 Call girls in Chandigarh
 

Kürzlich hochgeladen (20)

Katraj ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready For S...
Katraj ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready For S...Katraj ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready For S...
Katraj ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready For S...
 
20240507 QFM013 Machine Intelligence Reading List April 2024.pdf
20240507 QFM013 Machine Intelligence Reading List April 2024.pdf20240507 QFM013 Machine Intelligence Reading List April 2024.pdf
20240507 QFM013 Machine Intelligence Reading List April 2024.pdf
 
All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445
All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445
All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445
 
Pune Airport ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready...
Pune Airport ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready...Pune Airport ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready...
Pune Airport ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready...
 
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort ServiceCall Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
 
(INDIRA) Call Girl Pune Call Now 8250077686 Pune Escorts 24x7
(INDIRA) Call Girl Pune Call Now 8250077686 Pune Escorts 24x7(INDIRA) Call Girl Pune Call Now 8250077686 Pune Escorts 24x7
(INDIRA) Call Girl Pune Call Now 8250077686 Pune Escorts 24x7
 
💚😋 Salem Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
💚😋 Salem Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋💚😋 Salem Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
💚😋 Salem Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
 
Pirangut | Call Girls Pune Phone No 8005736733 Elite Escort Service Available...
Pirangut | Call Girls Pune Phone No 8005736733 Elite Escort Service Available...Pirangut | Call Girls Pune Phone No 8005736733 Elite Escort Service Available...
Pirangut | Call Girls Pune Phone No 8005736733 Elite Escort Service Available...
 
APNIC Policy Roundup, presented by Sunny Chendi at the 5th ICANN APAC-TWNIC E...
APNIC Policy Roundup, presented by Sunny Chendi at the 5th ICANN APAC-TWNIC E...APNIC Policy Roundup, presented by Sunny Chendi at the 5th ICANN APAC-TWNIC E...
APNIC Policy Roundup, presented by Sunny Chendi at the 5th ICANN APAC-TWNIC E...
 
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRLLucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
 
VIP Call Girls Pollachi 7001035870 Whatsapp Number, 24/07 Booking
VIP Call Girls Pollachi 7001035870 Whatsapp Number, 24/07 BookingVIP Call Girls Pollachi 7001035870 Whatsapp Number, 24/07 Booking
VIP Call Girls Pollachi 7001035870 Whatsapp Number, 24/07 Booking
 
pdfcoffee.com_business-ethics-q3m7-pdf-free.pdf
pdfcoffee.com_business-ethics-q3m7-pdf-free.pdfpdfcoffee.com_business-ethics-q3m7-pdf-free.pdf
pdfcoffee.com_business-ethics-q3m7-pdf-free.pdf
 
Sarola * Female Escorts Service in Pune | 8005736733 Independent Escorts & Da...
Sarola * Female Escorts Service in Pune | 8005736733 Independent Escorts & Da...Sarola * Female Escorts Service in Pune | 8005736733 Independent Escorts & Da...
Sarola * Female Escorts Service in Pune | 8005736733 Independent Escorts & Da...
 
20240510 QFM016 Irresponsible AI Reading List April 2024.pdf
20240510 QFM016 Irresponsible AI Reading List April 2024.pdf20240510 QFM016 Irresponsible AI Reading List April 2024.pdf
20240510 QFM016 Irresponsible AI Reading List April 2024.pdf
 
Thalassery Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call G...
Thalassery Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call G...Thalassery Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call G...
Thalassery Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call G...
 
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service AvailableCall Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
 
Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...
Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...
Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...
 
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
 
VVIP Pune Call Girls Sinhagad WhatSapp Number 8005736733 With Elite Staff And...
VVIP Pune Call Girls Sinhagad WhatSapp Number 8005736733 With Elite Staff And...VVIP Pune Call Girls Sinhagad WhatSapp Number 8005736733 With Elite Staff And...
VVIP Pune Call Girls Sinhagad WhatSapp Number 8005736733 With Elite Staff And...
 
Story Board.pptxrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrr
Story Board.pptxrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrStory Board.pptxrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrr
Story Board.pptxrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrr
 

AOL - Concordia use cases

  • 1. AOL Concordia Use Cases George Fletcher Chief Architect Identity Services AOL LLC
  • 2. AOL Concordia use cases 2 Agenda Historical Background AOL’s Perspective Use Cases
  • 3. AOL Concordia use cases 3 Historical Background Customer has always been first AOL users skew toward less tech-savy Started with closed identity: one client, one host • Identity was all about dial-up users and supporting multiple identities as part of a single account Added many additional “kinds” of identities • AIM, ICQ, ONS, … Complexity impacts on identity infrastructure
  • 4. AOL Concordia use cases 4 AOL’s Perspective Open AOL • Seamless user experience • Protect the user • Multi-client, multi-host • Support 3rd party services • Support 3rd party identities Looking to standard protocols to simplify implementation and integration Unfortunately the existing standards don’t currently work well together for the consumer
  • 5. AOL Concordia use cases 5 Current consumer confusion
  • 6. AOL Concordia use cases 6 Use Cases Seamless Sign-In/Sign-Out experience • Consumer should be able to login once and be able to seamlessly be authenticated (under user control) to any desired web site Identity Agents to hide protocol issues • Leverage identity agents to provide the seamless experience across web sites/apps that use different identity protocols Service invocation across protocols • Use a consumers authenticated session to invoke identity based services regardless of protocol
  • 7. AOL Concordia use cases 7 Seamless Sign-In/Sign-Out experience Bob turns on his computer to check his upcoming class schedule Bob uses his university ID and SAML IdP to login to the web site • Bob probably doesn’t know he’s using SAML Bob notices that his math exam has been moved to Friday With some extra time on his hands, Bob decides to write a story for ficlets
  • 8. AOL Concordia use cases 8 Seamless Sign-In/Sign-Out experience Bob “points” his browser to the ficlets site and is seamlessly logged in Bob writes his story and then logs out Bob is logged out of both ficlets as well as his university authenticated session
  • 9. AOL Concordia use cases 9 Identity Agents to hide protocol issues Alice wakes up Monday morning ready to face the day She fires up her computer and logs into her OS user account The first task of the day is to check email • The email client invokes Alice’s identity agent to authenticate Alice to her email provider –Email could be web based or client based
  • 10. AOL Concordia use cases 10 Identity Agents to hide protocol issues Alice authenticates by selecting one of her existing identities • Authenticating to the OS unlocked (to her identity agent) her previously stored identities • The selected identity was provisioned by Alice’s online identity provider • No password or pin is required because the credentials are unique to the identity and device Alice reads her email and sees a message from a friend recommending a cheesecake recipe
  • 11. AOL Concordia use cases 11 Identity Agents to hide protocol issues Alice clicks the link in the email which opens her browser As the browser loads the page, it notices that the site supports OpenID The browser communicates with the Identity Agent and determines that Alice’s currently authenticated identity also supports OpenID The Identity Agent asks Alice if she would like to sign into the web site using her current identity Alice goes ahead and signs into the site using the current identity
  • 12. AOL Concordia use cases 12 Identity Agents to hide protocol issues Since this is the first time Alice has logged into this web site, the Identity Agent presents to additional options for Alice • Remember the mapping between identity and web site • Automatically sign in the next time Alice goes to this web site Alice chooses to remember the identity mapping between the identity and the web site, but not to automatically sign on
  • 13. AOL Concordia use cases 13 Service invocation across protocols Alice wants to try AOL’s streaming radio client However, Alice doesn’t have an AOL account Alice notices that she can use her existing OpenID with the radio client Alice downloads and installs the client Alice provides the client her OpenID After authenticating to her OpenID provider, Alice is able to listen to the radio streams • AOL radio API uses Liberty ID-WSF
  • 14. AOL Concordia use cases 14 Questions Contact Information • George Fletcher • George.Fletcher@corp.aol.com • 703-265-2544