SlideShare ist ein Scribd-Unternehmen logo
1 von 10
8/27/2013
http://gluu.org
Federation Registry
SAML
OpenID
Connect
UMA
How can states support numerous applications
who want to use their open interfaces for
authentication and authorization?
Websites
SaaS
Apps
Mobile Apps
Multi-Party Federation Approach…
• Federations provide the “tools” and “rules” to
protect privacy while driving down the costs
for both the State and application developers
• Federations are a proven approach: they are
widely used in Higher Education and
government
– http://www.gluu.co/.hdr8
To be successful federations have to
“Ease the On-boarding”
with a simple process to Join
– Provide Registration
• Applicants agree to the participation agreement and
submit their certificate via a management website
– Vet participants
• The federation reviews the application, and ensures the
applicant qualifies to participate in the federation
– Collect fee
• It is common to collect setup and subscription fees to
offset the cost of managing the federation
infrastructure
The Participation Agreement
– Specifies Privacy Protections
• Species the Levels of Assurance (LOA) from the identity
provider that an accurate authentication has been
achieved
• Specifies the Level of Protection (LOP) from the website
or mobile application as to what security is in place to
protect a person’s data from loss
• The Level of Control (LOC) a person has to access,
correct or remove their data
– Standardize Terms and Conditions
– Clarify Policies and Operating Procedures
The Federation publishes the schema or
words used by the Participants
– Attributes of the Person
• Piece of information about the person
• AKA “user claims”
– mail, phone, address, state, grade, age…
– Authentication Mechanisms
• You need to make sure the apps request the right kind of
authentication
– http://www.example.com/schema/authn/auth_mode/myMobileToken
– http://www.example.com/schema/authn/auth_level/9
– Authorization Scopes
• You need to make sure the apps request the right kind of
authentication
– http://www.example.com/schema/authz/grade1
– http://www.example/schema/authz/teacher
– http://www.example.com/schema/authz/principal
The federation publishes the nightly
“metadata”
– A file that contains the official list of the
participants of the federation (at the time of
publication)
• http://www.incommon.org/federation/metadata.html
– Publishes the certificate of each participant
– A place for the federation to publish other
information about the participant’s role
Federation Registry
– Provides scalable administration interface for the
federation operator
– Open source web application developed by the
Australian higher education federation
– Deployed in several other countries: Ireland,
Switzerland
– Enables websites to enter all the information that
is needed by the federation and handles the
approval workflow
What does the Gluu Federation Registry
Subscription Include
– Deployment of the Federation Registry application
on an existing customer IAAS or Gluu Server
– Quick start generating the Participation
Agreement—will require review and modification
by the State
– Creation of initial schema for attributes,
authentication, and authorization
– Development of a operations guide for Registry
Administrators
– Monitoring / Support of the Federation Registry
Server
Future proofing…
– Current federations are defined using SAML,
however federations are not limited to supporting
one protocol
– OpenID Connect Federation standards are
evolving :
• http://www.gluu.co/multi-openid-wiki

Weitere ähnliche Inhalte

Andere mochten auch

Requirements for Personal Clouds : Tech Ranch Talk 8/7/13
Requirements for Personal Clouds : Tech Ranch Talk 8/7/13Requirements for Personal Clouds : Tech Ranch Talk 8/7/13
Requirements for Personal Clouds : Tech Ranch Talk 8/7/13Mike Schwartz
 
ID Next 2013 Keynote Slides by Mike Schwartz
ID Next 2013 Keynote Slides by Mike SchwartzID Next 2013 Keynote Slides by Mike Schwartz
ID Next 2013 Keynote Slides by Mike SchwartzMike Schwartz
 
Autenticación Shibboleth: Experiencia de la Universidad del Bío-Bío
Autenticación Shibboleth: Experiencia de la Universidad del Bío-BíoAutenticación Shibboleth: Experiencia de la Universidad del Bío-Bío
Autenticación Shibboleth: Experiencia de la Universidad del Bío-BíoEDUTIC
 
RSA Europe: Future of Cloud Identity
RSA Europe: Future of Cloud IdentityRSA Europe: Future of Cloud Identity
RSA Europe: Future of Cloud IdentityMike Schwartz
 
Gluu EDU Webinar: Shibboleth/SAML SSO
Gluu EDU Webinar: Shibboleth/SAML SSOGluu EDU Webinar: Shibboleth/SAML SSO
Gluu EDU Webinar: Shibboleth/SAML SSOMike Schwartz
 
Cloud Identity: A Recipe for Higher Education
Cloud Identity: A Recipe for Higher EducationCloud Identity: A Recipe for Higher Education
Cloud Identity: A Recipe for Higher EducationMike Schwartz
 
OAuth2 for IoT Security: Why OpenID Connect & UMA Are They Key
OAuth2 for IoT Security: Why OpenID Connect & UMA Are They KeyOAuth2 for IoT Security: Why OpenID Connect & UMA Are They Key
OAuth2 for IoT Security: Why OpenID Connect & UMA Are They KeyMike Schwartz
 
RSA Conference 2016: Who Are You? From Meat to Electrons and Back Again
RSA Conference 2016: Who Are You? From Meat to Electrons and Back AgainRSA Conference 2016: Who Are You? From Meat to Electrons and Back Again
RSA Conference 2016: Who Are You? From Meat to Electrons and Back AgainMike Schwartz
 
SAML Protocol Overview
SAML Protocol OverviewSAML Protocol Overview
SAML Protocol OverviewMike Schwartz
 
RSA Conference 2016: Don't Use Two-Factor Authentication... Unless You Need It!
RSA Conference 2016: Don't Use Two-Factor Authentication... Unless You Need It!RSA Conference 2016: Don't Use Two-Factor Authentication... Unless You Need It!
RSA Conference 2016: Don't Use Two-Factor Authentication... Unless You Need It!Mike Schwartz
 

Andere mochten auch (12)

Requirements for Personal Clouds : Tech Ranch Talk 8/7/13
Requirements for Personal Clouds : Tech Ranch Talk 8/7/13Requirements for Personal Clouds : Tech Ranch Talk 8/7/13
Requirements for Personal Clouds : Tech Ranch Talk 8/7/13
 
Kantara OTTO slides
Kantara OTTO slidesKantara OTTO slides
Kantara OTTO slides
 
ID Next 2013 Keynote Slides by Mike Schwartz
ID Next 2013 Keynote Slides by Mike SchwartzID Next 2013 Keynote Slides by Mike Schwartz
ID Next 2013 Keynote Slides by Mike Schwartz
 
Autenticación Shibboleth: Experiencia de la Universidad del Bío-Bío
Autenticación Shibboleth: Experiencia de la Universidad del Bío-BíoAutenticación Shibboleth: Experiencia de la Universidad del Bío-Bío
Autenticación Shibboleth: Experiencia de la Universidad del Bío-Bío
 
RSA Europe: Future of Cloud Identity
RSA Europe: Future of Cloud IdentityRSA Europe: Future of Cloud Identity
RSA Europe: Future of Cloud Identity
 
Gluu EDU Webinar: Shibboleth/SAML SSO
Gluu EDU Webinar: Shibboleth/SAML SSOGluu EDU Webinar: Shibboleth/SAML SSO
Gluu EDU Webinar: Shibboleth/SAML SSO
 
Cloud Identity: A Recipe for Higher Education
Cloud Identity: A Recipe for Higher EducationCloud Identity: A Recipe for Higher Education
Cloud Identity: A Recipe for Higher Education
 
OAuth2 for IoT Security: Why OpenID Connect & UMA Are They Key
OAuth2 for IoT Security: Why OpenID Connect & UMA Are They KeyOAuth2 for IoT Security: Why OpenID Connect & UMA Are They Key
OAuth2 for IoT Security: Why OpenID Connect & UMA Are They Key
 
RSA Conference 2016: Who Are You? From Meat to Electrons and Back Again
RSA Conference 2016: Who Are You? From Meat to Electrons and Back AgainRSA Conference 2016: Who Are You? From Meat to Electrons and Back Again
RSA Conference 2016: Who Are You? From Meat to Electrons and Back Again
 
SAML Protocol Overview
SAML Protocol OverviewSAML Protocol Overview
SAML Protocol Overview
 
Single Sign On 101
Single Sign On 101Single Sign On 101
Single Sign On 101
 
RSA Conference 2016: Don't Use Two-Factor Authentication... Unless You Need It!
RSA Conference 2016: Don't Use Two-Factor Authentication... Unless You Need It!RSA Conference 2016: Don't Use Two-Factor Authentication... Unless You Need It!
RSA Conference 2016: Don't Use Two-Factor Authentication... Unless You Need It!
 

Ähnlich wie Federation registry

project on Agile approach
project on Agile approachproject on Agile approach
project on Agile approachPrachi desai
 
Mobile Banking Security: Challenges, Solutions
Mobile Banking Security: Challenges, SolutionsMobile Banking Security: Challenges, Solutions
Mobile Banking Security: Challenges, SolutionsCognizant
 
Terbine DEP Policy Engine
Terbine DEP Policy EngineTerbine DEP Policy Engine
Terbine DEP Policy EngineDavid Knight
 
Messaging solutions for the government and authorities
Messaging solutions for the government and authoritiesMessaging solutions for the government and authorities
Messaging solutions for the government and authoritiesMDK Labs GmbH
 
Platform Events Demo (1).pptx
Platform Events Demo (1).pptxPlatform Events Demo (1).pptx
Platform Events Demo (1).pptxDileepSingh682144
 
Project 1 Template (Due on Week 4)Name.docx
Project 1 Template (Due on Week 4)Name.docxProject 1 Template (Due on Week 4)Name.docx
Project 1 Template (Due on Week 4)Name.docxsimonlbentley59018
 
API Security: Does My Business Need OAuth?
API Security: Does My Business Need OAuth?API Security: Does My Business Need OAuth?
API Security: Does My Business Need OAuth?Akana
 
API Security: Does My Business Need OAuth?
API Security: Does My Business Need OAuth?API Security: Does My Business Need OAuth?
API Security: Does My Business Need OAuth?Akana
 
Improving Veteran benefit services through efficient data streaming | Robert ...
Improving Veteran benefit services through efficient data streaming | Robert ...Improving Veteran benefit services through efficient data streaming | Robert ...
Improving Veteran benefit services through efficient data streaming | Robert ...HostedbyConfluent
 
Bloomberg Entity Exchange
Bloomberg Entity ExchangeBloomberg Entity Exchange
Bloomberg Entity ExchangeMarco Mejia
 
Bloomberg Entity Exchange
Bloomberg Entity ExchangeBloomberg Entity Exchange
Bloomberg Entity ExchangeHunter Smith
 
Bloomberg Entity Exchange
Bloomberg Entity ExchangeBloomberg Entity Exchange
Bloomberg Entity ExchangeDuncan Galloway
 
Bloomberg Entity Exchange
Bloomberg Entity ExchangeBloomberg Entity Exchange
Bloomberg Entity ExchangeJanique Broomes
 
Bloomberg Entity Exchange
Bloomberg Entity ExchangeBloomberg Entity Exchange
Bloomberg Entity ExchangeGia Freireich
 
Bloomberg Entity Exchange
Bloomberg Entity ExchangeBloomberg Entity Exchange
Bloomberg Entity ExchangeDavid Thomas
 

Ähnlich wie Federation registry (20)

Overview.ppt
Overview.pptOverview.ppt
Overview.ppt
 
Incommon overview
Incommon overviewIncommon overview
Incommon overview
 
TMCnet final
TMCnet finalTMCnet final
TMCnet final
 
project on Agile approach
project on Agile approachproject on Agile approach
project on Agile approach
 
Mobile Banking Security: Challenges, Solutions
Mobile Banking Security: Challenges, SolutionsMobile Banking Security: Challenges, Solutions
Mobile Banking Security: Challenges, Solutions
 
AD FS Workshop | Part 2 | Deep Dive
AD FS Workshop | Part 2 | Deep DiveAD FS Workshop | Part 2 | Deep Dive
AD FS Workshop | Part 2 | Deep Dive
 
Terbine DEP Policy Engine
Terbine DEP Policy EngineTerbine DEP Policy Engine
Terbine DEP Policy Engine
 
Messaging solutions for the government and authorities
Messaging solutions for the government and authoritiesMessaging solutions for the government and authorities
Messaging solutions for the government and authorities
 
Platform Events Demo (1).pptx
Platform Events Demo (1).pptxPlatform Events Demo (1).pptx
Platform Events Demo (1).pptx
 
wallet79
wallet79wallet79
wallet79
 
Project 1 Template (Due on Week 4)Name.docx
Project 1 Template (Due on Week 4)Name.docxProject 1 Template (Due on Week 4)Name.docx
Project 1 Template (Due on Week 4)Name.docx
 
API Security: Does My Business Need OAuth?
API Security: Does My Business Need OAuth?API Security: Does My Business Need OAuth?
API Security: Does My Business Need OAuth?
 
API Security: Does My Business Need OAuth?
API Security: Does My Business Need OAuth?API Security: Does My Business Need OAuth?
API Security: Does My Business Need OAuth?
 
Improving Veteran benefit services through efficient data streaming | Robert ...
Improving Veteran benefit services through efficient data streaming | Robert ...Improving Veteran benefit services through efficient data streaming | Robert ...
Improving Veteran benefit services through efficient data streaming | Robert ...
 
Bloomberg Entity Exchange
Bloomberg Entity ExchangeBloomberg Entity Exchange
Bloomberg Entity Exchange
 
Bloomberg Entity Exchange
Bloomberg Entity ExchangeBloomberg Entity Exchange
Bloomberg Entity Exchange
 
Bloomberg Entity Exchange
Bloomberg Entity ExchangeBloomberg Entity Exchange
Bloomberg Entity Exchange
 
Bloomberg Entity Exchange
Bloomberg Entity ExchangeBloomberg Entity Exchange
Bloomberg Entity Exchange
 
Bloomberg Entity Exchange
Bloomberg Entity ExchangeBloomberg Entity Exchange
Bloomberg Entity Exchange
 
Bloomberg Entity Exchange
Bloomberg Entity ExchangeBloomberg Entity Exchange
Bloomberg Entity Exchange
 

Kürzlich hochgeladen

Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobeapidays
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingEdi Saputra
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Scriptwesley chun
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfsudhanshuwaghmare1
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyKhushali Kathiriya
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAndrey Devyatkin
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024The Digital Insurer
 
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Jeffrey Haguewood
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWERMadyBayot
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxRustici Software
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CVKhem
 
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...Zilliz
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century educationjfdjdjcjdnsjd
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProduct Anonymous
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Drew Madelung
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...apidays
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...apidays
 

Kürzlich hochgeladen (20)

Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
 

Federation registry

  • 2. SAML OpenID Connect UMA How can states support numerous applications who want to use their open interfaces for authentication and authorization? Websites SaaS Apps Mobile Apps
  • 3. Multi-Party Federation Approach… • Federations provide the “tools” and “rules” to protect privacy while driving down the costs for both the State and application developers • Federations are a proven approach: they are widely used in Higher Education and government – http://www.gluu.co/.hdr8
  • 4. To be successful federations have to “Ease the On-boarding” with a simple process to Join – Provide Registration • Applicants agree to the participation agreement and submit their certificate via a management website – Vet participants • The federation reviews the application, and ensures the applicant qualifies to participate in the federation – Collect fee • It is common to collect setup and subscription fees to offset the cost of managing the federation infrastructure
  • 5. The Participation Agreement – Specifies Privacy Protections • Species the Levels of Assurance (LOA) from the identity provider that an accurate authentication has been achieved • Specifies the Level of Protection (LOP) from the website or mobile application as to what security is in place to protect a person’s data from loss • The Level of Control (LOC) a person has to access, correct or remove their data – Standardize Terms and Conditions – Clarify Policies and Operating Procedures
  • 6. The Federation publishes the schema or words used by the Participants – Attributes of the Person • Piece of information about the person • AKA “user claims” – mail, phone, address, state, grade, age… – Authentication Mechanisms • You need to make sure the apps request the right kind of authentication – http://www.example.com/schema/authn/auth_mode/myMobileToken – http://www.example.com/schema/authn/auth_level/9 – Authorization Scopes • You need to make sure the apps request the right kind of authentication – http://www.example.com/schema/authz/grade1 – http://www.example/schema/authz/teacher – http://www.example.com/schema/authz/principal
  • 7. The federation publishes the nightly “metadata” – A file that contains the official list of the participants of the federation (at the time of publication) • http://www.incommon.org/federation/metadata.html – Publishes the certificate of each participant – A place for the federation to publish other information about the participant’s role
  • 8. Federation Registry – Provides scalable administration interface for the federation operator – Open source web application developed by the Australian higher education federation – Deployed in several other countries: Ireland, Switzerland – Enables websites to enter all the information that is needed by the federation and handles the approval workflow
  • 9. What does the Gluu Federation Registry Subscription Include – Deployment of the Federation Registry application on an existing customer IAAS or Gluu Server – Quick start generating the Participation Agreement—will require review and modification by the State – Creation of initial schema for attributes, authentication, and authorization – Development of a operations guide for Registry Administrators – Monitoring / Support of the Federation Registry Server
  • 10. Future proofing… – Current federations are defined using SAML, however federations are not limited to supporting one protocol – OpenID Connect Federation standards are evolving : • http://www.gluu.co/multi-openid-wiki