SlideShare a Scribd company logo
1 of 8
Issues with Externalized Identity

An Internet Identity Workshop session proposed by
                    GE and Cisco
Agenda
• Overview:
  – Currently the identity externalization trend is forcing
    enterprises to continue enabling point-to-point
    connections from enterprise to cloud / business
    partner
  – We believe this may be headed towards scalability
    issues and is complicating provisioning
    processes, AuthZ and persona collisions
• Goal:
  – Understand 2012 direction from the identity industry
    leaders and service providers to help develop practical
    direction while longer term solutions unfold
Issues
• Point-to-Point federated identity and the cost and complexity of
  establishing connections
• Full life-cycle management for provisioning and de-provisioning
  user access to SaaS, and changing permissions within that lifecycle
• Synchronizing enterprise data between the enterprise and the SaaS
• Defining, distributing and executing policy consistently in the
  enterprise and in SaaS
• Second to n tier SaaS integration for federated identity,
  authorization, data synchronization and provisioning life cycle
• Visibility and auditing for all tiers of SaaS for federated identity,
  authorization, data synchronization, provisioning life cycle and
  network access
• Collision of external and enterprise identity
Point-to-Point Federated Identity
• Each connection is bespoke
   – Could we have some agreement on attribute sets?
   – How do we enable SAML re-use with persistent identities
     (routable identity)
   – When does point-to-point tip over?
• Legal contracts differ without potential for reuse
   – Could we have some standard Ts&Cs for identity
     exchange?
   – Is there a standard model for dispute resolution?
• IdP connection configuration process is complex
   – What scope is there for automation?
   – How do we make the protocol meaningful to the business?
Full life-cycle management for
    provisioning and de-provisioning
• Every federation is different!
   – Different APIs, CSVs, TDFs, Excel, spreadsheets, emails,
     pieces of paper, faxes, web pages …
• Three logical models
   – JIT – implicit lifecycle, BUT don’t persist attributes in
     service
   – Sync – complicated technology and privacy
   – Query – Opening up LDAP to external queries,
     transactionally expensive
• Privacy of identity data synchronized across SaaS
  providers
Defining, distributing and executing
 policy in the enterprise and in a SaaS
• How do we enforce enterprise policy at SaaS
  – XACML? Not interoperable in practice
  – Agree XACML on a per SaaS basis, see “Point-to-
    Point federated identity cost and complexity”
• Distributed Policy Management
  – Each provider has their own PAP/PDP, some on
    premise, some allows API but most different
Second to n tier SaaS integration for
         federated identity
• How do I enforce what services my SaaS uses?
• How do I enforce which users can use which
  SaaS leveraged service?
• What visibility do I have of services leveraged
  by SaaS providers?
• Who can consume data provided by services
  leveraged by my SaaS provider?
• Where did my data go?
Collision of external and enterprise
                 identity
• Potential for personal identities to bypass
  policies on enterprise Identities on the same
  SaaS service
• Users can store enterprise data on personal
  SaaS service offerings
• Duplicating (convoluting) identity between
  point-to-point federations

More Related Content

What's hot

SOA Reference Architecture
SOA Reference ArchitectureSOA Reference Architecture
SOA Reference ArchitectureRajan Ramanujam
 
What is a Service Taxonomy and Why Do I Need One?
What is a Service Taxonomy and Why Do I Need One?What is a Service Taxonomy and Why Do I Need One?
What is a Service Taxonomy and Why Do I Need One?Evergreen Systems
 
5 Surefire Ways To Make Your Soa A Success
5 Surefire Ways To Make Your Soa A Success5 Surefire Ways To Make Your Soa A Success
5 Surefire Ways To Make Your Soa A SuccessDavid Linthicum
 
Service Oriented Architecture (SOA)
Service Oriented Architecture (SOA)Service Oriented Architecture (SOA)
Service Oriented Architecture (SOA)Biniam Asnake
 
Soa Taking Theory Into Real World Application
Soa Taking Theory Into Real World ApplicationSoa Taking Theory Into Real World Application
Soa Taking Theory Into Real World ApplicationDavid Linthicum
 
DEVNET-1132 Create B2B Exchanges with Cisco Connected Processes
DEVNET-1132	Create B2B Exchanges with Cisco Connected ProcessesDEVNET-1132	Create B2B Exchanges with Cisco Connected Processes
DEVNET-1132 Create B2B Exchanges with Cisco Connected ProcessesCisco DevNet
 
SOA in a nutshell by Abhilash
 SOA in a nutshell by Abhilash SOA in a nutshell by Abhilash
SOA in a nutshell by AbhilashAbhilash Juluri
 
Understanding The Concept of SOA in Computer Programming
Understanding The Concept of SOA in Computer ProgrammingUnderstanding The Concept of SOA in Computer Programming
Understanding The Concept of SOA in Computer ProgrammingTafariSiphno
 
Web 2 0 To The Universal Soa
Web 2 0 To The Universal SoaWeb 2 0 To The Universal Soa
Web 2 0 To The Universal SoaDavid Linthicum
 
Service Oriented Infrastructure
Service Oriented InfrastructureService Oriented Infrastructure
Service Oriented InfrastructureHumberto Ramos
 
Service Oriented Architecture (SOA)
Service Oriented Architecture (SOA)Service Oriented Architecture (SOA)
Service Oriented Architecture (SOA)Mazhar Ishaq Khokhar
 

What's hot (19)

SOA Reference Architecture
SOA Reference ArchitectureSOA Reference Architecture
SOA Reference Architecture
 
What is a Service Taxonomy and Why Do I Need One?
What is a Service Taxonomy and Why Do I Need One?What is a Service Taxonomy and Why Do I Need One?
What is a Service Taxonomy and Why Do I Need One?
 
What is service
What is serviceWhat is service
What is service
 
5 Surefire Ways To Make Your Soa A Success
5 Surefire Ways To Make Your Soa A Success5 Surefire Ways To Make Your Soa A Success
5 Surefire Ways To Make Your Soa A Success
 
Service Oriented Architecture (SOA)
Service Oriented Architecture (SOA)Service Oriented Architecture (SOA)
Service Oriented Architecture (SOA)
 
Service oriented architecture 27 May 2014
Service oriented architecture 27 May 2014Service oriented architecture 27 May 2014
Service oriented architecture 27 May 2014
 
Soa Taking Theory Into Real World Application
Soa Taking Theory Into Real World ApplicationSoa Taking Theory Into Real World Application
Soa Taking Theory Into Real World Application
 
DEVNET-1132 Create B2B Exchanges with Cisco Connected Processes
DEVNET-1132	Create B2B Exchanges with Cisco Connected ProcessesDEVNET-1132	Create B2B Exchanges with Cisco Connected Processes
DEVNET-1132 Create B2B Exchanges with Cisco Connected Processes
 
12 Steps To Soa Final
12 Steps To Soa Final12 Steps To Soa Final
12 Steps To Soa Final
 
SOA in a nutshell by Abhilash
 SOA in a nutshell by Abhilash SOA in a nutshell by Abhilash
SOA in a nutshell by Abhilash
 
Microservices Decomposition Patterns
Microservices Decomposition PatternsMicroservices Decomposition Patterns
Microservices Decomposition Patterns
 
Soa To The Rescue
Soa To The RescueSoa To The Rescue
Soa To The Rescue
 
Soa overview
Soa overviewSoa overview
Soa overview
 
Understanding The Concept of SOA in Computer Programming
Understanding The Concept of SOA in Computer ProgrammingUnderstanding The Concept of SOA in Computer Programming
Understanding The Concept of SOA in Computer Programming
 
Web 2 0 To The Universal Soa
Web 2 0 To The Universal SoaWeb 2 0 To The Universal Soa
Web 2 0 To The Universal Soa
 
Service Oriented Infrastructure
Service Oriented InfrastructureService Oriented Infrastructure
Service Oriented Infrastructure
 
Service Oriented Architecture (SOA)
Service Oriented Architecture (SOA)Service Oriented Architecture (SOA)
Service Oriented Architecture (SOA)
 
Introduction to SOA
Introduction to SOAIntroduction to SOA
Introduction to SOA
 
Chap 1
Chap 1Chap 1
Chap 1
 

Viewers also liked

Iiw13 identifying with_your_bank
Iiw13 identifying with_your_bankIiw13 identifying with_your_bank
Iiw13 identifying with_your_bankSteve Sidner
 
בועז ארד מיה מחשבים
בועז ארד מיה מחשביםבועז ארד מיה מחשבים
בועז ארד מיה מחשביםAnochi.com.
 
העצמה של ניהול סיכונים (2) zalman el ani
העצמה של ניהול סיכונים (2) zalman el aniהעצמה של ניהול סיכונים (2) zalman el ani
העצמה של ניהול סיכונים (2) zalman el aniAnochi.com.
 
תפקידו של האנליסט בחברה עסקית אוּרי עייק
תפקידו של האנליסט בחברה עסקית   אוּרי עייקתפקידו של האנליסט בחברה עסקית   אוּרי עייק
תפקידו של האנליסט בחברה עסקית אוּרי עייקAnochi.com.
 
Jmp by wayne levin
Jmp by wayne levinJmp by wayne levin
Jmp by wayne levinAnochi.com.
 
תשובת משיבים 1 3
תשובת משיבים 1 3תשובת משיבים 1 3
תשובת משיבים 1 3Anochi.com.
 
Running with Sciccors! : Team Dynamics in Open Source
Running with Sciccors! : Team Dynamics in Open SourceRunning with Sciccors! : Team Dynamics in Open Source
Running with Sciccors! : Team Dynamics in Open SourceAmye Scavarda
 
管理原则与组织效
管理原则与组织效管理原则与组织效
管理原则与组织效卜家
 
התחממות גלובלית פלדור
התחממות גלובלית פלדורהתחממות גלובלית פלדור
התחממות גלובלית פלדורAnochi.com.
 
Quantity demanded for new dwellings january 2013
Quantity demanded for new dwellings january 2013Quantity demanded for new dwellings january 2013
Quantity demanded for new dwellings january 2013Anochi.com.
 
5 strategi pembelajaran_berbasis_tik
5 strategi pembelajaran_berbasis_tik5 strategi pembelajaran_berbasis_tik
5 strategi pembelajaran_berbasis_tikMASHANS
 
Westfield Health Care Reform Webinar Power Point
Westfield Health Care Reform Webinar Power PointWestfield Health Care Reform Webinar Power Point
Westfield Health Care Reform Webinar Power Pointjkoppenheffer
 
כלכלה מסביב לעולם - שבדיה
כלכלה מסביב לעולם - שבדיהכלכלה מסביב לעולם - שבדיה
כלכלה מסביב לעולם - שבדיהAnochi.com.
 
Hawaii linkedin social media bootcamp v1.pptx
Hawaii linkedin social media bootcamp v1.pptxHawaii linkedin social media bootcamp v1.pptx
Hawaii linkedin social media bootcamp v1.pptxMargo Rose
 
חגי גולדמן מיה מחשבים
חגי גולדמן מיה מחשביםחגי גולדמן מיה מחשבים
חגי גולדמן מיה מחשביםAnochi.com.
 
Radical privatization
Radical privatizationRadical privatization
Radical privatizationAnochi.com.
 

Viewers also liked (20)

Iiw13 identifying with_your_bank
Iiw13 identifying with_your_bankIiw13 identifying with_your_bank
Iiw13 identifying with_your_bank
 
Pcitf iiw10
Pcitf   iiw10Pcitf   iiw10
Pcitf iiw10
 
בועז ארד מיה מחשבים
בועז ארד מיה מחשביםבועז ארד מיה מחשבים
בועז ארד מיה מחשבים
 
Fido and Touch ID
Fido and Touch IDFido and Touch ID
Fido and Touch ID
 
העצמה של ניהול סיכונים (2) zalman el ani
העצמה של ניהול סיכונים (2) zalman el aniהעצמה של ניהול סיכונים (2) zalman el ani
העצמה של ניהול סיכונים (2) zalman el ani
 
תפקידו של האנליסט בחברה עסקית אוּרי עייק
תפקידו של האנליסט בחברה עסקית   אוּרי עייקתפקידו של האנליסט בחברה עסקית   אוּרי עייק
תפקידו של האנליסט בחברה עסקית אוּרי עייק
 
Zoranje School
Zoranje SchoolZoranje School
Zoranje School
 
Jmp by wayne levin
Jmp by wayne levinJmp by wayne levin
Jmp by wayne levin
 
תשובת משיבים 1 3
תשובת משיבים 1 3תשובת משיבים 1 3
תשובת משיבים 1 3
 
Running with Sciccors! : Team Dynamics in Open Source
Running with Sciccors! : Team Dynamics in Open SourceRunning with Sciccors! : Team Dynamics in Open Source
Running with Sciccors! : Team Dynamics in Open Source
 
管理原则与组织效
管理原则与组织效管理原则与组织效
管理原则与组织效
 
התחממות גלובלית פלדור
התחממות גלובלית פלדורהתחממות גלובלית פלדור
התחממות גלובלית פלדור
 
Quantity demanded for new dwellings january 2013
Quantity demanded for new dwellings january 2013Quantity demanded for new dwellings january 2013
Quantity demanded for new dwellings january 2013
 
5 strategi pembelajaran_berbasis_tik
5 strategi pembelajaran_berbasis_tik5 strategi pembelajaran_berbasis_tik
5 strategi pembelajaran_berbasis_tik
 
Westfield Health Care Reform Webinar Power Point
Westfield Health Care Reform Webinar Power PointWestfield Health Care Reform Webinar Power Point
Westfield Health Care Reform Webinar Power Point
 
כלכלה מסביב לעולם - שבדיה
כלכלה מסביב לעולם - שבדיהכלכלה מסביב לעולם - שבדיה
כלכלה מסביב לעולם - שבדיה
 
Hawaii linkedin social media bootcamp v1.pptx
Hawaii linkedin social media bootcamp v1.pptxHawaii linkedin social media bootcamp v1.pptx
Hawaii linkedin social media bootcamp v1.pptx
 
חגי גולדמן מיה מחשבים
חגי גולדמן מיה מחשביםחגי גולדמן מיה מחשבים
חגי גולדמן מיה מחשבים
 
Radical privatization
Radical privatizationRadical privatization
Radical privatization
 
Racissmee
RacissmeeRacissmee
Racissmee
 

Similar to IIW 13 - Scalability Point to Point Federation

Cloud Services Brokerage Demystified
Cloud Services Brokerage DemystifiedCloud Services Brokerage Demystified
Cloud Services Brokerage DemystifiedZach Gardner
 
Aws dev ops saif ahmed
Aws dev ops   saif ahmedAws dev ops   saif ahmed
Aws dev ops saif ahmedsaifam
 
Cloud Catalog Management – Services Aggregation and Delivery Best Practices
Cloud Catalog Management – Services Aggregation and Delivery Best PracticesCloud Catalog Management – Services Aggregation and Delivery Best Practices
Cloud Catalog Management – Services Aggregation and Delivery Best Practicesjamcracker4677
 
Shared Services Canada - A Transformational Journey Through Enterprise Initia...
Shared Services Canada - A Transformational Journey Through Enterprise Initia...Shared Services Canada - A Transformational Journey Through Enterprise Initia...
Shared Services Canada - A Transformational Journey Through Enterprise Initia...KBIZEAU
 
Building the Agile Enterprise - Cloud Computing
Building the Agile Enterprise - Cloud ComputingBuilding the Agile Enterprise - Cloud Computing
Building the Agile Enterprise - Cloud ComputingSrinivas Koushik
 
Model Confidence for Master Data with David Loshin
Model Confidence for Master Data with David LoshinModel Confidence for Master Data with David Loshin
Model Confidence for Master Data with David LoshinEmbarcadero Technologies
 
The Emerging Data Lake IT Strategy
The Emerging Data Lake IT StrategyThe Emerging Data Lake IT Strategy
The Emerging Data Lake IT StrategyThomas Kelly, PMP
 
SAS 70 in a Post-Sarbanes, SaaS World: Quest Session 52070
SAS 70 in a Post-Sarbanes, SaaS World: Quest Session 52070SAS 70 in a Post-Sarbanes, SaaS World: Quest Session 52070
SAS 70 in a Post-Sarbanes, SaaS World: Quest Session 52070retheauditors
 
South Florida HDI Event, Managing Service Delivery
South Florida HDI Event, Managing Service DeliverySouth Florida HDI Event, Managing Service Delivery
South Florida HDI Event, Managing Service DeliveryEddie Vidal
 
Practical soa for business and researchers
Practical soa for business and researchersPractical soa for business and researchers
Practical soa for business and researchersMustafa Gamal
 
SOA - Unit 2 - Service Oriented Architecture
SOA - Unit   2 - Service Oriented ArchitectureSOA - Unit   2 - Service Oriented Architecture
SOA - Unit 2 - Service Oriented Architecturehamsa nandhini
 
Empower Your Support Ecosystem with Cisco ServiceGrid
Empower Your Support Ecosystem with Cisco ServiceGridEmpower Your Support Ecosystem with Cisco ServiceGrid
Empower Your Support Ecosystem with Cisco ServiceGridCisco Services
 
Overcoming Barriers to the Cloud
Overcoming Barriers to the Cloud Overcoming Barriers to the Cloud
Overcoming Barriers to the Cloud Andy Milsark
 
MuCon 2015 - Microservices in Integration Architecture
MuCon 2015 - Microservices in Integration ArchitectureMuCon 2015 - Microservices in Integration Architecture
MuCon 2015 - Microservices in Integration ArchitectureKim Clark
 
CIS13: Cloud, Identity Bridges, and ITSM: Three is Not a Crowd
CIS13: Cloud, Identity Bridges, and ITSM: Three is Not a CrowdCIS13: Cloud, Identity Bridges, and ITSM: Three is Not a Crowd
CIS13: Cloud, Identity Bridges, and ITSM: Three is Not a CrowdCloudIDSummit
 
I T E007 Warner 091807
I T E007  Warner 091807I T E007  Warner 091807
I T E007 Warner 091807Dreamforce07
 
Radu crahmaliuc 23feb2012
Radu crahmaliuc 23feb2012Radu crahmaliuc 23feb2012
Radu crahmaliuc 23feb2012Agora Group
 
Sso security&business tool_2018_issa_infosecsummit_grant_reveal_final
Sso security&business tool_2018_issa_infosecsummit_grant_reveal_finalSso security&business tool_2018_issa_infosecsummit_grant_reveal_final
Sso security&business tool_2018_issa_infosecsummit_grant_reveal_finalGrant Reveal
 
AWS Summit 2013 | Singapore - Service Orchestration – Managing the Cloud Disr...
AWS Summit 2013 | Singapore - Service Orchestration – Managing the Cloud Disr...AWS Summit 2013 | Singapore - Service Orchestration – Managing the Cloud Disr...
AWS Summit 2013 | Singapore - Service Orchestration – Managing the Cloud Disr...Amazon Web Services
 

Similar to IIW 13 - Scalability Point to Point Federation (20)

Cloud Services Brokerage Demystified
Cloud Services Brokerage DemystifiedCloud Services Brokerage Demystified
Cloud Services Brokerage Demystified
 
Aws dev ops saif ahmed
Aws dev ops   saif ahmedAws dev ops   saif ahmed
Aws dev ops saif ahmed
 
Cloud Catalog Management – Services Aggregation and Delivery Best Practices
Cloud Catalog Management – Services Aggregation and Delivery Best PracticesCloud Catalog Management – Services Aggregation and Delivery Best Practices
Cloud Catalog Management – Services Aggregation and Delivery Best Practices
 
Shared Services Canada - A Transformational Journey Through Enterprise Initia...
Shared Services Canada - A Transformational Journey Through Enterprise Initia...Shared Services Canada - A Transformational Journey Through Enterprise Initia...
Shared Services Canada - A Transformational Journey Through Enterprise Initia...
 
Building the Agile Enterprise - Cloud Computing
Building the Agile Enterprise - Cloud ComputingBuilding the Agile Enterprise - Cloud Computing
Building the Agile Enterprise - Cloud Computing
 
Model Confidence for Master Data with David Loshin
Model Confidence for Master Data with David LoshinModel Confidence for Master Data with David Loshin
Model Confidence for Master Data with David Loshin
 
The Emerging Data Lake IT Strategy
The Emerging Data Lake IT StrategyThe Emerging Data Lake IT Strategy
The Emerging Data Lake IT Strategy
 
SAS 70 in a Post-Sarbanes, SaaS World: Quest Session 52070
SAS 70 in a Post-Sarbanes, SaaS World: Quest Session 52070SAS 70 in a Post-Sarbanes, SaaS World: Quest Session 52070
SAS 70 in a Post-Sarbanes, SaaS World: Quest Session 52070
 
South Florida HDI Event, Managing Service Delivery
South Florida HDI Event, Managing Service DeliverySouth Florida HDI Event, Managing Service Delivery
South Florida HDI Event, Managing Service Delivery
 
Practical soa for business and researchers
Practical soa for business and researchersPractical soa for business and researchers
Practical soa for business and researchers
 
Security - A Digital Transformation Enabler
Security - A Digital Transformation EnablerSecurity - A Digital Transformation Enabler
Security - A Digital Transformation Enabler
 
SOA - Unit 2 - Service Oriented Architecture
SOA - Unit   2 - Service Oriented ArchitectureSOA - Unit   2 - Service Oriented Architecture
SOA - Unit 2 - Service Oriented Architecture
 
Empower Your Support Ecosystem with Cisco ServiceGrid
Empower Your Support Ecosystem with Cisco ServiceGridEmpower Your Support Ecosystem with Cisco ServiceGrid
Empower Your Support Ecosystem with Cisco ServiceGrid
 
Overcoming Barriers to the Cloud
Overcoming Barriers to the Cloud Overcoming Barriers to the Cloud
Overcoming Barriers to the Cloud
 
MuCon 2015 - Microservices in Integration Architecture
MuCon 2015 - Microservices in Integration ArchitectureMuCon 2015 - Microservices in Integration Architecture
MuCon 2015 - Microservices in Integration Architecture
 
CIS13: Cloud, Identity Bridges, and ITSM: Three is Not a Crowd
CIS13: Cloud, Identity Bridges, and ITSM: Three is Not a CrowdCIS13: Cloud, Identity Bridges, and ITSM: Three is Not a Crowd
CIS13: Cloud, Identity Bridges, and ITSM: Three is Not a Crowd
 
I T E007 Warner 091807
I T E007  Warner 091807I T E007  Warner 091807
I T E007 Warner 091807
 
Radu crahmaliuc 23feb2012
Radu crahmaliuc 23feb2012Radu crahmaliuc 23feb2012
Radu crahmaliuc 23feb2012
 
Sso security&business tool_2018_issa_infosecsummit_grant_reveal_final
Sso security&business tool_2018_issa_infosecsummit_grant_reveal_finalSso security&business tool_2018_issa_infosecsummit_grant_reveal_final
Sso security&business tool_2018_issa_infosecsummit_grant_reveal_final
 
AWS Summit 2013 | Singapore - Service Orchestration – Managing the Cloud Disr...
AWS Summit 2013 | Singapore - Service Orchestration – Managing the Cloud Disr...AWS Summit 2013 | Singapore - Service Orchestration – Managing the Cloud Disr...
AWS Summit 2013 | Singapore - Service Orchestration – Managing the Cloud Disr...
 

Recently uploaded

ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProduct Anonymous
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobeapidays
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfsudhanshuwaghmare1
 
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu SubbuApidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbuapidays
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodJuan lago vázquez
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdflior mazor
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businesspanagenda
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxRustici Software
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherRemote DBA Services
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyKhushali Kathiriya
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAndrey Devyatkin
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc
 
Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024The Digital Insurer
 
A Beginners Guide to Building a RAG App Using Open Source Milvus
A Beginners Guide to Building a RAG App Using Open Source MilvusA Beginners Guide to Building a RAG App Using Open Source Milvus
A Beginners Guide to Building a RAG App Using Open Source MilvusZilliz
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesrafiqahmad00786416
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024The Digital Insurer
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonAnna Loughnan Colquhoun
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDropbox
 
Navi Mumbai Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Navi Mumbai Call Girls 🥰 8617370543 Service Offer VIP Hot ModelNavi Mumbai Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Navi Mumbai Call Girls 🥰 8617370543 Service Offer VIP Hot ModelDeepika Singh
 

Recently uploaded (20)

ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu SubbuApidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024
 
A Beginners Guide to Building a RAG App Using Open Source Milvus
A Beginners Guide to Building a RAG App Using Open Source MilvusA Beginners Guide to Building a RAG App Using Open Source Milvus
A Beginners Guide to Building a RAG App Using Open Source Milvus
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challenges
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
Navi Mumbai Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Navi Mumbai Call Girls 🥰 8617370543 Service Offer VIP Hot ModelNavi Mumbai Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Navi Mumbai Call Girls 🥰 8617370543 Service Offer VIP Hot Model
 

IIW 13 - Scalability Point to Point Federation

  • 1. Issues with Externalized Identity An Internet Identity Workshop session proposed by GE and Cisco
  • 2. Agenda • Overview: – Currently the identity externalization trend is forcing enterprises to continue enabling point-to-point connections from enterprise to cloud / business partner – We believe this may be headed towards scalability issues and is complicating provisioning processes, AuthZ and persona collisions • Goal: – Understand 2012 direction from the identity industry leaders and service providers to help develop practical direction while longer term solutions unfold
  • 3. Issues • Point-to-Point federated identity and the cost and complexity of establishing connections • Full life-cycle management for provisioning and de-provisioning user access to SaaS, and changing permissions within that lifecycle • Synchronizing enterprise data between the enterprise and the SaaS • Defining, distributing and executing policy consistently in the enterprise and in SaaS • Second to n tier SaaS integration for federated identity, authorization, data synchronization and provisioning life cycle • Visibility and auditing for all tiers of SaaS for federated identity, authorization, data synchronization, provisioning life cycle and network access • Collision of external and enterprise identity
  • 4. Point-to-Point Federated Identity • Each connection is bespoke – Could we have some agreement on attribute sets? – How do we enable SAML re-use with persistent identities (routable identity) – When does point-to-point tip over? • Legal contracts differ without potential for reuse – Could we have some standard Ts&Cs for identity exchange? – Is there a standard model for dispute resolution? • IdP connection configuration process is complex – What scope is there for automation? – How do we make the protocol meaningful to the business?
  • 5. Full life-cycle management for provisioning and de-provisioning • Every federation is different! – Different APIs, CSVs, TDFs, Excel, spreadsheets, emails, pieces of paper, faxes, web pages … • Three logical models – JIT – implicit lifecycle, BUT don’t persist attributes in service – Sync – complicated technology and privacy – Query – Opening up LDAP to external queries, transactionally expensive • Privacy of identity data synchronized across SaaS providers
  • 6. Defining, distributing and executing policy in the enterprise and in a SaaS • How do we enforce enterprise policy at SaaS – XACML? Not interoperable in practice – Agree XACML on a per SaaS basis, see “Point-to- Point federated identity cost and complexity” • Distributed Policy Management – Each provider has their own PAP/PDP, some on premise, some allows API but most different
  • 7. Second to n tier SaaS integration for federated identity • How do I enforce what services my SaaS uses? • How do I enforce which users can use which SaaS leveraged service? • What visibility do I have of services leveraged by SaaS providers? • Who can consume data provided by services leveraged by my SaaS provider? • Where did my data go?
  • 8. Collision of external and enterprise identity • Potential for personal identities to bypass policies on enterprise Identities on the same SaaS service • Users can store enterprise data on personal SaaS service offerings • Duplicating (convoluting) identity between point-to-point federations

Editor's Notes

  1. But