OpenAthensSP: A technical overview

Loading...

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

0 comments

Post a comment

    Post a comment
    Embed Video
    Edit your comment Cancel

    Favorites, Groups & Events

    OpenAthensSP: A technical overview - Presentation Transcript

    1. OpenAthens SP: Technical Overview
    2. Topics • The shape and significance of new identity architectures • The benefits of OpenAthens SP • Walk-through demo
    3. The OpenAthens premise Identity standards are maturing and will play an essential part in modern web applications... ...but building practical, yet effective architectures around them can be a major challenge
    4. Evolution of identity architectures • Previously bespoke solutions, based on a variety of technologies: – IP authentication – Username/password – LDAP – SQL – X.509 certificates
    5. Recent changes • 2 significant changes in last 2-3 years directly concerned with identity: 1) 'Federation' has become widely accepted as the future of identity architectures 2) Standards dealing specifically with (federated) identities have emerged • These standards are now reaching maturity
    6. Meanwhile... • The web is reshaping... • User's concept of online identity has radically changed • Web APIs are opening up
    7. The identity Threats Identity theft environment Phishing Web 2.0 SAML OpenID Social networking Shibboleth Blogging Wikis CardSpace XACML Instant messaging LDAP WS-* X.509 User trends Standards/ Protocols Browser Apache IIS J2EE .NET PHP Ruby on Rails Open Source Applications
    8. Implications of this • These changes have meant a bespoke approach to identity is no longer appropriate – Standards are too complicated for this! • A flexible approach to identity is fundamental to modern web applications
    9. Where does 'identity' fit? SOAP Application XML SQL Web server Database HTTP TCP Network DNS
    10. Where does 'identity' fit? SOAP Application XML SAML WS-* 'Identity infrastructure' OpenID SQL XACML Web server Database HTTP TCP Network DNS
    11. So what does this imply? • Standards facilitate 'layering' of technologies • People are already talking about an ‘identity infrastructure' • Projects addressing this now: Higgins (Eclipse), Bandit (Novell)
    12. Introducing OpenAthens SP... • OpenAthens SP contributes to an identity infrastructure in 3 ways: 1) It provides a set of software components to support various identity standards 2) It provides the necessary 'glue' to integrate with an application 3) It provides a supported package to connect to communities of users
    13. Application SQL Platform Audit LDAP SAML Shib ... Policy IdP identity SP identity infrastructure infrastructure OpenAthens SP component Existing or 3rd party component
    14. 1) Components • OpenAthens SP comprises a set of modules supporting – Athens – SAML 1.0/1.1/2.0 – Shibboleth – OpenID – MS information cards
    15. 2) Integration with applications • OpenAthens SP is built on a 'data layer' – the OpenAthens SP platform • Abstraction – Application interacts with the platform not individual modules • Support for multiple languages and platforms
    16. 3) Connecting to users • The combination of 1) and 2) allows for pre- packaged solutions for different communities • OpenAthens SP is available fully supported, currently in 2 different flavours – Athens (inc. NHS) – UKAMF
    17. Application SQL Platform Audit Federation LDAP data SAML Shib ... Policy SP identity infrastructure OpenAthens SP component Existing or 3rd party component
    18. Examples...
    19. Select organisation: OpenAthens SP finds organisation in SAML metadata:
    20. SAML response: Platform 'exports' attributes to application:
    21. Summary • OpenAthens SP can: – Connect a SP to Athens – Connect a SP to Shibboleth identity providers in the UK Access Management Federation • OpenAthens SP is: – Supported by Eduserv in the above scenarios – Actively developing to support the latest identity standards (eg. information cards)
    22. Where to find out more? • There’s more information on our website http://www.athensams.net • Information and live demos are available on the stand outside david.orrell@eduserv.org.uk

    + david.orrelldavid.orrell, 3 years ago

    custom

    1156 views, 0 favs, 2 embeds more stats

    OpenAthensSP provides a flexible platform for integ more

    More info about this document

    © All Rights Reserved

    Go to text version

    • Total Views 1156
      • 1153 on SlideShare
      • 3 from embeds
    • Comments 0
    • Favorites 0
    • Downloads 3
    Most viewed embeds
    • 2 views on http://www.davidorrell.net
    • 1 views on http://localhost

    more

    All embeds
    • 2 views on http://www.davidorrell.net
    • 1 views on http://localhost

    less

    Flagged as inappropriate Flag as inappropriate
    Flag as inappropriate

    Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

    Cancel
    File a copyright complaint
    Having problems? Go to our helpdesk?

    Categories