OpenID Tutorials

Loading...

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

0 comments

Post a comment

    Post a comment
    Embed Video
    Edit your comment Cancel

    Favorites, Groups & Events

    OpenID Tutorials - Presentation Transcript

    1. OpenID Tutorial. Naofumi HAIDA from Cirius Technologies.
    2. Table of Contents. • Self-Introduction. • What is OpenID? • OpenID 2.0 quick look. • Security Issues. • Other related OpenAPIs.
    3. Self-introduction. • Working @Cirius Technologies, Inc. • Architect @Cirius Lab. • Ruby Programmer. • GeoAPIs, Twitwi Twitter, Twittalk etc... • OpenAPIS & Beyond LT • http://docs.google.com/Presentation? id=dgp485h4_561dwgpsrcd
    4. Questions. • OpenID ? • RP OpenID ? • OpenID 2.0 ? • XRI ?
    5. Authentication ( ) ID Authorization ( ) ID
    6. Backgrounds.
    7. • Internet Identity Workshop Six Apart Brad Fitzpatrick OpenID (2005.10) • Web OpenID (2007.02) • Blogger OpenID (2007.11) • OpenID Authentication 2.0 & OpenID Attribute Exchange 1.0 (2007.12)
    8. • Blogger OpenID IdP (2008.01) • Yahoo OpenID 2.0 IdP (2008.01) • OpenID Foundation Google IBM MS Yahoo! (2008.02) • Six Apart Verisign NRI OpenID Japan Foundation (2008.02)
    9. Many Internet users are “End User” of OpenID Now!
    10. ~ 360 million OpenIDs.
    11. Total Relying Parties Borrowed from David Recordon
    12. There are over 11,000 OpenID enable sites!
    13. What’s for OpenID?
    14. We use more and more sites!
    15. OpenID solves...
    16. Too many passwords!
    17. My Online Profile scattered across many sites!
    18. What is an OpenID??
    19. http://www.hatena.ne.jp/haida/
    20. http://profile.livedoor.com/haida
    21. http://haida.livejurnal.com/
    22. Is an OpenID a URI? It has changed in OpenID ver 2.0.
    23. yahoo.com
    24. coderepos.org
    25. xri://=haida
    26. OpenID: Identity URI Web Authority http://www.slideshare.net/zigorou/ openid-20-quick-note/
    27. These are not OpenID.
    28. Authorization Authentication Delegation Privacy Identity Maneger Trust Control Single-Sign-On Distributed SSO
    29. Login with OpenID.
    30. Input Claimed Identifier @ RP.
    31. Authenticate @ OP.
    32. Merits & Demerits of OpenID.
    33. End User URI
    34. Relying Party - - Sun OpenID Sun Sun
    35. 2. OpenID 2.0 Quick look.
    36. User-Supplied Identifier
    37. URL ID ID
    38. https://me.yahoo.co.jp/a/ X4F0sewBfO6V5S31BLZsyz4BnEx0# fdf84 yahoo.com
    39. XRI
    40. Identity URI XRI
    41. xri://=haida
    42. xri xri ID i-name
    43. = @
    44. xri://@yahoo
    45. ※ XRI xri://=haida 12 $/year xri://@mixi 55 $/year
    46. Terms around OpenID.
    47. identifier http, https URI URI 2.0 URI XRI
    48. OpenID Provider: OP Ver 1.1 IdP OpenID
    49. OP Identifier OP Identifier
    50. Relying Party: RP Consumer OpenID Identifier OP Web Web
    51. Claimed Identifier URI OP
    52. User-Supplied Identifier RP Claimed Identifier OP Identifier
    53. OP-Local Identifier OP Identifier OP Identifier
    54. How does authentication work with OpenID ?
    55. 1. RP Claimed Identifier HTML 2. openid.server link 3. RP 4. OP 5. OP RP 6. RP
    56. How does this work?
    57. Discovery with XRDS.
    58. OP delegate Identifier OpenID 1.1 HTML OpenID 2.0 XRDS XML
    59. Claimed Identifier XRI - XRDS Claimed Identifier URL - HTML x-xrds-location URL - meta http-equiv x-xrds-location URL - Content-type application/xrds+xml XRDS
    60. <?xml version=\"1.0\" encoding=\"UTF-8\"?> <xrds:XRDS xmlns:xrds=\"xri://$xrds\" xmlns:openid=\"http://openid.net/xmlns/1.0\" xmlns=\"xri://$xrd*($v*2.0)\"> <XRD> <Service priority=\"0\"> <Type>http://specs.openid.net/auth/2.0/server</Type> <URI>http://openid.example.com/auth</URI> </Service> </XRD> </xrds:XRDS>
    61. Service Type
    62. Security Risks.
    63. Phishing.
    64. 1. Malicious Consumer OpenID 2. Identifier URI 3. Malicious Consumer OP OP 4. OP OP ID, Password 5. 6. OP
    65. Firefox OpenID SeatBelt (by VeriSign) -- OpenID -- Malicious Consumer Malicious Consumer OP -- OP
    66. OP nonce trust_root, return_to return_to malicious consumer OP robots.txt OpenID “Identity Page for\" site:*.myopenid.com” OP
    67. RP for Mobile OP RP for Mobile OpenID ?
    68. orz..
    69. OpenID Security ! http://wiki.openid.net/Security
    70. Reputation Problem OP
    71. OP RP AOL OP http://dev.aol.com/node/578
    72. OP https Attribute Exchange Provider Authentication Policy Extension
    73. OP Reputation OP !
    74. Summary • OpenID • OpenID 2.0 User Friendly! • IdP
    75. Thank you!

    + planetsplanets, 2 years ago

    custom

    784 views, 0 favs, 1 embeds more stats

    More info about this document

    © All Rights Reserved

    Go to text version

    • Total Views 784
      • 768 on SlideShare
      • 16 from embeds
    • Comments 0
    • Favorites 0
    • Downloads 0
    Most viewed embeds
    • 16 views on http://blog.cirius.co.jp

    more

    All embeds
    • 16 views on http://blog.cirius.co.jp

    less

    Flagged as inappropriate Flag as inappropriate
    Flag as inappropriate

    Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

    Cancel
    File a copyright complaint
    Having problems? Go to our helpdesk?

    Categories