Cloudcard2

Avoco Secure,[object Object],The I-Card Cloud Selector,[object Object],CloudCard,[object Object]
An introduction to Avoco’s fully Cloud based I-Card Selector, CloudCard,[object Object],A demonstration of the logon process using the Cloud selector and a shared secret,[object Object],A demonstration of the extended use of Information Cards:,[object Object],Digital signing in the Cloud using Information Cards,[object Object],Access control of documents using Information Cards,[object Object],What you will see today,[object Object]
A fully Cloud based Information Card selector,[object Object],A leap forward in Information Card usability,[object Object],Bypasses the world of Windows desktops,[object Object],Designed to have similar functionality to Windows CardSpace, e.g.,[object Object],Personal cards can be created,[object Object],Cards can be imported,[object Object],Cards can be backed up,[object Object],Works with standard and auditing cards – not yet tested with others e.g. Relationship and Signalling cards,[object Object],Like CardSpace, token encryption is left to IdP for auditing cards,[object Object],CloudCard: What is it?,[object Object]
Usability benefits include:,[object Object],Universal access to your Information Cards,[object Object],True zero footprint for end users – no plug-ins, ActiveX, downloads, etc.,[object Object],Access from normal desktops/laptops as well as phones/mobile devices,[object Object],Test Implementation Site: https://www.secure2cardspace.com,[object Object],Why Bother?,[object Object]
Extensibility: Modular design permits simple use of alternative login protocols, etc.,[object Object],Portability: Written in PHP ∴ easy to port to other languages such as Java (if needed),[object Object],Security: Incorporates anti-phishing technology through shared-secret log in control,[object Object],Security: SSL - MITM attacks less feasible,[object Object],Standards: HTML spec to be submitted as standard ,[object Object],Nitty Gritty,[object Object]
CloudCard called as a post from RP web page:,[object Object],<a href="https://www.secure2cardspace.com/CloudCardA/CardView.php?ampIssuer=www.secure2cardspace.com&RequiredClaims=http....,[object Object],Link specifies entry point to selector, required card issuer, claims, etc., like calling a desktop selector.,[object Object],Additionally certificate of RP is included. ,[object Object],RP Use of CloudCard,[object Object]
Used to provide anti-phishing of the I-Card web service account,[object Object],User chooses a photo before logging into their account,[object Object],If correct photo displayed, user can log in knowing the site is genuine,[object Object],A photo always presented to prevent guessing username,[object Object],More on using photos as a shared secret ,[object Object],Sir Henry No-Tail,[object Object]
What’s to stop Phisher from Relaying?,[object Object],1. Generate phishing page,[object Object],Phishing server (PS),[object Object],2. Username submitted,[object Object],CS Backend,[object Object],3. PS submits username to CS backend,[object Object],4. PS gets image from response,[object Object],5. Correct image set in fake password entry page,[object Object]
Session key with real site ,[object Object],1. Create page and setup session key,[object Object],CS Backend,[object Object],2. Username submitted,[object Object],with session key data,[object Object],3. Valid Session key: Image returned,[object Object]
Session key with Phishing Site,[object Object],1. Generate phishing page,[object Object],Phishing server (PS),[object Object],2. Username submitted,[object Object],CS Backend,[object Object],3. PS submits username to CS backend (invalid session key),[object Object],4. No response,[object Object],5. Cannot set correct image,[object Object]
No protection against desktop Trojan / virus (but then entire system is potentially compromised including desktop selector),[object Object],Weaknesses,[object Object]
Use your preferred login scheme e.g. OpenID.,[object Object],If you don’t like this...,[object Object]
Face recognition and recognition of familiar objects is part of an acquired evolutionary trait that helps us survive,[object Object],We are good at it,[object Object],We place trust in our ability to use face recognition and object recognition,[object Object],We use processes of cheat recognition all the time, everyday, to interact with others,[object Object],An identity system must mesh real world me with digital me,[object Object],We must use existing human traits when designing the system ,[object Object],Human Beings, Digital Identity and Pictures of Familiar Things,[object Object]
If you’re interested in the research into cheat recognition and similar:,[object Object],Cartwright, J 2000. Evolution & Human Behaviour. Palgrave,[object Object],Daly, M & Wilson, MI 1999.  Human evolutionary psychology and animal behaviour,[object Object],Cosmides, L and Tooby, University of California at Santa Barbara,[object Object],http://www.psych.ucsb.edu/research/cep/primer.html,[object Object],	http://www.psych.ucsb.edu/research/cep/papers/TOMbroadnarrow.pdf,[object Object],Further Reading,[object Object]
The Avoco Cloud Selector is modular, so,[object Object],Can choose to use a myriad of authentication techniques – this presentation shows one,[object Object],Important not to forget the big picture:,[object Object],Usability – for a consumer as well as business audience,[object Object],Represents the real world me in a familiar way,[object Object],I am me because of these reasons (claims)…,[object Object],Can be used not just for logging into web sites,[object Object],Identity is more than just access control,[object Object],Authentication, Authentication or a Bigger Picture,[object Object]
Current Developments,[object Object],Authentication:,[object Object],Digital certificate,[object Object],OpenID,[object Object],LiveID,[object Object],Card authentication specified by RP,[object Object],e.g. only a card backed by X509 can be selected,[object Object],Seamless upload of cards from IdP to Selector – transparent management for users,[object Object]
A system for issuing OpenID’s with an Information Card ,[object Object],Links the two ID system – best of both worlds,[object Object],OpenID attributes can be set as a Information Card Claim ,[object Object],Information  card can be authenticated by that OpenID,[object Object],OpenID linked to the extended claims system of the Information Card,[object Object],Best of each to create a symbiotic ID system,[object Object],Futures: Information cards and OpenID: SymbioticID (SymID),[object Object]
Requires additional HTML / JavaScript,[object Object],Recommended for web pages to allow user to select a Cloud Selector and Desktop Selector where appropriate / available.,[object Object],How are multiple Selectors to be addressed?,[object Object],Preconfigured to a single Selector,[object Object],Preconfigured dropdown list,[object Object],Dynamic list populated from discovery service.,[object Object],Cloud Selectors: Adoption: ,[object Object]
Extending the Uses of Information Cards,[object Object],Digital Signing in the Cloud,[object Object]
Digital certificates are user-unfriendly and unpopular,[object Object],People don’t like to install software, including browser plug-ins,[object Object],Current solutions for signing on-line forms are open to denial of signing caused by only including form text in signature,[object Object],Therefore, to encourage digital signing, these issues must be addressed,[object Object],Why aren’t we all digitally signing?,[object Object]
Avoco Secure have developed first truly Cloud based digital signing,[object Object],Can be used on:,[object Object],On any operating system,[object Object],Using any browser ,[object Object],From desktops, laptops, mobile devices, phones and so on,[object Object],Signing does not require user to have X509, but standard PKCS#7 signature produced.,[object Object],Nothing to install – fully Cloud based.,[object Object],Non-repudiation addressed.,[object Object],Signing in the Cloud,[object Object]
Always a problem to identify the signer,[object Object],Avoco – generate repeatable RSA key pair from ID info e.g.,[object Object],Information Card claims,[object Object],OpenID attributes,[object Object],ATM Card numbers,[object Object],Passwords,[object Object],etc., etc.,[object Object],Exact data specified by host,[object Object],Key pair -> transient X509 used to sign with,[object Object],Cert and key pair destroyed after signing,[object Object],Digital Signing and Identity,[object Object]
Image of the completed form incorporated into the digital signature,[object Object],Non-Repudiation of Signature,[object Object]
Incorporates timestamp (RFC3161),[object Object],Emails signature to user,[object Object],Signature verifiable by common tools as well as Avoco on-line verifier,[object Object],Other,[object Object]
Demo of CloudCard with Cloud Signing Demo,[object Object]
Extending the Uses of Information Card,[object Object],Controlling Access and Applying Usage Policies to Documents and Emails,[object Object]
Controlling access to documents, emails using Identity Information from Information Cards,[object Object],secure2trust,[object Object],secure2email,[object Object],secure2access,[object Object],Claims used to:,[object Object],Control document and email access,[object Object],Apply usage policies, post access,[object Object],Done in a content centric manner,[object Object],Security is persistent across perimeters,[object Object],And there’s more…,[object Object]
Demo of document access control and policy application,[object Object]
Thanks for your time,[object Object],Susan Morrow,[object Object],Head of Product Development,[object Object],Avoco Secure,[object Object],susan.morrow@avocosecure.com,[object Object]
1 of 29

Recommended

ChatGPT and the Future of Work - Clark Boyd by
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd Clark Boyd
25.3K views69 slides
Getting into the tech field. what next by
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next Tessa Mero
6K views22 slides
Google's Just Not That Into You: Understanding Core Updates & Search Intent by
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentLily Ray
6.5K views99 slides
How to have difficult conversations by
How to have difficult conversations How to have difficult conversations
How to have difficult conversations Rajiv Jayarajah, MAppComm, ACC
5.2K views19 slides
Introduction to Data Science by
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data ScienceChristy Abraham Joy
82.4K views51 slides
Time Management & Productivity - Best Practices by
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best PracticesVit Horky
169.7K views42 slides

More Related Content

Recently uploaded

CloudStack and GitOps at Enterprise Scale - Alex Dometrius, Rene Glover - AT&T by
CloudStack and GitOps at Enterprise Scale - Alex Dometrius, Rene Glover - AT&TCloudStack and GitOps at Enterprise Scale - Alex Dometrius, Rene Glover - AT&T
CloudStack and GitOps at Enterprise Scale - Alex Dometrius, Rene Glover - AT&TShapeBlue
56 views34 slides
Updates on the LINSTOR Driver for CloudStack - Rene Peinthor - LINBIT by
Updates on the LINSTOR Driver for CloudStack - Rene Peinthor - LINBITUpdates on the LINSTOR Driver for CloudStack - Rene Peinthor - LINBIT
Updates on the LINSTOR Driver for CloudStack - Rene Peinthor - LINBITShapeBlue
91 views8 slides
Microsoft Power Platform.pptx by
Microsoft Power Platform.pptxMicrosoft Power Platform.pptx
Microsoft Power Platform.pptxUni Systems S.M.S.A.
67 views38 slides
Network Source of Truth and Infrastructure as Code revisited by
Network Source of Truth and Infrastructure as Code revisitedNetwork Source of Truth and Infrastructure as Code revisited
Network Source of Truth and Infrastructure as Code revisitedNetwork Automation Forum
42 views45 slides
Igniting Next Level Productivity with AI-Infused Data Integration Workflows by
Igniting Next Level Productivity with AI-Infused Data Integration Workflows Igniting Next Level Productivity with AI-Infused Data Integration Workflows
Igniting Next Level Productivity with AI-Infused Data Integration Workflows Safe Software
344 views86 slides
PharoJS - Zürich Smalltalk Group Meetup November 2023 by
PharoJS - Zürich Smalltalk Group Meetup November 2023PharoJS - Zürich Smalltalk Group Meetup November 2023
PharoJS - Zürich Smalltalk Group Meetup November 2023Noury Bouraqadi
141 views17 slides

Recently uploaded(20)

CloudStack and GitOps at Enterprise Scale - Alex Dometrius, Rene Glover - AT&T by ShapeBlue
CloudStack and GitOps at Enterprise Scale - Alex Dometrius, Rene Glover - AT&TCloudStack and GitOps at Enterprise Scale - Alex Dometrius, Rene Glover - AT&T
CloudStack and GitOps at Enterprise Scale - Alex Dometrius, Rene Glover - AT&T
ShapeBlue56 views
Updates on the LINSTOR Driver for CloudStack - Rene Peinthor - LINBIT by ShapeBlue
Updates on the LINSTOR Driver for CloudStack - Rene Peinthor - LINBITUpdates on the LINSTOR Driver for CloudStack - Rene Peinthor - LINBIT
Updates on the LINSTOR Driver for CloudStack - Rene Peinthor - LINBIT
ShapeBlue91 views
Igniting Next Level Productivity with AI-Infused Data Integration Workflows by Safe Software
Igniting Next Level Productivity with AI-Infused Data Integration Workflows Igniting Next Level Productivity with AI-Infused Data Integration Workflows
Igniting Next Level Productivity with AI-Infused Data Integration Workflows
Safe Software344 views
PharoJS - Zürich Smalltalk Group Meetup November 2023 by Noury Bouraqadi
PharoJS - Zürich Smalltalk Group Meetup November 2023PharoJS - Zürich Smalltalk Group Meetup November 2023
PharoJS - Zürich Smalltalk Group Meetup November 2023
Noury Bouraqadi141 views
Keynote Talk: Open Source is Not Dead - Charles Schulz - Vates by ShapeBlue
Keynote Talk: Open Source is Not Dead - Charles Schulz - VatesKeynote Talk: Open Source is Not Dead - Charles Schulz - Vates
Keynote Talk: Open Source is Not Dead - Charles Schulz - Vates
ShapeBlue119 views
Backup and Disaster Recovery with CloudStack and StorPool - Workshop - Venko ... by ShapeBlue
Backup and Disaster Recovery with CloudStack and StorPool - Workshop - Venko ...Backup and Disaster Recovery with CloudStack and StorPool - Workshop - Venko ...
Backup and Disaster Recovery with CloudStack and StorPool - Workshop - Venko ...
ShapeBlue77 views
Transitioning from VMware vCloud to Apache CloudStack: A Path to Profitabilit... by ShapeBlue
Transitioning from VMware vCloud to Apache CloudStack: A Path to Profitabilit...Transitioning from VMware vCloud to Apache CloudStack: A Path to Profitabilit...
Transitioning from VMware vCloud to Apache CloudStack: A Path to Profitabilit...
ShapeBlue57 views
iSAQB Software Architecture Gathering 2023: How Process Orchestration Increas... by Bernd Ruecker
iSAQB Software Architecture Gathering 2023: How Process Orchestration Increas...iSAQB Software Architecture Gathering 2023: How Process Orchestration Increas...
iSAQB Software Architecture Gathering 2023: How Process Orchestration Increas...
Bernd Ruecker50 views
Data Integrity for Banking and Financial Services by Precisely
Data Integrity for Banking and Financial ServicesData Integrity for Banking and Financial Services
Data Integrity for Banking and Financial Services
Precisely56 views
Don’t Make A Human Do A Robot’s Job! : 6 Reasons Why AI Will Save Us & Not De... by Moses Kemibaro
Don’t Make A Human Do A Robot’s Job! : 6 Reasons Why AI Will Save Us & Not De...Don’t Make A Human Do A Robot’s Job! : 6 Reasons Why AI Will Save Us & Not De...
Don’t Make A Human Do A Robot’s Job! : 6 Reasons Why AI Will Save Us & Not De...
Moses Kemibaro29 views
Mitigating Common CloudStack Instance Deployment Failures - Jithin Raju - Sha... by ShapeBlue
Mitigating Common CloudStack Instance Deployment Failures - Jithin Raju - Sha...Mitigating Common CloudStack Instance Deployment Failures - Jithin Raju - Sha...
Mitigating Common CloudStack Instance Deployment Failures - Jithin Raju - Sha...
ShapeBlue74 views
What’s New in CloudStack 4.19 - Abhishek Kumar - ShapeBlue by ShapeBlue
What’s New in CloudStack 4.19 - Abhishek Kumar - ShapeBlueWhat’s New in CloudStack 4.19 - Abhishek Kumar - ShapeBlue
What’s New in CloudStack 4.19 - Abhishek Kumar - ShapeBlue
ShapeBlue131 views
Developments to CloudStack’s SDN ecosystem: Integration with VMWare NSX 4 - P... by ShapeBlue
Developments to CloudStack’s SDN ecosystem: Integration with VMWare NSX 4 - P...Developments to CloudStack’s SDN ecosystem: Integration with VMWare NSX 4 - P...
Developments to CloudStack’s SDN ecosystem: Integration with VMWare NSX 4 - P...
ShapeBlue82 views
Hypervisor Agnostic DRS in CloudStack - Brief overview & demo - Vishesh Jinda... by ShapeBlue
Hypervisor Agnostic DRS in CloudStack - Brief overview & demo - Vishesh Jinda...Hypervisor Agnostic DRS in CloudStack - Brief overview & demo - Vishesh Jinda...
Hypervisor Agnostic DRS in CloudStack - Brief overview & demo - Vishesh Jinda...
ShapeBlue63 views
2FA and OAuth2 in CloudStack - Andrija Panić - ShapeBlue by ShapeBlue
2FA and OAuth2 in CloudStack - Andrija Panić - ShapeBlue2FA and OAuth2 in CloudStack - Andrija Panić - ShapeBlue
2FA and OAuth2 in CloudStack - Andrija Panić - ShapeBlue
ShapeBlue50 views
HTTP headers that make your website go faster - devs.gent November 2023 by Thijs Feryn
HTTP headers that make your website go faster - devs.gent November 2023HTTP headers that make your website go faster - devs.gent November 2023
HTTP headers that make your website go faster - devs.gent November 2023
Thijs Feryn28 views

Featured

Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present... by
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Applitools
55.5K views138 slides
12 Ways to Increase Your Influence at Work by
12 Ways to Increase Your Influence at Work12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at WorkGetSmarter
401.7K views64 slides
ChatGPT webinar slides by
ChatGPT webinar slidesChatGPT webinar slides
ChatGPT webinar slidesAlireza Esmikhani
30.4K views36 slides
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G... by
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...DevGAMM Conference
3.6K views12 slides
Barbie - Brand Strategy Presentation by
Barbie - Brand Strategy PresentationBarbie - Brand Strategy Presentation
Barbie - Brand Strategy PresentationErica Santiago
25.1K views46 slides

Featured(20)

Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present... by Applitools
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Applitools55.5K views
12 Ways to Increase Your Influence at Work by GetSmarter
12 Ways to Increase Your Influence at Work12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work
GetSmarter401.7K views
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G... by DevGAMM Conference
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
DevGAMM Conference3.6K views
Barbie - Brand Strategy Presentation by Erica Santiago
Barbie - Brand Strategy PresentationBarbie - Brand Strategy Presentation
Barbie - Brand Strategy Presentation
Erica Santiago25.1K views
Good Stuff Happens in 1:1 Meetings: Why you need them and how to do them well by Saba Software
Good Stuff Happens in 1:1 Meetings: Why you need them and how to do them wellGood Stuff Happens in 1:1 Meetings: Why you need them and how to do them well
Good Stuff Happens in 1:1 Meetings: Why you need them and how to do them well
Saba Software25.2K views
Introduction to C Programming Language by Simplilearn
Introduction to C Programming LanguageIntroduction to C Programming Language
Introduction to C Programming Language
Simplilearn8.4K views
The Pixar Way: 37 Quotes on Developing and Maintaining a Creative Company (fr... by Palo Alto Software
The Pixar Way: 37 Quotes on Developing and Maintaining a Creative Company (fr...The Pixar Way: 37 Quotes on Developing and Maintaining a Creative Company (fr...
The Pixar Way: 37 Quotes on Developing and Maintaining a Creative Company (fr...
Palo Alto Software88.4K views
9 Tips for a Work-free Vacation by Weekdone.com
9 Tips for a Work-free Vacation9 Tips for a Work-free Vacation
9 Tips for a Work-free Vacation
Weekdone.com7.2K views
How to Map Your Future by SlideShop.com
How to Map Your FutureHow to Map Your Future
How to Map Your Future
SlideShop.com275.1K views
Beyond Pride: Making Digital Marketing & SEO Authentically LGBTQ+ Inclusive -... by AccuraCast
Beyond Pride: Making Digital Marketing & SEO Authentically LGBTQ+ Inclusive -...Beyond Pride: Making Digital Marketing & SEO Authentically LGBTQ+ Inclusive -...
Beyond Pride: Making Digital Marketing & SEO Authentically LGBTQ+ Inclusive -...
AccuraCast3.4K views
Exploring ChatGPT for Effective Teaching and Learning.pptx by Stan Skrabut, Ed.D.
Exploring ChatGPT for Effective Teaching and Learning.pptxExploring ChatGPT for Effective Teaching and Learning.pptx
Exploring ChatGPT for Effective Teaching and Learning.pptx
Stan Skrabut, Ed.D.57.7K views
How to train your robot (with Deep Reinforcement Learning) by Lucas García, PhD
How to train your robot (with Deep Reinforcement Learning)How to train your robot (with Deep Reinforcement Learning)
How to train your robot (with Deep Reinforcement Learning)
Lucas García, PhD42.5K views
4 Strategies to Renew Your Career Passion by Daniel Goleman
4 Strategies to Renew Your Career Passion4 Strategies to Renew Your Career Passion
4 Strategies to Renew Your Career Passion
Daniel Goleman122K views
The Student's Guide to LinkedIn by LinkedIn
The Student's Guide to LinkedInThe Student's Guide to LinkedIn
The Student's Guide to LinkedIn
LinkedIn88K views
Different Roles in Machine Learning Career by Intellipaat
Different Roles in Machine Learning CareerDifferent Roles in Machine Learning Career
Different Roles in Machine Learning Career
Intellipaat12.4K views
Defining a Tech Project Vision in Eight Quick Steps pdf by TechSoup
Defining a Tech Project Vision in Eight Quick Steps pdfDefining a Tech Project Vision in Eight Quick Steps pdf
Defining a Tech Project Vision in Eight Quick Steps pdf
TechSoup 9.7K views

Cloudcard2

  • 1.
  • 2.
  • 3.
  • 4.
  • 5.
  • 6.
  • 7.
  • 8.
  • 9.
  • 10.
  • 11.
  • 12.
  • 13.
  • 14.
  • 15.
  • 16.
  • 17.
  • 18.
  • 19.
  • 20.
  • 21.
  • 22.
  • 23.
  • 24.
  • 25.
  • 26.
  • 27.
  • 28.
  • 29.

Editor's Notes

  1. Photo’s can also be used by an OpenID system if required
  2. Extensibility via HTML parameters